#daggerfly
A bug among the thorns... hmmm... I guess that's not really the expression! However, this is two "sharp" things because the bug is a dagger fly and they get their name from their sharp mouthparts. #sharp #blueskyartshow #bug #plantphotos #thorn #photos #photography #daggerfly
June 13, 2026 at 1:28 PM
March 14, 2026 at 8:20 PM
📌 Chinese APT Group Evasive Panda Uses DNS Poisoning to Deploy MgBot Backdoor in Targeted Cyberespionage Campaign https://www.cyberhub.blog/article/17420-chinese-apt-group-evasive-panda-uses-dns-poisoning-to-deploy-mgbot-backdoor-in-targeted-cyberespionage-campaign
Chinese APT Group Evasive Panda Uses DNS Poisoning to Deploy MgBot Backdoor in Targeted Cyberespionage Campaign
The Chinese Advanced Persistent Threat (APT) group, Evasive Panda (also known as Daggerfly, Bronze Highland, or StormBamboo), has been identified by Kaspersky researchers as conducting a targeted cyberespionage campaign using DNS poisoning to deploy the MgBot backdoor. The campaign has targeted victims in Turkey, China, and India. DNS poisoning involves manipulating DNS responses to redirect requests to malicious servers, which then install the MgBot backdoor on the compromised systems. This technique allows the attackers to maintain persistent access to the systems, enabling data exfiltration and further attacks. The use of DNS poisoning by an APT group highlights the continued evolution of attack techniques and underscores the importance of securing DNS infrastructure and monitoring for unusual DNS activity. Organizations should ensure robust endpoint protection and network monitoring to detect and respond to such threats. The targeting of victims in multiple countries suggests a broad interest in intelligence gathering, which could have geopolitical implications. Cybersecurity professionals should stay informed about the tactics, techniques, and procedures (TTPs) used by APT groups to effectively defend against these advanced threats.
www.cyberhub.blog
December 31, 2025 at 3:20 AM
Evasive Panda Uses DNS Poisoning to Deploy MgBot Backdoor in Long-Running Espionage Campaign #ChinalinkedAPT #CyberAttacks #CyberEspionageCampaign
Evasive Panda Uses DNS Poisoning to Deploy MgBot Backdoor in Long-Running Espionage Campaign
  Security researchers at Kaspersky have uncovered a sophisticated cyber-espionage operation attributed to the China-linked advanced persistent threat (APT) group known as Evasive Panda, also tracked as Daggerfly, Bronze Highland, and StormBamboo. The campaign leveraged DNS poisoning techniques to distribute the MgBot backdoor, targeting select victims across Türkiye, China, and India. Active for over a decade, Evasive Panda is widely recognized for developing and deploying the custom MgBot malware framework. In 2023, Symantec previously linked the group to an intrusion at an African telecommunications provider, where new MgBot plugins were observed—demonstrating the group’s continued refinement of its cyber-espionage toolkit. According to Kaspersky, the latest campaign was highly selective in nature and operated for nearly two years, beginning in November 2022 and continuing through November 2024. The attackers employed adversary-in-the-middle (AiTM) techniques, delivering encrypted malware components through manipulated DNS responses. Each target received a tailored implant designed to evade detection. The MgBot backdoor was injected directly into legitimate processes in memory, frequently using DLL sideloading, allowing the malware to remain concealed for extended periods. Initial compromise was achieved through fake software updates masquerading as legitimate applications. In one observed case, threat actors distributed a malicious executable posing as a SohuVA update, likely delivered through DNS poisoning that redirected update requests to infrastructure under attacker control. “The malicious package, named sohuva_update_10.2.29.1-lup-s-tp.exe, clearly impersonates a real SohuVA update to deliver malware from the following resource” “There is a possibility that the attackers used a DNS poisoning