Evasive Panda is a China-aligned cyberespionage threat actor, also tracked as Daggerfly and BRONZE HIGHLAND, that has been active since at least 2012. The group is known for long-running intelligence collection operations focused on geopolitical targets, with particular emphasis on Tibetans, the Tibetan diaspora, and organizations of strategic interest to the Chinese state. Evasive Panda has conducted both watering hole and supply-chain compromise operations. In one notable campaign active since at least 2023, the group compromised websites associated with Tibetan communities and a Tibetan-language software developer to distribute trojanized installers for both Windows and macOS. The operation used selective victim filtering and delivered custom malware families including MgBot and the Nightdoor backdoor. The actor demonstrates mature tradecraft across the intrusion lifecycle. Observed techniques include initial access through compromised websites and software distribution channels, DLL side-loading, scheduled-task persistence, code-signing abuse, reflective code loading, process injection, and use of cloud services for command and control. Nightdoor has been observed collecting system, user, and network information, supporting file operations and reverse shell functionality, and enabling staged exfiltration. MgBot and related tooling have also been used to maintain covert access and support post-compromise activity. Evasive Panda’s victimology spans multiple countries in Asia and beyond, including entities in Hong Kong, Macao, Taiwan, India, Myanmar, Vietnam, Malaysia, the Philippines, Nigeria, Australia, and the United States. Its targeting patterns, operational security, and malware development are consistent with a state-linked espionage mission rather than financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader campaign delivered via supply-chain compromise/tainted distribution channels to insert a malicious payload into trusted software, enabling broad victim impact.
Evasive Panda is a Chinese-speaking APT group active since at least 2012, known for cyberespionage campaigns. In this campaign, they targeted Tibetans and related organizations via watering hole and supply-chain attacks, delivering custom malware (MgBot and Nightdoor) to Windows and macOS systems. The group leverages strategic web compromises and trojanized software installers to gain access to victims, focusing on espionage and intelligence collection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.