MgBot is a malware family tracked across 9 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed December 24, 2025; most recent activity April 22, 2026.
MgBot is a backdoor/malware linked to China-state–affiliated APT operations (notably Evasive Panda and related China-Nexus activities) that is deployed against targets in Asia, including South Asia telecoms. It is primarily delivered through DNS poisoning and related man-in-the-middle techniques to drop a persistent backdoor, enabling espionage and data exfiltration. Its significance lies in the use of DNS-based delivery to bypass defenses and extend access for ongoing intelligence-gathering campaigns.
A new threat actor, UAT-7290, has been identified conducting cyberattacks on telecommunications infrastructure in South Asia. This operation is linked to a China-Nexus state-sponsored advanced persistent threat (APT)…
The HoneyMyte APT group has developed a new cyberespionage campaign utilizing a malicious kernel-mode driver to deploy the ToneShell backdoor. This driver, signed with a stolen digital certificate, operates as a rootkit…
The China-linked APT group Evasive Panda has conducted cyber-espionage campaigns using DNS poisoning to install the MgBot backdoor. Targeted victims include entities in Türkiye, China, and India. Kaspersky researchers…
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
The Evasive Panda APT group, also known as Bronze Highland, has been conducting targeted campaigns since November 2022, utilizing adversary-in-the-middle (AitM) attacks and DNS poisoning to deliver the MgBot malware.…
The Evasive Panda APT group has conducted targeted campaigns from November 2022 to November 2024, employing adversary-in-the-middle (AitM) attacks. Their tactics included poisoning DNS requests to deliver the MgBot…
Evasive Panda, an advanced persistent threat group, has been conducting a targeted cyberespionage campaign in Asia for two years. The group utilizes adversary-in-the-middle (AitM) and DNS poisoning techniques to…
In 2025, Group-IB reported over 1,500 fraudulent job advertisements targeting the MENA region, particularly Egypt and Gulf states. Scammers exploited the demand for remote work, using localized language and familiar…
APT group Evasive Panda is using DNS poisoning to deliver MgBot malware, targeting U.S. and allied manufacturing and healthcare organizations. Additionally, a spearphishing campaign is exploiting the npm registry to…