attack to alter the DNS response of p2p.hd.sohu.com[.]cn to an attacker-controlled server’s IP address, while the genuine update module of the SohuVA application tries to update its binaries located in appdata\roaming\shapp\7.0.18.0\package.” Beyond SohuVA, similar trojanized updaters were observed targeting widely used applications such as iQIYI Video, IObit Smart Defrag, and Tencent QQ, often launched by legitimate system services to reinforce trust and avoid suspicion. The initial malware loader, written in C++ and built using the Windows Template Library, was disguised as a harmless sample project. Once executed, it decrypted and decompressed its configuration data, revealing installation directories, command-and-control domains, and encrypted MgBot parameters. The malware dynamically altered its behavior based on the active user context, decrypted strings only at runtime, and used XOR and LZMA obfuscation to hinder analysis. Ultimately, it executed shellcode directly in memory after modifying memory permissions, enabling covert deployment without leaving obvious forensic traces. The infection chain followed a multi-stage execution model. The first-stage loader launched shellcode that concealed API usage by resolving Windows functions via hashing. This shellcode searched for a specific DAT file within the installation directory. If found, the file was decrypted using Windows CryptUnprotectData, ensuring it could only be accessed on the infected system, before being deleted to erase evidence. If the DAT file was absent, the shellcode retrieved the next stage from the internet. Through DNS poisoning, victims were redirected to attacker-controlled servers while believing they were accessing legitimate domains such as dictionary.com. System details, including the Windows version, were transmitted via HTTP headers, allowing attackers to tailor payloads accordingly. The downloaded data was decrypted using XOR, memory permissions were altered, and the payload was executed. The malware later re-encrypted the payload and stored it in a newly created DAT file, often unique to each victim. Researchers also identified a secondary loader named libpython2.4.dll, which masqueraded as a legitimate Windows library. This component was loaded through a signed executable, evteng.exe—an outdated Python binary—to further mask malicious activity. The loader recorded its file path in status.dat, likely to support future updates, and decrypted additional payloads from perf.dat, which were also delivered via DNS poisoning. Throughout this process, the attackers repeatedly renamed and relocated the payloads, decrypting them with XOR and re-encrypting them using a customized combination of DPAPI and RC5, effectively binding the malware to the infected host and complicating analysis. Kaspersky telemetry indicates confirmed victims in Türkiye, China, and India, with some systems remaining compromised for more than a year. The prolonged duration of the operation highlights the attackers’ persistence, operational maturity, and access to substantial resources. The observed tactics, techniques, and procedures (TTPs) strongly align with previous Evasive Panda operations. While a new loader was introduced, the attackers continued to rely on the long-established MgBot implant, albeit with updated configuration elements. As seen in earlier campaigns, Evasive Panda favored stealthy propagation methods such as supply-chain compromise, adversary-in-the-middle attacks, and watering-hole techniques to avoid detection. “The Evasive Panda threat actor has once again showcased its advanced capabilities, evading security measures with new techniques and tools while maintaining long-term persistence in targeted systems.” “Our investigation suggests that the attackers are continually improving their tactics, and it is likely that other ongoing campaigns exist. The introduction of new loaders may precede further updates to their arsenal.”
dlvr.it
December 30, 2025 at 10:28 AM
Evasive Panda cyberespionage campaign uses DNS poisoning to install MgBot backdoor

