ATT&CKGroupsDaggerfly

Daggerfly

G1034

Threat group.View on attack.mitre.org

About this group

Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa. Daggerfly is associated with exclusive use of MgBot malware and is noted for several potential supply chain infection campaigns.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1003.002
Security Account Manager

Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction.

T1012
Query Registry

Daggerfly used Reg to dump the Security Account Manager (SAM), System, and Security Windows registry hives from victim machines.

T1036.003
Rename Legitimate Utilities

Daggerfly used a renamed version of rundll32.exe, such as "dbengin.exe" located in the `ProgramData\Microsoft\PlayReady` directory, to proxy malicious DLL execution.

T1053.005
Scheduled Task

Daggerfly has attempted to use scheduled tasks for persistence in victim environments.

T1059.001
PowerShell

Daggerfly used PowerShell to download and execute remote-hosted files on victim systems.

T1071.001
Web Protocols

Daggerfly uses HTTP for command and control communication.

T1082
System Information Discovery

Daggerfly utilizes victim machine operating system information to create custom User Agent strings for subsequent command and control communication.

T1105
Ingress Tool Transfer

Daggerfly has used PowerShell and BITSAdmin to retrieve follow-on payloads from external locations for execution on victim machines.

T1136.001
Local Account

Daggerfly created a local account on victim machines to maintain access.

T1189
Drive-by Compromise

Daggerfly has used strategic website compromise for initial access against victims.

T1195.002
Compromise Software Supply Chain

Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims.

T1204.001
Malicious Link

Daggerfly has used strategic website compromise to deliver a malicious link requiring user interaction.

T1218.011
Rundll32

Daggerfly proxied execution of malicious DLLs through a renamed rundll32.exe binary.

T1553.002
Code Signing

Daggerfly has used signed, but not notarized, malicious files for execution in macOS environments.

T1574.001
DLL

Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. Daggerfly is also linked to multiple other instances of side-loading for initial loading activity.

View all 17 procedure examples

Software6

Campaigns0

None recorded.

References4

  1. ESET EvasivePanda 2023 Open source
    Facundo Muñoz. (2023, April 26). Evasive Panda APT group delivers malware via updates for popular Chinese software. Retrieved July 25, 2024.
  2. ESET EvasivePanda 2024 Open source
    Ahn Ho, Facundo Muñoz, & Marc-Etienne M.Léveillé. (2024, March 7). Evasive Panda leverages Monlam Festival to target Tibetans. Retrieved July 25, 2024.
  3. Symantec Daggerfly 2023 Open source
    Threat Hunter Team. (2023, April 20). Daggerfly: APT Actor Targets Telecoms Company in Africa. Retrieved July 25, 2024.
  4. Symantec Daggerfly 2024 Open source
    Threat Hunter Team. (2024, July 23). Daggerfly: Espionage Group Makes Major Update to Toolset. Retrieved July 25, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.