#daggerfly
March 14, 2026 at 8:20 PM
April 2, 2024 at 4:52 PM
This was one laid back daggerfly Empis digramma. It was completely unbothered by my manipulations with the Meum blossom to prevent it from swaying in the wind. ISOP web has only thirteen observations and zero in my region, yet they seem pretty common around here. #diptera #insects
June 3, 2025 at 8:22 PM
Is Spiday a thing here? If not, why not?
This is a Xysticus sp., I believe, predating a dagger fly. Which seems fair.
#insects #arachnids #spider #fly #Xysticus #EmpisLivida #DaggerFly #predation #GardenWildlife #UKWildlife #NaturePhotography #MacroPhotography #StingsNWings
May 31, 2024 at 12:16 PM
A bug among the thorns... hmmm... I guess that's not really the expression! However, this is two "sharp" things because the bug is a dagger fly and they get their name from their sharp mouthparts. #sharp #blueskyartshow #bug #plantphotos #thorn #photos #photography #daggerfly
June 13, 2026 at 1:28 PM
Daggerfly Empis digramma (Czech: kroužilka) on a blossom of Meum athamanticum (Czech: koprník štětinatý) in Ore Mountains of the Czech Republic. Daggerflies are predators of other arthropods and most also pollinate flowers. Meum is a monotypic genus of highly (and pleasantly) aromatic plants.
May 29, 2025 at 8:09 PM
Daggerfly
December 18, 2024 at 6:09 PM
Day 15 - Dagger 

"Daggerfly" - 8.5x11, ink on bristol. You may have heard of a bullet with butterfly wings but now I present... a magical dagger with dragonfly wings? A daggerfly!

To bid on pieces, join me on Patreon! www.patreon.com/tortoiseharecreations

#inktober #inktober2023
October 15, 2023 at 4:54 PM
Evasive Panda/DaggerFly uses SSH backdoor ELF/Sshdinjector.A!tr to compromise devices. This malware injects a malicious library for remote command execution, data theft, and credential stealing. Fortinet's FortiGuard offers protection.#PandaDaggerFlyMalware
February 4, 2025 at 6:05 PM
Chinese Hackers’ Four-Month Email Heist: A Comedic Tragedy in Cybersecurity

