Names | Bronze Highland (SecureWorks) Evasive Panda (Malwarebytes) Daggerfly (Symantec) | |
Country | ![]() | |
Motivation | Information theft and espionage | |
First seen | 2012 | |
Description | (SecureWorks) BRONZE HIGHLAND has been observed using spearphishing as an initial infection vector to deploy the MgBot remote access trojan against targets in Hong Kong. Third party reporting suggests the threat group also targets India, Malaysia and Taiwan and leverages Cobalt Strike and KsRemote Android Rat. CTU researchers assess with moderate confidence that BRONZE HIGHLAND operates on behalf of China and has a remit covering espionage against domestic human rights and pro-democracy advocates and nations neighbouring China. | |
Observed | Sectors: Telecommunications and human rights and pro-democracy advocates. Countries: China, Hong Kong, India, Macao, Malaysia, Myanmar, Nigeria, Philippines, Taiwan, Vietnam and Africa. | |
Tools used | Cobalt Strike, MgBot, KsRemote, Living off the Land. | |
Operations performed | 2020 | Evasive Panda APT group delivers malware via updates for popular Chinese software <https://www.welivesecurity.com/2023/04/26/evasive-panda-apt-group-malware-updates-popular-chinese-software/> |
Nov 2022 | Daggerfly: APT Actor Targets Telecoms Company in Africa <https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/apt-attacks-telecoms-africa-mgbot> | |
Information | <https://www.secureworks.com/research/threat-profiles> <https://blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-group-targets-india-and-hong-kong-using-new-variant-of-mgbot-malware/> <https://vb2020.vblocalhost.com/uploads/VB2020-43.pdf> |
Last change to this card: 21 June 2023
Digital Service Security Center Follow us on![]() ![]() |
Report incidents |
|
![]() |
+66 (0)2-123-1227 | |
![]() |
[email protected] |