China-linked APT Evasive Panda used DNS poisoning to deliver the MgBot backdoor in targeted cyber-espionage attacks in Türkiye, China, and India. Kaspersky researchers spotted the China-linked APT …
#hackernews #news
Evasive Panda cyberespionage campaign uses DNS poisoning to install MgBot backdoor
China-linked APT Evasive Panda used DNS poisoning to deliver the MgBot backdoor in targeted cyber-espionage attacks in Türkiye, China, and India. Kaspersky researchers spotted the China-linked APT group Evasive Panda (aka Daggerfly, Bronze Highland, and StormBamboo) running a targeted cyber-espionage campaign using DNS poisoning to deliver the MgBot backdoor against victims in Türkiye, China, and […]
securityaffairs.com
December 30, 2025 at 4:02 AM
影のアップデート:Evasive Pandaの2年にわたるスパイ活動が明らかに

Evasive Panda(Bronze Highland、Daggerfly、StormBambooとしても追跡されている)として知られる中国のハッキンググループは、近年でも最も高度かつ長期にわたるサイバーキャンペーンの一つを実行し、被害者のシステムにひそかに感染させ、ほぼ2年にわたって支配を維持しました。カスペルスキー研究所の新たな調査が明らかにしたところによると、この作戦は2022年11月から2024年11月まで続き、卓越した精密さ、ステルス性、そして高度な技術力が特徴でした。…
影のアップデート:Evasive Pandaの2年にわたるスパイ活動が明らかに
Evasive Panda(Bronze Highland、Daggerfly、StormBambooとしても追跡されている)として知られる中国のハッキンググループは、近年でも最も高度かつ長期にわたるサイバーキャンペーンの一つを実行し、被害者のシステムにひそかに感染させ、ほぼ2年にわたって支配を維持しました。カスペルスキー研究所の新たな調査が明らかにしたところによると、この作戦は2022年11月から2024年11月まで続き、卓越した精密さ、ステルス性、そして高度な技術力が特徴でした。 攻撃者は特に、いわゆる中間者(MitM)攻撃に重点を置きました。これは、信頼されたアプリケーションの正規アップデートを装って、被害者に悪意あるコードを配布する手法です。キャンペーンを通じて、ハッカーはストリーミングサービスを含む広く利用されているソフトウェアのアップデートを改ざんし、その過程でマルウェアローダーを密かに埋め込みました。いくつかの事例では、DNS応答の改ざんに依存していた可能性があり、被害者のシステムが正規のアップデートサーバーではなく、攻撃者が管理するインフラへ接続するよう誘導されていました。 偽のアップデートは、SohuVAやiQIYI Videoといった人気アプリケーションのほか、数百万台のコンピュータにインストールされているユーティリティやメッセージングクライアント向けにも作成されました。悪意あるコードは正規ソフトウェアのディレクトリ内に慎重に配置され、アプリケーション自身のサービスによって起動されるため、長期間にわたり検知されずに潜伏できました。 このキャンペーンを特徴づける要素の一つは、解析と検知を大幅に困難にするよう設計された新開発のローダーでした。これは多段階アーキテクチャを採用しており、ペイロードの各コンポーネントは暗号化された形で保存され、特定の条件が満たされた場合にのみ取得されます。設定データ、文字列、さらにはファイル名までも暗号化によって隠蔽され、マルウェアは完全にシステムメモリ上で実行されるため、ディスク上に従来型の痕跡をほとんど残しません。 攻撃の最終段階では、オペレーターはよく知られている一方で現在も進化を続けるスパイ活動モジュールMgBotを展開します。これは、署名付きで一見無害な実行ファイルを用い、svchost.exeなどの正規のWindowsプロセスへのコードインジェクションによって実現されます。こうした手法により侵入は数か月、場合によっては数年にわたり、静かに持続します。 Evasive Pandaはさらに、ハイブリッド暗号化の使用によってインフラを保護しました。ペイロードの一部は、被害者固有のマシンに紐づくネイティブのWindows機構を用いて暗号化されます。その結果、傍受されたファイルは他のシステムでは復号や解析ができず、セキュリティアナリストや研究者の作業を大幅に困難にします。 テレメトリデータによれば、トルコ、中国、インドのユーザーが影響を受け、一部のシステムは1年以上にわたって侵害されたままでした。このキャンペーンの規模と期間は、攻撃者側に相当なリソースがあり、意図的で戦略的なアプローチを取っていたことを示しています。 研究者は、この作戦を高い確度でEvasive Pandaによるものと結論づけています。手法とツールが、同グループの過去に文書化された活動と密接に一致しているためです。新たなローダーや難読化手法が導入されたにもかかわらず、MgBotは攻撃の最終段階であり続けています—ただし、設定は更新され、機能は拡張されています。 専門家は、この作戦がサイバースパイ活動の進化を鮮明に示していると指摘します。攻撃者は、信頼されたアプリケーションやネットワークインフラ、さらには防御目的のシステム機構までも、ユーザー自身に対して武器化する傾向を強めています。あらゆる兆候から見て、このキャンペーンが最後である可能性は低く、新たなツールの出現は、Evasive Pandaが将来さらに複雑な作戦に備えていることを示唆しているのかもしれません。 翻訳元:
blackhatnews.tokyo
December 29, 2025 at 3:49 AM
中国と関連するEvasive Panda、DNSポイズニング・キャンペーンでMgBotマルウェアを配布