Chinese hackers lingered in a US company's network for months, using DLL sideloading and more. Daggerfly strikes again! Time to beef up that email security, folks!
https://buff.ly/3D3r4e3
Chinese Hackers’ Four-Month Email Heist: A Comedic Tragedy in Cybersecurity
Chinese hackers maintained a four-month-long access to a major U.S. company’s network, likely swiping sensitive emails. Employing sneaky techniques like DLL sideloading, they targeted Exchange Servers for intelligence-gathering. Linked to the infamous Chinese group Daggerfly, this cyber-espionage highlights the need for stronger email security.
buff.ly
December 5, 2024 at 10:40 PM
⚠️ New Threat! Beijing-affiliated #hacking group Daggerfly targets Taiwan and U.S. NGO in China with upgraded #malware tools, exploiting Apache HTTP server vulnerabilities.
#CyberSecurity #cyberattack
thehackernews.com/2024/07/chin...
Chinese Hackers Target Taiwan and US NGO with MgBot Malware
Chinese hackers target Taiwan and US NGO with advanced malware. Daggerfly group upgrades cyber arsenal for espionage, exploiting vulnerabilities.
thehackernews.com
July 24, 2024 at 1:08 AM
Alert: Chinese #EvasivePanda (also known as Daggerfly) is targeting Tibetans with watering hole attack and Nightdoor backdoor globally.
hackread.com/chinese-evas...
#CyberSecurity #Tibet #China #CyberAttack #Malware
Chinese Evasive Panda Targets Tibetans with Nightdoor Backdoor
Follow us on Twitter (X) @Hackread - Facebook @ /Hackread
hackread.com
March 8, 2024 at 9:21 PM
Chinese Hackers Attacking Linux Devices With New SSH Backdoor
Chinese Hackers Attacking Linux Devices With New SSH Backdoor
A new report from FortiGuard Labs reveals that Chinese hackers are actively targeting Linux devices with a sophisticated SSH backdoor dubbed ELF/Sshdinjector.A!tr. This malware, attributed to the DaggerFly espionage group, has been used in the Lunar Peek campaign since mid-November 2024, primarily targeting network appliances and IoT devices. The attack involves several malicious components working in tandem. The initial entry point is a dropper, which first verifies if it has root privileges. Experts at Fortinet identified that if the system isn’t already compromised, the dropper deploys a suite of malicious binaries, including a modified SSH library named "libsshd.so" and infected versions of common utilities like "ls" , "netstat" , and "crond" . Overview of ELF – Sshdinjector (Source – Fortinet) The "libsshd.so" library is the core of the backdoor, equipped with the capability to communicate with a remote command-and-control (C2) server. The primary malicious functionality resides within a function named “haha,” which spawns two additional threads from functions “heihei” and “xixi” – all terms signifying laughter in Chinese. The “xixi” function monitors the "/root/intensify-mm-inject/ xxx" directory and restarts the SSH and Cron daemons if necessary. The “heihei” function establishes a connection with the hardcoded C2 server at IP address 45.125.64[.]200 on ports 33200 or 33223 , awaiting commands. The malware uses a custom communication protocol with the C2 server, embedding a hard-coded UUID ( a273079c-3e0f-4847-a075-b4e1f9549e88 ) and an identifier ( afa8dcd81a854144 ) in each packet, along with the command response. The C2 server can issue a variety of commands, including:- Command Id Description 1 “SERVER_REQ_BASE_INFO”. Exfiltrates uname, MAC address etc to C2 2 List running services, by listing files in “/etc/ init.d” 3 Reads users from “/etc/ shadow” 4 Lists running process 5 Tests access to “/var/log/ dmesg” 6 Tests access to “/tmp/ fcontr.xml” 7 Lists a given directory 8 File transfer 9 Opens a shell terminal 10 Executes a command in the terminal 11 Unloads and exits the malicious process 12 Removes a file 13 Renames a file 1000 “SERVER_RET_ONLINE_ACK” 0x80000001 Client status change notification. It sends base info, service list, read “/etc/ shadow”. This allows the attackers to gather system information, exfiltrate sensitive data , and execute arbitrary commands on the compromised device. AI extrapolation (Source – Fortinet) It is highly recommended that users of Linux-based network appliances and IoT devices ensure their AntiVirus definitions are up-to-date. Indicators of Compromise (IOCs) FortiGuard Labs has identified the following Indicators of Compromise (IOCs):- SHA256: 94e8540ea39893b6be910cfee0331766e4a199684b0360e367741facca74191f SHA256: 0e2ed47c0a1ba3e1f07711fb90ac8d79cb3af43e82aa4151e5c7d210c96baebb C2 Server: 45.125.64[.]200:33200 and 45.125.64[.]200:33223 Investigate Real-World Malicious Links & Phishing Attacks With  Threat Intelligence Lookup  -  Try for Free The post Chinese Hackers Attacking Linux Devices With New SSH Backdoor appeared first on Cyber Security News .
cybersecuritynews.com
February 5, 2025 at 4:55 PM
Evasive Panda Uses DNS Poisoning to Deploy MgBot Backdoor in Long-Running Espionage Campaign #ChinalinkedAPT #CyberAttacks #CyberEspionageCampaign
Evasive Panda Uses DNS Poisoning to Deploy MgBot Backdoor in Long-Running Espionage Campaign
  Security researchers at Kaspersky have uncovered a sophisticated cyber-espionage operation attributed to the China-linked advanced persistent threat (APT) group known as Evasive Panda, also tracked as Daggerfly, Bronze Highland, and StormBamboo. The campaign leveraged DNS poisoning techniques to distribute the MgBot backdoor, targeting select victims across Türkiye, China, and India. Active for over a decade, Evasive Panda is widely recognized for developing and deploying the custom MgBot malware framework. In 2023, Symantec previously linked the group to an intrusion at an African telecommunications provider, where new MgBot plugins were observed—demonstrating the group’s continued refinement of its cyber-espionage toolkit. According to Kaspersky, the latest campaign was highly selective in nature and operated for nearly two years, beginning in November 2022 and continuing through November 2024. The attackers employed adversary-in-the-middle (AiTM) techniques, delivering encrypted malware components through manipulated DNS responses. Each target received a tailored implant designed to evade detection. The MgBot backdoor was injected directly into legitimate processes in memory, frequently using DLL sideloading, allowing the malware to remain concealed for extended periods. Initial compromise was achieved through fake software updates masquerading as legitimate applications. In one observed case, threat