MgBot Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
11
occurrences
First Seen
December 24, 2025
Last Seen
July 23, 2026

MgBot is a backdoor/malware linked to China-state–affiliated APT operations (notably Evasive Panda and related China-Nexus activities) that is deployed against targets in Asia, including South Asia telecoms.

Overview

MgBot is a backdoor/malware linked to China-state–affiliated APT operations (notably Evasive Panda and related China-Nexus activities) that is deployed against targets in Asia, including South Asia telecoms. It is primarily delivered through DNS poisoning and related man-in-the-middle techniques to drop a persistent backdoor, enabling espionage and data exfiltration. Its significance lies in the use of DNS-based delivery to bypass defenses and extend access for ongoing intelligence-gathering campaigns.

Related Threat Clusters

Recent Intelligence Reports

  • T1539 — attack.mitre.org · July 23, 2026
  • T1005 — attack.mitre.org · April 22, 2026
  • China-Nexus Espionage APT Targets South Asia Telecoms — Technadu · January 9, 2026
  • SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 78 — Securityaffairs.Co · January 4, 2026
  • China-Linked Evasive Panda Uses DNS Poisoning to Deploy MgBot Malware — Varindia · January 1, 2026
  • HoneyMyte APT Campaign Uses Kernel-Mode Rootkit to Deploy ToneShell — Technadu · December 29, 2025
  • Evasive Panda cyberespionage campaign uses DNS poisoning to install MgBot backdoor — Securityaffairs.Co · December 29, 2025
  • Scams target MENA region, pen testers accused of blackmail, DDoS protection faces fresh ... — Linkedin · December 25, 2025

CVSS v3.1 Breakdown