中国と関連する高度持続的脅威(APT)グループが、敵対者がドメイン・ネーム・システム(DNS)リクエストを汚染して、同グループ特有のMgBotバックドアを配布した高度に標的化されたサイバー諜報キャンペーンに関与したとされている。この攻撃は、トルコ、中国、インドの被害者を標的としていた。 カスペルスキーによると、この活動は2022年11月から2024年11月の間に観測された。これはEvasive Pandaと呼ばれるハッキンググループに関連付けられており、Bronze…
中国と関連するEvasive Panda、DNSポイズニング・キャンペーンでMgBotマルウェアを配布
中国と関連する高度持続的脅威(APT)グループが、敵対者がドメイン・ネーム・システム(DNS)リクエストを汚染して、同グループ特有のMgBotバックドアを配布した高度に標的化されたサイバー諜報キャンペーンに関与したとされている。この攻撃は、トルコ、中国、インドの被害者を標的としていた。 カスペルスキーによると、この活動は2022年11月から2024年11月の間に観測された。これはEvasive Pandaと呼ばれるハッキンググループに関連付けられており、Bronze Highland、Daggerfly、StormBambooとして追跡されている。少なくとも2012年以降活動していると評価されている。 「このグループは主に、特定の被害者に対してアドバーサリー・イン・ザ・ミドル(AitM)攻撃を実行しました」とカスペルスキー研究者のFatih Şensoyは詳細分析で述べた。「これには、特定の場所にローダーを投下することや、マルウェアの暗号化された部品を攻撃者が管理するサーバーに保存し、特定のウェブサイトのDNSリクエストへの応答としてそれらが解決される、といった手法が含まれていました。」 Evasive PandaのDNSポイズニング能力が注目されたのは今回が初めてではない。2023年4月の時点で、ESETは、同脅威アクターがサプライチェーン侵害またはAitM攻撃のいずれかを実施し、中国本土の国際的な非政府組織(NGO)を標的とした攻撃で、Tencent QQのような正規アプリケーションのトロイの木馬化されたバージョンを配布した可能性があると指摘している。 2024年8月には、Volexityの報告が、同脅威アクターがDNSポイズニング攻撃によって匿名のインターネットサービスプロバイダー(ISP)を侵害し、関心のある標的に悪意あるソフトウェア更新を配信した方法を明らかにした。 Evasive Pandaは、マルウェア配布のためにAitMポイズニングに依存してきた中国系脅威活動クラスターの一つでもある。先月の分析でESETは、初期侵入またはラテラルムーブメントのためにこの手法を活用している中国の活動中グループ10件を追跡していると述べ、その中にはLuoYu、BlackTech、TheWizards APT、Blackwood、PlushDaemon、FontGoblinが含まれる。 カスペルスキーが文書化した攻撃では、脅威アクターが、中国のインターネット企業Sohuの動画配信サービスであるSohuVAなど、サードパーティ製ソフトウェアの更新を装った誘導手口を利用していたことが判明している。悪意ある更新はドメイン「p2p.hd.sohu.com[.]cn」から配信されており、DNSポイズニング攻撃を示唆している可能性が高い。 「攻撃者がDNSポイズニング攻撃を用いてp2p.hd.sohu.com[.]cnのDNS応答を改ざんし、攻撃者管理サーバーのIPアドレスに変更した可能性があります。その一方で、SohuVAアプリケーションの正規の更新モジュールは、appdata\roaming\shapp\7.0.18.0\packageにあるバイナリを更新しようとします」とŞensoyは説明した。 このロシアのサイバーセキュリティ企業はまた、Evasive PandaがBaiduのiQIYI Videoの偽アップデーターに加え、IObit Smart DefragやTencent QQも利用した別のキャンペーンを特定したと述べた。 この攻撃により、初期ローダーの展開が可能となる。このローダーはシェルコードを起動し、そのシェルコードが、正規サイトdictionary[.]comに対するDNSポイズニングを再び利用して、PNG画像ファイルの形をした暗号化済み第2段階シェルコードを取得する。 