MgBot, also known as POCOSTICK, is a modular Windows backdoor framework uniquely associated with the China-linked Daggerfly threat actor, also tracked as Evasive Panda and Bronze Highland, since at least 2012. It comprises a dropper, DLL loader, and extensible plugins, and has been used in cyberespionage operations including attacks against telecommunications organizations in Africa and organizations in Asia. MgBot plugins support network and service scanning, Active Directory and local-account enumeration, browser-data and browser-cookie theft, credential theft from browsers, email clients, and file-transfer applications, process-memory credential dumping, keylogging, clipboard collection, removable-media collection, and audio capture. MgBot has been delivered to Windows systems through compromised insecure software-update workflows involving ISP-level DNS poisoning, and has also been observed alongside DLL side-loading and PlugX loader activity in Daggerfly intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Daggerfly is known for exclusively using MgBot malware; the observed Linux implants attributed to the group function as backdoors embedding themselves in crond, sshd, and netstat binaries and services.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The installer eventually downloads either MGBot malware for Windows or MACMA for macOS. MgBOT is a modular framework with various plugins enabling network scanning, information stealing from browser, keylogging and password dumping.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Password dumper – cpfwplgx.dll Drops a file to call the MiniDumpWriteDump API to dump a process memory.
MgBot includes modules for dumping and capturing credentials from process memory. Mustang Panda utilized "Hdump" to dump credentials from memory.
MgBOT ... enables ... keylogging and password dumping. MACMA is able to perform device fingerprinting, keylogging, executing commands, screen and audio capture.
"APT42 has used custom malware to steal login and cookie data from common browsers." / "...extracts the web session cookie and sends it to the C2 server." / "...stole Chrome browser cookies by copying the Chrome profile directories of targeted users."
Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI.
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Evilnum can collect email credentials from victims... Malteiro has obtained credentials from mail clients via NirSoft MailPassView... MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software... PLEAD has the ability to steal saved passwords from Microsoft Outlook.
Active Directory enumeration – ceeeb.dll Collects the following information from Active directory: Members info Computers Local Admins Remote Desktop Users Dcom Users
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
Network scanner – innocence.dll Capabilities include: arp scan, http scan, determining the type of server (e.g. SQL, WebLogic, Redis, etc.) it is running on.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content notes checks for whether the current user is an administrator or privileged, including 'AsyncRAT can check if the current user of a compromised system is an administrator,' 'Gelsemium has the ability to distinguish between a standard user and an administrator,' and 'Wizard Spider has used whoami to identify the local user and their privileges.'
BADNEWS crawls the victim's local drives and collects documents with selected extensions; Machete searches the file system for files of interest; Rover searches for files on local drives based on a predefined list of file extensions.
Examples include 'Caterpillar WebShell can obtain a list of user accounts from a victim's machine,' 'DRATzarus can obtain a list of users from an infected machine,' 'Woody RAT can retrieve a list of user accounts and usernames from an infected machine,' and 'TrickBot can identify the user and groups the user belongs to on a compromised host.'
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
AppleSeed can find and collect data from removable media devices. APT28 backdoor may collect the entire contents of an inserted USB device. Aria-body has the ability to collect data from USB devices. BADNEWS copies files with certain extensions from USB devices to a predefined directory.
MgBOT ... enables ... keylogging and password dumping. MACMA is able to perform device fingerprinting, keylogging, executing commands, screen and audio capture.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor delivered via DNS poisoning in a targeted espionage campaign (victims in Türkiye, China, India).
MgBot is a backdoor malware delivered via DNS poisoning by the Evasive Panda APT group.
Backdoor malware used in cyberespionage campaigns, delivered via DNS poisoning techniques.
MgBot is a modular remote access trojan (RAT) used for espionage, featuring keylogging, file theft, command execution, and is delivered via sophisticated DNS poisoning and fake update mechanisms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.