The HoneyMyte APT group has developed a new cyberespionage campaign utilizing a malicious kernel-mode driver to deploy the ToneShell backdoor. This driver, signed with a stolen digital certificate, operates as a rootkit…
The China-linked APT group Evasive Panda has conducted cyber-espionage campaigns using DNS poisoning to install the MgBot backdoor. Targeted victims include entities in Türkiye, China, and India. Kaspersky researchers…
The Evasive Panda APT group, also known as Bronze Highland, has been conducting targeted campaigns since November 2022, utilizing adversary-in-the-middle (AitM) attacks and DNS poisoning to deliver the MgBot malware.…
Evasive Panda, an advanced persistent threat group, has been conducting a targeted cyberespionage campaign in Asia for two years. The group utilizes adversary-in-the-middle (AitM) and DNS poisoning techniques to…
In 2025, Group-IB reported over 1,500 fraudulent job advertisements targeting the MENA region, particularly Egypt and Gulf states. Scammers exploited the demand for remote work, using localized language and familiar…
APT group Evasive Panda is using DNS poisoning to deliver MgBot malware, targeting U.S. and allied manufacturing and healthcare organizations. Additionally, a spearphishing campaign is exploiting the npm registry to…