Evasive Panda APT Delivers MgBot Malware via AitM and DNS Poisoning
First seen 24 Dec 2025, 19:09 UTC
•

•81% similarity
•44
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Evasive Panda APT group, also known as Bronze Highland, has been conducting targeted campaigns since November 2022, utilizing adversary-in-the-middle (AitM) attacks and DNS poisoning to deliver the MgBot malware. These operations have affected multiple industries and continued until November 2024.
ThreatCluster AI