No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

China-Linked Cyber Spies Blend Watering Hole, Supply Chain Attacks

March 7, 2024
in Protection
0
China-Linked Cyber Spies Blend Watering Hole, Supply Chain Attacks


A targeted watering-hole cyberattack linked to a Chinese threat group infected visitors to a Buddhism festival website and users of a Tibetan language translation application.

The cyber-operations campaign by the so-called Evasive Panda hacking team began September 2023 or earlier and affected systems in India, Taiwan, Australia, the United States, and Hong Kong, according to new research from ESET.

As part of the campaign, the attackers compromised the websites of an India-based organization that promotes Tibetan Buddhism; a development company that produces Tibetan language translation; and news website Tibetpost, which then unknowingly hosted malicious programs. Visitors to the sites from specific global geographies were infected with droppers and backdoors, including the group’s preferred MgBot as well as a relatively new backdoor program, Nightdoor.

Overall, the group executed an impressive variety of attack vectors in the campaign: an adversary-in-the-middle (AitM) attack via a software update, exploiting a development server; a watering hole; and phishing emails, says ESET researcher Anh Ho, who discovered the attack.

“The fact that they orchestrate both a supply chain and watering-hole attack within the same campaign showcases the resources they have,” he says. “Nightdoor is quite complex, which is technically significant, but in my opinion Evasive Panda’s [most significant] attribute is the variety of the attack vectors they have been able to perform.”

Evasive Panda is a relatively small team typically focused on the surveillance of individuals and organizations in Asia and Africa. The group is associated with attacks on telecommunications firms in 2023, dubbed Operation Tainted Love by SentinelOne, and associated with the attribution group Granite Typhoon, née Gallium, per Microsoft. It’s also known as Daggerfly by Symantec, and it appears to overlap with a cybercriminal and espionage group known by Google Mandiant as APT41.

Watering Holes and Supply Chain Compromises

The group, active since 2012, is well-known for supply chain attacks and for using stolen code-signing credentials and application updates to infect the systems of users in China and Africa in 2023.

In this latest campaign flagged by ESET, the group compromised a website for the Tibetan Buddhist Monlam festival to serve up a backdoor or downloader tool, and planted payloads on a compromised Tibetan news site, according to ESET’s published analysis.

The group also targeted users by compromising a developer of Tibetan translation software with Trojanized applications to infect both Windows and Mac OS systems.

“At this point, it is impossible to know exactly what information they are after, but when the backdoors — Nightdoor or MgBot — are deployed, the victim’s machine is like an open book,” Ho says. “The attacker can access any information they want.”

Evasive Panda has targeted individuals within China for surveillance purposes, including people living in mainland China, Hong Kong, and Macao. The group has also compromised government agencies in China, Macao, and Southeast and East Asian nations.

In the latest attack, the Georgia Institute of Technology was among the organizations attacked in the United States, ESET stated in its analysis.

Cyber Espionage Ties

Evasive Panda has developed its own custom malware framework, MgBot, that implements a modular architecture and has the ability to download addition components, execute code, and steal data. Among other features, MgBot modules can spy on compromised victims and download additional capabilities.

In 2020, Evasive Panda targeted users in India and Hong Kong using the MgBot downloader to deliver final payloads, according to Malwarebytes, which linked the group to previous attacks in 2014 and 2018.

Nightdoor, a backdoor the group introduced in 2020, communicates with a command-and-control server to issue commands, upload data, and create a reverse shell.

The collection of tools — including MgBot, used exclusively by Evasive Panda, and Nightdoor — directly points to the China-linked cyber-espionage group, ESET’s Ho stated in the firm’s published analysis.

“ESET attributes this campaign to the Evasive Panda APT group, based on the malware that was used: MgBot and Nightdoor,” the analysis stated. “Over the past two years, we have seen both backdoors deployed together in an unrelated attack against a religious organization in Taiwan, in which they also shared the same command [and] control server.”



Editorial Team

Editorial Team

Related Posts

You Can Get These Nothing Over-Ear Headphones for $79 Right Now
Protection

You Can Get These Nothing Over-Ear Headphones for $79 Right Now

March 19, 2026
Meta Has Announced the End of the Metaverse, and I'm a Little Sad
Protection

Meta Has Announced the End of the Metaverse, and I’m a Little Sad

March 19, 2026
The New Amazon Echo Studio Speaker Is Under $200 Right Now
Protection

The New Amazon Echo Studio Speaker Is Under $200 Right Now

March 18, 2026
Apple Finally Has a Fix for Your iPhone's Buggy Keyboard
Protection

Apple Finally Has a Fix for Your iPhone’s Buggy Keyboard

March 18, 2026
An Amazon Echo Spot Is Just $50 Right Now
Protection

An Amazon Echo Spot Is Just $50 Right Now

March 18, 2026
Spotify's New 'Exclusive Mode' Can Make Your Music Sound Better, but There's a Catch
Protection

Spotify’s New ‘Exclusive Mode’ Can Make Your Music Sound Better, but There’s a Catch

March 18, 2026
Load More
Next Post
NYCB lost 7% of deposits in one month, highlighting challenges of new rescue

NYCB lost 7% of deposits in one month, highlighting challenges of new rescue

Popular News

  • SEC approves tokenized securities to trade alongside traditional stocks

    SEC approves tokenized securities to trade alongside traditional stocks

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • BlockFi Customers Lose Battle To Recover $300 Million, U.S. Judge Says

    0 shares
    Share 0 Tweet 0
  • The 6 biggest changes to Social Security over the past 20 years that affect how much money you’ll get in retirement

    0 shares
    Share 0 Tweet 0
  • The 10 best banks for college students in 2025

    0 shares
    Share 0 Tweet 0

Latest News

Rivian’s stock is popping as the EV maker becomes the latest to partner with Uber

Rivian’s stock is popping as the EV maker becomes the latest to partner with Uber

March 19, 2026
0

Uber plans to invest as much as $1.25 billion in the EV maker as they partner on robotaxis.

Ethereum Whale Accumulates $111M in ETH After Strategic Sell-Off

Ethereum Whale Accumulates $111M in ETH After Strategic Sell-Off

March 19, 2026
0

A sophisticated crypto trading entity has aggressively purchased 50,706 ETH worth approximately $111.62 million across two wallet addresses, marking a...

Dogecoin price

Dogecoin Is No Longer Bearish: Why Analysts Are Predicting A Better Future

March 19, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure With the recent turn in the tide...

Secondaries market to hit $225bn

Secondaries market to hit $225bn

March 19, 2026
0

Private markets secondaries volumes are set to surpass $225bn (£169.5bn) in 2025, driven by a continuation of slow distributions and...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.