IQIYI — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 24, 2025
Last Seen
December 24, 2025

iQIYI is a Chinese online video platform and streaming service.

Overview

iQIYI is a Chinese online video platform and streaming service. A recent campaign attributed to the Evasive Panda APT used DNS poisoning to deliver MgBot to iQIYI, highlighting the actor's ability to leverage DNS manipulation to deploy malware against high-profile media platforms and the ongoing risk of APT activity targeting such services.

Related Threat Clusters

  • Evasive Panda APT Targets DNS to Deploy MgBot

    The Evasive Panda APT group has conducted targeted campaigns from November 2022 to November 2024, employing adversary-in-the-middle (AitM) attacks. Their tactics included poisoning DNS requests to deliver the MgBot…

    1 article · Updated December 24, 2025

Recent Intelligence Reports

  • Evasive Panda APT poisons DNS requests to deliver MgBot — Securelist · December 24, 2025

CVSS v3.1 Breakdown