{"id":4608,"date":"2024-07-23T14:39:56","date_gmt":"2024-07-23T19:39:56","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/china-evasive-panda-apt-spies-taiwan-targets-across-platforms"},"modified":"2024-07-23T14:39:56","modified_gmt":"2024-07-23T19:39:56","slug":"chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/23\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms\/","title":{"rendered":"China&#8217;s &#8216;Evasive Panda&#8217; APT Spies on Taiwan Targets Across Platforms"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt4fffe0cfbde74594\/66a00132a5606cc35e3af6b5\/China_Taiwan-Christophe_Coat-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A Chinese advanced persistent threat (APT) is upgrading its espionage capabilities by developing and iterating on malware across operating systems (OSes).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Evasive Panda \u2014 which Symantec tracks as &#8220;Daggerfly&#8221; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/symantec-enterprise-blogs.security.com\/threat-intelligence\/daggerfly-espionage-updated-toolset\" rel=\"noopener\">in a new blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 has been known to target telecommunications companies, government agencies, NGOs, universities, and private individuals of interest to the Chinese state. Recently it has carried out a handful of attacks against similar targets, mostly located in Taiwan, plus one American non-governmental organization (NGO) based in China.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Though its victims are predictable, the platforms it targets for its chicanery are varied. Besides Windows and macOS, Symantec found evidence of Evasive Panda Trojanizing Android Package Kits (APKs), developing SMS and DNS request interception tools, and developing malware families around Linux and even Solaris OS.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Their ability to develop malware for multiple different platforms is noteworthy,&#8221; says Dick O&#8217;Brien, principal intelligence analyst for the Symantec threat hunter team. &#8220;It&#8217;s not uncommon to see APT groups targeting two or three different platforms, but this group has the ambition and the skills to target every major platform, including some pretty niche ones like Solaris. That\u2019s not something you see very often.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Daggerfly's Diverse Devices\">Daggerfly&#8217;s Diverse Devices<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Evasive Panda is at least a decade old. To keep things fresh after that long a time, it develops and builds on a variety of custom malware tools designed for different operating systems. Underpinning them all is a shared library or framework.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Its best known tool incorporating this shared code is the modular MgBot malware. MgBot has been used recently in attacks against the China-based American NGO, an African telecoms operator in 2023, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/china-linked-cyber-spies-blend-watering-hole-supply-chain-attacks\" rel=\"noopener\">watering hole attacks late last year<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, where it worked alongside a newer tool, &#8220;Nightdoor,&#8221; tracked by Symantec as &#8220;Trojan.Suzafk.&#8221;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Nightdoor is loaded onto newly infected systems alongside the legitimate DAEMON Tools Lite program for creating and mounting virtual disk drives, and a dynamic link library (DLL) that establishes persistence via scheduled tasks. The final payload \u2014 a multistage backdoor \u2014 uses TCP or OneDrive for command-and-control (C2), and comes embedded with the open source (OSS) tool &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/github.com\/LordNoteworthy\/al-khaser\" rel=\"noopener\">al-khaser<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&#8221; Al-khaser markets itself as a proof-of-concept (PoC) application &#8220;that aims to stress your anti-malware system&#8221; by incorporating various anti-analysis tricks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When Evasive Panda wants to attack a Mac, it uses <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/new-mac-malware-samples-underscore-growing-threat\" rel=\"noopener\">Macma<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, a backdoor celebrating a half-decade in the wild this year. Like its Windows cousins, Macma has been used in various watering hole attacks. In 2021, for instance, it was <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/mac-os-0-day-used-in-watering-hole-attacks\" rel=\"noopener\">deployed against media and protestors<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> fighting for an independent Hong Kong. It can fingerprint devices, upload and download files from them, capture keystrokes, screenshots, and audio, and more.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Recently, on top of developing new backdoors, Evasive Panda has updated Macma in a variety of mostly minor ways. That, O&#8217;Brien says, &#8220;shows evidence of ongoing, iterative development. While some of these tweaks may help in avoiding detection, by subtly altering the malware&#8217;s fingerprint, the main thing this tells us is that they have that capacity for continuous development, where they can continually roll out new versions, making small improvements and fixing bugs.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/china-evasive-panda-apt-spies-taiwan-targets-across-platforms\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Chinese advanced persistent threat (APT) is upgrading its espionage<\/p>\n","protected":false},"author":12,"featured_media":4609,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4608","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/chinas-evasive-panda-apt-spies-on-taiwan-targets-across-platforms-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4608","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4608"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4608\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4609"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4608"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4608"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4608"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}