ATT&CKReferencesESET EvasivePanda 2023

ESET EvasivePanda 2023

Facundo Muñoz. (2023, April 26). Evasive Panda APT group delivers malware via updates for popular Chinese software. Retrieved July 25, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareMgBot

MgBot includes modules for collecting files from local systems based on a given set of properties and filenames.

T1025
Data from Removable Media
MalwareMgBot

MgBot includes modules capable of gathering information from USB thumb drives and CD-ROMs on the victim machine given a list of provided criteria.

T1056.001
Keylogging
MalwareMgBot

MgBot includes keylogger payloads focused on the QQ chat application.

T1115
Clipboard Data
MalwareMgBot

MgBot can capture clipboard data.

T1123
Audio Capture
MalwareMgBot

MgBot can capture input and output audio streams from infected devices.

T1195.002
Compromise Software Supply Chain
GroupDaggerfly

Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims.

T1213.006
Databases
MalwareMgBot

MgBot includes a module capable of stealing content from the Tencent QQ database storing user QQ message history on infected devices.

T1539
Steal Web Session Cookie
MalwareMgBot

MgBot includes modules that can steal cookies from Firefox, Chrome, and Edge web browsers.

T1555
Credentials from Password Stores
MalwareMgBot

MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software.

T1555.003
Credentials from Web Browsers
MalwareMgBot

MgBot includes modules for stealing credentials from various browsers and applications, including Chrome, Opera, Firefox, Foxmail, QQBrowser, FileZilla, and WinSCP.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.