MgBot is a modular Windows malware framework closely associated with the China-linked espionage actor Daggerfly, also known as Evasive Panda and Bronze Highland, and has been linked to that actor’s operations since at least 2012. It is designed for long-term intelligence collection and is composed of a dropper, a DLL loader, and multiple plugins that can be selectively deployed to extend functionality during an intrusion.
Observed MgBot capabilities include theft of stored credentials from web browsers and client applications, including browser password stores, email clients, and file transfer tools; theft of browser cookies and session material from Chromium- and Firefox-based browsers; dumping and capture of credentials from process memory; clipboard capture; and audio capture from infected systems. MgBot also supports extensive internal reconnaissance through plugins that enumerate local users and administrators, collect Active Directory domain account information, perform ARP and HTTP-based network scanning, identify server technologies, and gather data from removable media such as USB devices and optical media according to attacker-supplied criteria.
Campaigns using MgBot have targeted telecommunications organizations and appear focused on espionage and information gathering rather than disruptive effects. In documented intrusions, MgBot has been used alongside PlugX loaders, DLL sideloading, and legitimate remote administration software, with operators also leveraging living-off-the-land utilities to stage or retrieve additional tooling. The framework’s plugin-based architecture, breadth of collection modules, and continued operational use indicate an actively maintained malware platform intended to support stealthy post-compromise collection and network situational awareness in enterprise Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group’s most recent campaign using previously unseen plugins from the MgBot malware framework... researchers ... found multiple unique plugins associated with the MgBot modular malware framework on the victim’s network.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Password dumper – cpfwplgx.dll Drops a file to call the MiniDumpWriteDump API to dump a process memory.
MgBot includes modules for dumping and capturing credentials from process memory. Mustang Panda utilized "Hdump" to dump credentials from memory.
QQ Keylogger – kstrcs.dll Keylogger that targets QQEdit.exe and QQ.exe processes.
"APT42 has used custom malware to steal login and cookie data from common browsers." / "...extracts the web session cookie and sends it to the C2 server." / "...stole Chrome browser cookies by copying the Chrome profile directories of targeted users."
Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI.
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Evilnum can collect email credentials from victims... Malteiro has obtained credentials from mail clients via NirSoft MailPassView... MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software... PLEAD has the ability to steal saved passwords from Microsoft Outlook.
Active Directory enumeration – ceeeb.dll Collects the following information from Active directory: Members info Computers Local Admins Remote Desktop Users Dcom Users
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
Network scanner – innocence.dll Capabilities include: arp scan, http scan, determining the type of server (e.g. SQL, WebLogic, Redis, etc.) it is running on.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content notes checks for whether the current user is an administrator or privileged, including 'AsyncRAT can check if the current user of a compromised system is an administrator,' 'Gelsemium has the ability to distinguish between a standard user and an administrator,' and 'Wizard Spider has used whoami to identify the local user and their privileges.'
BADNEWS crawls the victim's local drives and collects documents with selected extensions; Machete searches the file system for files of interest; Rover searches for files on local drives based on a predefined list of file extensions.
Examples include 'Caterpillar WebShell can obtain a list of user accounts from a victim's machine,' 'DRATzarus can obtain a list of users from an infected machine,' 'Woody RAT can retrieve a list of user accounts and usernames from an infected machine,' and 'TrickBot can identify the user and groups the user belongs to on a compromised host.'
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
AppleSeed can find and collect data from removable media devices. APT28 backdoor may collect the entire contents of an inserted USB device. Aria-body has the ability to collect data from USB devices. BADNEWS copies files with certain extensions from USB devices to a predefined directory.
QQ Keylogger – kstrcs.dll Keylogger that targets QQEdit.exe and QQ.exe processes.
Screen and clipboard grabber – cbmrpa.dll Captures clipboard and drag and drop data and saves it to a file.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor delivered via DNS poisoning in a targeted espionage campaign (victims in Türkiye, China, India).
MgBot is a backdoor malware delivered via DNS poisoning by the Evasive Panda APT group.
Backdoor malware used in cyberespionage campaigns, delivered via DNS poisoning techniques.
MgBot is a modular remote access trojan (RAT) used for espionage, featuring keylogging, file theft, command execution, and is delivered via sophisticated DNS poisoning and fake update mechanisms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.