Evasive Pandaはdictionary[.]comに関連付けられたIPアドレスを操作し、被害者システムが地理的位置とインターネットサービスプロバイダーに基づいて、同ウェブサイトを攻撃者管理のIPアドレスに解決するようにしたとされる。 現時点では、脅威アクターがどのようにDNS応答を汚染しているのかは不明だ。しかし、2つの可能性が疑われている。被害者が利用するISPが選択的に標的化され、侵害されてエッジデバイスに何らかのネットワーク・インプラントがインストールされたか、あるいは被害者が使用するルーターまたはファイアウォールがこの目的でハッキングされたかのいずれかである。 第2段階シェルコードを取得するためのHTTPリクエストには、現在のWindowsのバージョン番号も含まれている。これは、攻撃者が特定のOSバージョンを狙い、使用されているOSに基づいて戦略を適応させようとしている可能性が高い。なお、Evasive Pandaは以前、ウォータリングホール攻撃を利用して、MACMAというコードネームのApple macOSマルウェアを配布していた。 第2段階ペイロードの正確な性質は不明だが、カスペルスキーの分析によれば、第1段階シェルコードが取得したペイロードを復号して実行する。検知回避の手段として、攻撃者は被害者ごとに固有の暗号化済み第2シェルコードファイルを生成していると評価されている。 作戦の重要な要素は、サイドロードされるようにリネームされた古い「python.exe」に依存する二次ローダー(「libpython2.4.dll」)の使用である。起動すると、「C:\ProgramData\Microsoft\eHome\perf.dat」というファイルの内容を読み取ることで次段階のマルウェアをダウンロードして復号する。このファイルには、前段階でダウンロードされた復号済みペイロードが含まれている。 「攻撃者は、当初XORで暗号化されていたリソースからこの段階を取得するために複雑なプロセスを用いたようです」とカスペルスキーは述べた。「その後、攻撃者はこの段階をXORで復号し、続いてMicrosoftのデータ保護API(DPAPI)とRC5アルゴリズムを独自に組み合わせた方式で暗号化してperf.datに保存しました。」 独自の暗号化アルゴリズムの使用は、暗号化データが暗号化が最初に行われた特定のシステム上でのみ復号できるようにし、悪意あるペイロードを傍受して解析しようとする試みを阻止することで、分析を困難にする狙いがあるとみられる。 復号されたコードはMgBotの亜種で、二次ローダーによって正規の「svchost.exe」プロセスにインジェクトされる。モジュール型インプラントであるMgBotは、ファイルの収集、キーストロークの記録、クリップボードデータの収集、音声ストリームの録音、ウェブブラウザーからの認証情報窃取が可能だ。これにより、マルウェアは侵害されたシステム内で長期間にわたり秘匿的な常駐を維持できる。 「Evasive Pandaの脅威アクターは、新たな技術とツールでセキュリティ対策を回避しつつ、標的システムでの長期的な永続性を維持するという高度な能力を、改めて示しました」とカスペルスキーは述べた。 翻訳元:
blackhatnews.tokyo
December 26, 2025 at 3:29 PM
Feed: "GBHackers Security | #1 Globally Trusted Cyber Security News Platform"
By: Mayura Kathir on Wednesday, December 24, 2025
Evasive Panda APT: Malware Delivery via AitM and DNS Poisoning
Evasive Panda, a sophisticated threat actor known by the aliases Bronze Highland, Daggerfly, and StormBamboo, has escalated its offensive capabilities through a two-year campaign.
gbhackers.com
December 25, 2025 at 5:46 AM
Evasive Panda APT:AitMとDNSポイズニングによるマルウェア配布

