Macma Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
December 24, 2025
Last Seen
July 4, 2026

Macma is a malware family tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed December 24, 2025; most recent activity July 4, 2026.

Related Threat Clusters

  • Exploitation of Remote Services in Cyber Attacks

    Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…

    2 articles · Updated June 3, 2026
  • Cyber Adversaries Exploit File Enumeration and Data Collection Techniques

    Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…

    2 articles · Updated April 22, 2026
  • Evasive Panda APT Targets DNS to Deploy MgBot

    The Evasive Panda APT group has conducted targeted campaigns from November 2022 to November 2024, employing adversary-in-the-middle (AitM) attacks. Their tactics included poisoning DNS requests to deliver the MgBot…

    1 article · Updated December 24, 2025

Recent Intelligence Reports

  • T1021 — attack.mitre.org · July 4, 2026
  • T1005 — attack.mitre.org · April 22, 2026
  • Evasive Panda APT poisons DNS requests to deliver MgBot — Securelist · December 24, 2025

CVSS v3.1 Breakdown