China-Linked Hackers Compromise ISP to Deploy Malicious Software Updates
In mid-2023, the China-affiliated threat actor Evasive Panda gained access to an unidentified ISP and used it to distribute malicious software upgrades to targeted businesses, demonstrating a newfound level of competence for the outfit.
Evasive Panda is a cyber espionage gang that has been operating since at least 2012. They go by the names Bronze Highland, Daggerfly, and StormBamboo and use backdoors like MgBot (also known as POCOSTICK) and Nightdoor (also known as NetMM and Suzafk) to obtain sensitive data.
A macOS malware strain known as MACMA, which has been seen in the wild since 2021, was officially linked to the threat actor more recently.
In a report released last week, Volexity stated that StormBamboo is an extremely proficient and belligerent threat actor that infiltrat...

