A Chinese group is responsible for the spread of the new variant of the MgBot Trojan malware across India and Hong Kong.
According to Malwarebytes researchers Hossein Jazi and Jérôme Segura, the phishing documents used to spread the malware, which are associated with tensions in Hong Kong and China, indicate that a Chinese cyberattack group – active since 2014 – is likely behind the attack.
In a blog post on Tuesday, cybersecurity researchers said that an archive file that had been disguised as communication from the Indian government was detected on July 2.

The phishing document initially distributed a variant of Cobalt Strike, a legitimate penetration testing that can be abused by threat actors. However, on the same day, the template changed to carry a loader for MgBot, a Remote Access Trojan (RAT).
On July 5, additional phishing documents loaded with MgBot were found in statements by UK Prime Minister Boris Johnsonregarding the current political situation between China and Hong Kong.
It is believed that the group uses the tactic of spear phishing emails in targeted attacks against political entities and individuals.
“The lures used in this campaign indicate that the threat actor may be targeting the Indian government and individuals in Hong Kong, or at least those who oppose the new security being enacted by China,” the group says.
If a victim downloads the phishing document and activates the macros, the payload is deployed and executed, disguised as the Realtek Audio Manager tool. The final payload is distributed via the Application Management (AppMgmt) service in Windows.
MgBot can connect to a command and control (C2) server to exfiltrate data from compromised devices, take screenshots, terminate and create processes, create Mutex resources, and use persistence mechanisms.
The authors of the malware also tried to stop the analysis of the malicious code by applying anti-analysis and anti-virtualization methods. These include self-modification of the code, checks for existing antivirus products, and scanning for virtual environments such as VirtualBox. If a sandbox is detected, the MgBot Trojan does not carry out malicious activity.
The C2 servers and IP addresses associated with the malware are almost all based in Hong Kong. The coding in simple Chinese suggests that the malware is the work of Chinese speakers.
During the C2 examination, Malwarebytes also found several malicious Android APKs believed to be part of the toolkit . The apps contain an embedded Trojan capable of recording video and audio from a smartphone, tracking a phone's location after stealing GPS data, stealing phone contacts, call logs, SMS messages, and web history, and sending SMS messages without permission.
Malwarebytes believes that the group responsible for this wave of attacks is not collaborating with Rancor or APT40, as APT has always used a variant of the MgBot Trojan in every campaign it has detected – at least, until now.
“Given the ongoing tensions between India and China, as well as the new security in Hong Kong, we believe this new campaign is being operated by a hacker funded by the Chinese government,” Malwarebytes says. “Given these factors, we attribute this attack with all due caution to a new Chinese APT group.”