Bronze Highland、Daggerfly、StormBambooという別名でも知られる高度な脅威アクター「Evasive Panda」は、2年にわたるキャンペーンを通じて攻撃能力を増強し、敵対者中間者(AitM)攻撃やDNSポイズニングなどの高度な攻撃手法を展開してきました。 2025年6月の調査によると、同グループは2022年11月から2024年11月まで継続的な活動を維持し、検知回避を目的として進化するマルウェア配布メカニズムを用いて、トルコ、中国、インドの被害者を標的にしていました。…
Evasive Panda APT:AitMとDNSポイズニングによるマルウェア配布
Bronze Highland、Daggerfly、StormBambooという別名でも知られる高度な脅威アクター「Evasive Panda」は、2年にわたるキャンペーンを通じて攻撃能力を増強し、敵対者中間者(AitM)攻撃やDNSポイズニングなどの高度な攻撃手法を展開してきました。 2025年6月の調査によると、同グループは2022年11月から2024年11月まで継続的な活動を維持し、検知回避を目的として進化するマルウェア配布メカニズムを用いて、トルコ、中国、インドの被害者を標的にしていました。 このキャンペーンは、脅威アクターの運用アプローチにおける顕著な進化を明らかにしています。直接的な配布手法に依存するのではなく、Evasive PandaはDNSポイズニングと組み合わせたAitM手法を用いて正規のトラフィックを傍受し、被害者を攻撃者が管理するサーバーへリダイレクトする高度に標的化された攻撃を組織的に実行しました。 攻撃者は、SohuVA、iQIYI Video、IObit Smart Defrag、Tencent QQなどの正規アプリケーション更新を装ったローダーを配布し、馴染みのあるソフトウェアベンダーへのユーザーの信頼を悪用して初期のシステムアクセスを確立しました。 技術的高度化 Evasive Pandaのローダーの高度さは、相当な開発投資を示しています。Windows Template Library(WTL)を用いたC++で記述されており、解析を困難にするために複数の暗号化レイヤーと難読化手法を採用しています。 ローダーはXORベースの復号アルゴリズムを使用して、実行後にのみ設定要素を露出させます。また、システムパスやコマンド実行パラメータを含むすべての重要な文字列は、実行時まで暗号化されたままです。 特に注目すべき点として、攻撃者は正規プロセス内でMgBotインプラントをメモリ上で実行可能にする新しいインジェクターを開発しました。 Webリソースからペイロードをダウンロード. 10年前の署名付き実行ファイル(evteng.exe)とDLLサイドローディング手法を活用することで、同グループは主要ペイロードをディスクに書き込むことなく永続的な常駐を実現しました。このアプローチは検知対象領域を大幅に縮小し、フォレンジック調査を複雑化させます。 DNSポイズニングの仕組みは、このキャンペーンで最も革新的な要素です。攻撃者はdictionary.comを含む正規WebサイトのDNS応答を改ざんし、地理的位置やISPの所属に基づいて被害者のシステムを攻撃者管理のインフラへリダイレクトしました。 マルウェアは、これらの汚染されたドメインからPNG画像に偽装された暗号化ペイロードを取得し、ペイロードの選択は被害者のWindowsバージョンとシステム構成に合わせて調整されます。 感染チェーンは多段階実行を採用しています。初期ローダーがシェルコードを復号し、DNSポイズニングされたトラフィックを介して暗号化された第2段階ペイロードを取得します。 傍受と解析を防ぐため、攻撃者はMicrosoftのData Protection API(DPAPI)とRC5暗号を組み合わせたカスタムのハイブリッド暗号を実装しました。 ハイブリッド暗号を用いてペイロードをディスクに保存する一般的な概要. このアプローチにより、ペイロードの復号は侵害されたシステム上でのみ行われ、フォレンジック復旧を試みる防御側に対して非対称な優位性を生み出します。 永続性と帰属 一部の侵害システムでは1年以上にわたりアクティブな感染が維持されており、持続的な運用コミットメントを示しています。 攻撃者は複数のコマンド&コントロール(C2)サーバーを何年にもわたり稼働させており、テイクダウン作戦の可能性があっても制御を維持するために意図的なインフラ冗長性を設計していたことが示唆されます。 注入されたMgBotインプラントにおける設定の復号. Evasive Pandaへの帰属は、過去の作戦との戦術的な一致に基づき、非常に高い確度であるように見えます。 同グループが一貫して用いてきたサプライチェーン侵害、AitM手法、およびウォータリングホール攻撃に加え、設定要素が強化されたMgBotインプラントの再登場は、既知の脅威アクターの行動様式と一致します。 技術的な可視性がある一方で、重要な運用上の空白は残っています。研究者は、Evasive Pandaが大規模にDNSポイズニングを実行するために、どのようにして当初ネットワークインフラを侵害するのかをまだ特定できていません。 考えられるシナリオは2つあります。選択的にISPネットワーク向けのインプラントが展開されたか、あるいは被害者が管理するネットワーク機器(ルーター、ファイアウォール)が個別に侵害されたかです。 このキャンペーンは、Evasive Pandaのツールキットにおける継続的な進化を示しています。新たなローダー開発は、さらなる能力向上が今後も見込まれることを示唆します。 組織は、堅牢なDNS監視、ラテラルムーブメントの可能性を制限するネットワークセグメンテーション、そして多段階シェルコード実行パターンに最適化したエンドポイント検知メカニズムを実装すべきです。 翻訳元:
blackhatnews.tokyo
December 24, 2025 at 6:14 PM
Feed: "Cyber Security News"
By: Priya on Wednesday, December 24, 2025
Evasive Panda exploits network trust using adversary in the middle attacks and DNS poisoning
Evasive Panda adversary - The China-linked advanced persistent threat (APT) group Evasive Panda, also tracked as Bronze Highland, Daggerfly.
cyberpress.org
December 24, 2025 at 4:23 PM
**Evasive Panda APT poisons DNS requests to deliver MgBot**

## Introduction

The Evasive Panda APT group (also known as Bronze Highland, Daggerfly, and StormBamboo) has been active since 2012, targeting multiple industries with sophisticated, evolving tactics […]

[Original post on poliverso.org]
December 24, 2025 at 7:55 AM
I might take another enemy that was planned for later and bring it down a bit? a ranged variant of the Flood Geist.

some kind of ranged enemy in general seems like a good one to go for. maybe have it be evasive but very fragile, like the daggerfly?

or perhaps something extremely slow and bulky?
October 24, 2025 at 12:35 AM
for existing there are:
Drowned Ghoul - basic melee zombies, nothing fancy.
Flood Geist - small and weak. floods the ground around it, making movement more difficult.
Pillar Crab - guarding and two-hit combos.
Daggerfly - extremely fast and weak, inflicts bleed (vulnerability debuff)
October 24, 2025 at 12:35 AM
This was one laid back daggerfly Empis digramma. It was completely unbothered by my manipulations with the Meum blossom to prevent it from swaying in the wind. ISOP web has only thirteen observations and zero in my region, yet they seem pretty common around here. #diptera #insects
June 3, 2025 at 8:22 PM
Daggerfly Empis digramma (Czech: kroužilka) on a blossom of Meum athamanticum (Czech: koprník štětinatý) in Ore Mountains of the Czech Republic. Daggerflies are predators of other arthropods and most also pollinate flowers. Meum is a monotypic genus of highly (and pleasantly) aromatic plants.
May 29, 2025 at 8:09 PM
#Sshdinjector is a #backdoor which injects itself into the SSH daemon, & is used by the #Daggerfly #APT group for espionage purposes. Don't become a victim, deploy our public #YARArules: github.com/reversinglab...

#Malware #Cybersecurity
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules
ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.
github.com
March 28, 2025 at 6:41 PM
中国のサイバー攻撃グループがSSHデーモン侵害するマルウェア利用 - マイナビニュース

Fortinetはこのほど、中国に関係しているとみられる持続的標的型攻撃(APT: Advanced Persistent Threat)グループの「Evasive Panda(別名:Daggerfly)」がSSH ...

news.mynavi.jp/techplus/art...
中国のサイバー攻撃グループがSSHデーモン侵害するマルウェア利用
Fortinetはこのほど、中国に関係しているとみられる持続的標的型攻撃(APT: Advanced Persistent Threat)グループの「Evasive Panda(別名:Daggerfly)」がSSHデーモンを侵害するマルウェア「ELF/Sshdinjector.A!tr」を用いたとして、その調査結果を公表した。
news.mynavi.jp
February 12, 2025 at 11:23 PM
Le groupe chinois DaggerFly cible les appareils Linux avec un backdoor SSH avancé, ELF/Sshdinjector.A!tr, via la campagne Lunar Peek depuis novembre 2024. L'attaque utilise un dropper pour installer des outils compromis, permettant l'exfiltration de données et l'exécution de commandes à distance.
Chinese Hackers Attacking Linux Devices With New SSH Backdoor
Chinese hackers are actively targeting Linux devices with a sophisticated SSH backdoor dubbed ELF/Sshdinjector.A!tr.
cybersecuritynews.com
February 7, 2025 at 10:03 AM
中国のハッカーがビジネスネットワークを狙う効果的な新しいハッキング手法を開発

Chinese hackers develop effective new hacking technique to go after business networks #TechRadar (Feb 5)

#EvasivePanda #Daggerfly #BRONZEHIGHLAND #APTグループ #ネットワーク機器攻撃
Chinese hackers develop effective new hacking technique to go after business networks
Criminals are using new backdoors for persistent access
buff.ly
February 6, 2025 at 10:00 PM
New Fortinet Research Analyzes ELF/Sshdinjector.A!tr
Fortinet’s FortiGuard Labs has released new research on ELF/
New Fortinet Research Analyzes ELF/Sshdinjector.A!tr
Fortinet’s FortiGuard Labs has released new research on ELF/Sshdinjector.A!tr malware, which targets Linux systems, particularly affecting IoT and network appliances. This malware enables data exfiltration and is linked to the DaggerFly espionage group. The research emphasizes the role of AI in reversing engineering malware.
sdx.io
February 6, 2025 at 9:48 PM