actors distributed a malicious executable posing as a SohuVA update, likely delivered through DNS poisoning that redirected update requests to infrastructure under attacker control. “The malicious package, named sohuva_update_10.2.29.1-lup-s-tp.exe, clearly impersonates a real SohuVA update to deliver malware from the following resource” “There is a possibility that the attackers used a DNS poisoning attack to alter the DNS response of p2p.hd.sohu.com[.]cn to an attacker-controlled server’s IP address, while the genuine update module of the SohuVA application tries to update its binaries located in appdata\roaming\shapp\7.0.18.0\package.” Beyond SohuVA, similar trojanized updaters were observed targeting widely used applications such as iQIYI Video, IObit Smart Defrag, and Tencent QQ, often launched by legitimate system services to reinforce trust and avoid suspicion. The initial malware loader, written in C++ and built using the Windows Template Library, was disguised as a harmless sample project. Once executed, it decrypted and decompressed its configuration data, revealing installation directories, command-and-control domains, and encrypted MgBot parameters. The malware dynamically altered its behavior based on the active user context, decrypted strings only at runtime, and used XOR and LZMA obfuscation to hinder analysis. Ultimately, it executed shellcode directly in memory after modifying memory permissions, enabling covert deployment without leaving obvious forensic traces. The infection chain followed a multi-stage execution model. The first-stage loader launched shellcode that concealed API usage by resolving Windows functions via hashing. This shellcode searched for a specific DAT file within the installation directory. If found, the file was decrypted using Windows CryptUnprotectData, ensuring it could only be accessed on the infected system, before being deleted to erase evidence. If the DAT file was absent, the shellcode retrieved the next stage from the internet. Through DNS poisoning, victims were redirected to attacker-controlled servers while believing they were accessing legitimate domains such as dictionary.com. System details, including the Windows version, were transmitted via HTTP headers, allowing attackers to tailor payloads accordingly. The downloaded data was decrypted using XOR, memory permissions were altered, and the payload was executed. The malware later re-encrypted the payload and stored it in a newly created DAT file, often unique to each victim. Researchers also identified a secondary loader named libpython2.4.dll, which masqueraded as a legitimate Windows library. This component was loaded through a signed executable, evteng.exe—an outdated Python binary—to further mask malicious activity. The loader recorded its file path in status.dat, likely to support future updates, and decrypted additional payloads from perf.dat, which were also delivered via DNS poisoning. Throughout this process, the attackers repeatedly renamed and relocated the payloads, decrypting them with XOR and re-encrypting them using a customized combination of DPAPI and RC5, effectively binding the malware to the infected host and complicating analysis. Kaspersky telemetry indicates confirmed victims in Türkiye, China, and India, with some systems remaining compromised for more than a year. The prolonged duration of the operation highlights the attackers’ persistence, operational maturity, and access to substantial resources. The observed tactics, techniques, and procedures (TTPs) strongly align with previous Evasive Panda operations. While a new loader was introduced, the attackers continued to rely on the long-established MgBot implant, albeit with updated configuration elements. As seen in earlier campaigns, Evasive Panda favored stealthy propagation methods such as supply-chain compromise, adversary-in-the-middle attacks, and watering-hole techniques to avoid detection. “The Evasive Panda threat actor has once again showcased its advanced capabilities, evading security measures with new techniques and tools while maintaining long-term persistence in targeted systems.” “Our investigation suggests that the attackers are continually improving their tactics, and it is likely that other ongoing campaigns exist. The introduction of new loaders may precede further updates to their arsenal.”
dlvr.it
December 30, 2025 at 10:28 AM
China-based Evasive Panda hackers compromised an ISP to spread malware, report says
China-based Evasive Panda hackers compromised an ISP to spread malware, report says
Analysts said a China-linked hacking operation — known as Evasive Panda, Bronze Highland, Daggerfly and StormBamboo — was undertaking “adversary in the middle” attacks in 2023 as it infected Mac and Windows systems.
therecord.media
August 2, 2024 at 7:25 PM
China-linked APT group uses new Macma macOS backdoor version
Chinese Daggerfly uses a new version of Macma macOS backdoor
China-linked APT Daggerfly (aka Evasive Panda, Bronze Highland) has been spotted using a new version of the macOS backdoor Macma.
securityaffairs.com
July 24, 2024 at 11:23 AM
China-linked Daggerfly hackers update their toolset, likely after exposure
China-linked Daggerfly hackers update their toolset, likely after exposure
An alleged Chinese government-backed hacking group has made a major update to its toolset and introduced several new versions of its malware, most likely to avoid detection after its older variants were uncovered, according to recent research.
therecord.media
July 23, 2024 at 2:53 PM
Chinese Hackers Target Taiwan and US NGO with MgBot Malware
Chinese Hackers Target Taiwan and US NGO with MgBot Malware
Chinese hackers target Taiwan and US NGO with advanced malware. Daggerfly group upgrades cyber arsenal for espionage, exploiting vulnerabilities.
thehackernews.com
July 23, 2024 at 1:52 PM
Chinese Hackers Hijack Linux Network Devices via SSH: A Chinese hacking group, called Evasive Panda (or DaggerFly), has found a new way to attack Linux-based network devices. By using the SSH (Secure Shell) ...

The post Chinese Hackers Hijack Linux Network Devices via SSH appeared first on…
Chinese Hackers Hijack Linux Network Devices via SSH
A Chinese hacking group, called Evasive Panda (or DaggerFly), has found a new way to attack Linux-based network devices. By using the SSH (Secure Shell) ... The post Chinese Hackers Hijack Linux Network Devices via SSH appeared first on Gizchina.com.
dlvr.it
February 6, 2025 at 5:09 AM