China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware
A highly focused cyber espionage campaign has been traced to an advanced persistent threat (APT) group with ties to China. The adversary poisoned Domain Name System (DNS) requests to deliver its signature MgBot backdoor in attacks that targeted victims in China, India, and Turkey.
According to Kaspersky, the action took place between November 2022 and November 2024. It has been connected to Evasive Panda, a hacker collective that goes by the names Bronze Highland, Daggerfly, and StormBamboo. It has been considered active since at least 2012.
According to a detailed investigation by Kaspersky researcher Fatih Şensoy, the gang primarily carried out adversary-in-the-middle (AitM) attacks on certain victims. These included methods like storing encrypted portions of the malware on attack...





