Friday, August 14, 2026
LIVE
Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///
Subscribe
The Levant
Independent · Digital
The Levant Herald
PoliticsAI-assisted

Evasive Panda APT: Malware Delivery via AitM and DNS Poisoning

## Cybersecurity: Evasive Panda Threat Analysis

Cybersecurity: Evasive Panda Threat Analysis

Evasive Panda, also known as Bronze Highland, Daggerfly, and StormBamboo, has enhanced its threat capabilities through a two-year campaign utilizing advanced techniques such as adversary-in-the-middle (AitM) attacks and DNS poisoning.

Research indicates that from November 2022 to November 2024, the group consistently targeted individuals in Turkey, China, and India with evolving malware delivery methods to avoid detection.

Evasive Panda's loader, developed in C++ using the Windows Template Library (WTL), employs encryption and obfuscation to hinder analysis. It uses XOR-based decryption to reveal configuration elements only during execution, ensuring that critical strings are encrypted until runtime.

The attackers have created an injector that allows the in-memory execution of their MgBot implant within legitimate processes, using DLL sideloading with the signed executable evteng.exe to maintain persistence without writing primary payloads to disk.

Evasive Panda, also known as Bronze Highland, Daggerfly, and StormBamboo, has enhanced its threat capabilities through a two-year campaign utilizing advanced techniques such as adversary-in-the-middle (AitM) attacks and DNS poisoning.
Samira Haddad · The Levant Herald

The campaign's DNS poisoning mechanism targeted legitimate websites, redirecting users to attacker-controlled servers based on their location and ISP. The malware downloaded encrypted payloads disguised as PNG images, with payloads customized to the victim's Windows version and system configuration.

The infection chain involves multi-stage execution, with the initial loader decrypting shellcode and retrieving encrypted payloads via DNS-poisoned traffic. A combination of Microsoft's Data Protection API (DPAPI) and RC5 encryption was utilized to prevent interception and analysis.

Some systems remained compromised for over a year, indicating a sustained commitment to maintaining operations. Multiple command-and-control (C2) servers were active for extended periods, suggesting infrastructure redundancy to withstand potential takedowns.

Advertisement

Attribution to Evasive Panda is supported by tactical similarities with historical operations, including supply-chain compromise, AitM techniques, and watering-hole attacks. Despite detailed visibility, the initial method of network compromise for DNS poisoning remains undetermined, with potential scenarios involving ISP network implants or compromised network devices.

The campaign reflects ongoing evolution in Evasive Panda’s capabilities, suggesting further developments are anticipated. Organizations are advised to implement DNS monitoring, network segmentation, and endpoint detection mechanisms to counteract multi-stage shellcode execution patterns.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories