HomeSecurityEvasive Panda: Uses MgBot malware to target international NGOs in China

Evasive Panda: Uses MgBot malware to target international NGOs in China

The APT group referred to as Evasive Panda has been observed targeting an international non-governmental organization (NGO) in mainland China with malware delivered through update channels of legitimate applications such as Tencent QQ.

MgBot malware

The attack chains are designed to distribute a Windows installer for the MgBot malware, ESET security researcher Facundo Muñoz said in a new report published today. The activity began in November 2020 and continued throughout 2021.

The Evasive Panda group, also known as Bronze Highland and Daggerfly, is a Chinese-speaking APT group that has been attributed with a series of cyberespionage attacks targeting various entities in China, Hong Kong , and other countries located in East and South Asia since at least December 2012.

The group's trademark is the use of the custom MgBot modular malware framework, which is able to receive additional components on the fly to expand its intelligence gathering capabilities.

Some of the malware's prominent capabilities include file theft, keystroke logging, clipboard data collection, audio stream recording, and web browser credentials theft

ESET, which discovered the campaign in January 2022 after a legitimate Chinese app was used to deploy an installer for the MgBot backdoor, said the targeted users were located in Gansu, Guangdong and Jiangsu provinces and are members of an unnamed international NGO.

The trojanized application is the Tencent QQ Windows client software updater (“QQUrlMgr.exe”) hosted on the domain “update.browser.qq[.]com.” It is not immediately clear how the threat actor managed to deliver the implant via legitimate updates.

Panda

However, it points to one of two scenarios, a compromise of the supply chain of Tencent QQ update servers or an adversary-in-the-middle (AitM) case, as reported by Kaspersky in June 2022, involving a Chinese hacking crew named LuoYu.

In recent years, many software supply chain attacks have been orchestrated by nation-state groups from Russia, China , and North Korea. The ability to quickly acquire a large malicious footprint has not been lost on these attackers, who are increasingly targeting the IT supply chain to compromise corporate environments.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS