A government entity and a religious organization in Taiwan have been targeted by Chinese hackers Evasive Panda, who infected them with the new CloudScout toolset.

“ The CloudScout toolset is able to retrieve data from various cloud services, leveraging stolen web session cookies ,” said an ESET security researcher . “ Through a plugin, CloudScout works seamlessly with MgBot, the signature malware framework of the Evasive Panda team .”
ESET says that the use of the .NET-based malware tool was observed between May 2022 and February 2023. The module incorporates 10 different modules, written in C#. Three are intended to steal data from Google Drive, Gmail, and Outlook. The purpose of the remaining modules remains unknown.
See also: Canadian Cyber Center warns that Chinese hackers are scanning IT systems
Chinese hackers Evasive Panda, also known as Bronze Highland, Daggerfly, and StormBamboo, are a espionage that has targeted various entities in Taiwan and Hong Kong.
These hackers use a variety of methods for initial compromise, ranging from exploiting security vulnerabilities to compromising the supply chain via DNS poisoning. The ultimate goal is the deployment of MgBot and Nightdoor.
ESET said that the CloudScout modules are designed to compromise authenticated browser sessions, stealing cookies and using them to gain unauthorized access to Google Drive, Gmail and Outlook. Each of these modules is powered by a MgBot plugin.
“At the heart of CloudScout is the CommonUtilities package, which provides all the necessary low-level libraries to run the modules,” explained the ESET researcher.
See also: FBI, CISA: Chinese hackers have breached multiple telecommunications providers
“CommonUtilities contains several custom libraries, despite the abundant availability of similar open source libraries on the internet. These custom libraries provide developers with greater flexibility and control over the internals of their implant.“:
- HTTPAccess, which provides functions for handling HTTP communications
- ManagedCookie, which provides cookie management functions for web requests between CloudScout and the targeted service
- Logger
- SimpleJSON
The information gathered from the three modules – mail folder entries, email messages (including attachments), and files matching specific extensions (.doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, and .txt) – is compressed into a ZIP file and then collected by either MgBot or Nightdoor.

“CloudScout is a .NET toolkit used by Evasive Panda hackers to steal data stored in cloud. It is implemented as an extension of MgBot and uses the pass-the-cookie technique to compromise authenticated sessions from web browsers,” the ESET researcher summarized.
See also: Chinese hackers APT41 target gambling and gaming companies
The recent attacks by hackers in Taiwan serve as a reminder of the evolving threat landscape and the need for constant vigilance when it comes to cybersecurity. As more organizations and individuals store their data in the cloud, cybercriminals are targeting cloud services and constantly adapting their tactics to evade detection.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
To defend against such attacks, it is important for organizations to implement multi-layered security measures and regularly update their protection tools. In addition, collaboration between government agencies, private companies, and cybersecurity can significantly improve our defenses against sophisticated attackers like the Evasive Panda group.
Source: thehackernews.com
