The Evasive Panda advanced persistent threat (APT) group, also known as Bronze Highland, Daggerfly, and StormBamboo, has conducted targeted campaigns since November 2022 using sophisticated adversary-in-the-middle (AitM) attacks and DNS poisoning to deliver the MgBot malware. The group targets victims in Türkiye, China, and India by disguising malicious executables as legitimate software updates for popular applications such as SohuVA, iQIYI Video, IObit Smart Defrag, and Tencent QQ. Attackers manipulate DNS responses to redirect update requests to attacker-controlled servers, where users unknowingly download malware-laden packages like sohuva_update_10.2.29.1-lup-s-tp.exe. The malware employs advanced evasion techniques, including encrypted payload delivery, memory injection via DLL sideloading, and hybrid encryption to make detection and analysis more difficult.
Technical analysis reveals that the initial loader decrypts its configuration and shellcode using XOR-based algorithms, checks for SYSTEM privileges, and leverages the VirtualProtect API to execute code stealthily. The group stores encrypted malware components on their servers, which are resolved through poisoned DNS responses, further complicating detection. The MgBot implant is injected into legitimate processes, allowing the attackers to maintain persistence and evade security controls for extended periods. Indicators of compromise and further technical details are available through specialized threat intelligence services.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
In June 2025, Kaspersky reported on the campaign and assessed with high confidence that it was conducted by Evasive Panda, also known as Bronze Highland, Daggerfly, and StormBamboo. The attribution was based on the observed tactics, techniques, and procedures and the use of the MgBot malware family.
Kaspersky's reporting indicates the documented activity it analyzed was observed from November 2022 through November 2024. This marks the end of the specific campaign period covered in the research.
Across the November 2022 to November 2024 campaign window, victims were observed in Türkiye, China, and India, with some systems remaining under attacker control for more than a year. The operators maintained multiple command-and-control IPs and used per-victim encryption to support long dwell time and hinder analysis.
As the operation evolved, Evasive Panda used a multi-stage loader with shellcode, XOR/LZMA obfuscation, API hashing, and hybrid encryption to fetch and execute payloads with minimal disk artifacts. The final stage loaded the MgBot implant in memory through DLL sideloading into a signed older Python wrapper executable, then injected into legitimate processes such as svchost.exe.
During the campaign, the group abused legitimate platforms and update mechanisms, including requests for dictionary.com and software such as SohuVA, iQIYI, IObit Smart Defrag, and Tencent QQ, to deliver staged malware. Redirection and payload delivery were tailored by victim geography or ISP, complicating detection and investigation.
Evasive Panda began a highly targeted campaign in November 2022, using adversary-in-the-middle techniques likely involving DNS poisoning to redirect legitimate software update requests to attacker-controlled infrastructure. Early delivery chains impersonated trusted software updaters to infect selected victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcesecurityonline.info
Open sourcecybersecuritynews.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.