MgBot Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
December 24, 2025
Last Seen
April 22, 2026

MgBot is a malware family tracked across 9 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed December 24, 2025; most recent activity April 22, 2026.

Overview

MgBot is a backdoor/malware linked to China-state–affiliated APT operations (notably Evasive Panda and related China-Nexus activities) that is deployed against targets in Asia, including South Asia telecoms. It is primarily delivered through DNS poisoning and related man-in-the-middle techniques to drop a persistent backdoor, enabling espionage and data exfiltration. Its significance lies in the use of DNS-based delivery to bypass defenses and extend access for ongoing intelligence-gathering campaigns.

Related Threat Clusters

Recent Intelligence Reports

  • T1005 — attack.mitre.org · April 22, 2026
  • China-Nexus Espionage APT Targets South Asia Telecoms — Technadu · January 9, 2026
  • SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 78 — Securityaffairs.Co · January 4, 2026
  • China-Linked Evasive Panda Uses DNS Poisoning to Deploy MgBot Malware — Varindia · January 1, 2026
  • HoneyMyte APT Campaign Uses Kernel-Mode Rootkit to Deploy ToneShell — Technadu · December 29, 2025
  • Evasive Panda cyberespionage campaign uses DNS poisoning to install MgBot backdoor — Securityaffairs.Co · December 29, 2025
  • Scams target MENA region, pen testers accused of blackmail, DDoS protection faces fresh ... — Linkedin · December 25, 2025
  • Evasive Panda APT Using AitM Attack and DNS Poisoning to Deliver Malware — Cybersecuritynews · December 24, 2025

CVSS v3.1 Breakdown