China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware

A highly focused cyber espionage campaign has been traced to an advanced persistent threat (APT) group with ties to China. The adversary poisoned Domain Name System (DNS) requests to deliver its signature MgBot backdoor in attacks that targeted victims in China, India, and Turkey.

According to Kaspersky, the action took place between November 2022 and November 2024. It has been connected to Evasive Panda, a hacker collective that goes by the names Bronze Highland, Daggerfly, and StormBamboo. It has been considered active since at least 2012.

According to a detailed investigation by Kaspersky researcher Fatih Şensoy, the gang primarily carried out adversary-in-the-middle (AitM) attacks on certain victims. These included methods like storing encrypted portions of the malware on attacker-controlled servers, which were resolved in response to particular website DNS requests read more about China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *