Chinese Hacking Group StormBamboo Strikes Again: Malware Hidden in Software Updates

StormBamboo, also known as Evasive Panda, has hijacked an ISP to poison software updates with malware. By exploiting insecure update mechanisms, they delivered malware like MACMA and POCOSTICK to victims’ devices. This Chinese hacking group has been targeting organizations across multiple countries since at least…

Hot Take:

When life gives you lemons, make lemonade. When cyber-espionage groups give you malware, make sure your DNS requests aren’t being poisoned!

Key Points:

  • StormBamboo, aka Evasive Panda, Daggerfly, and StormCloud, compromised an ISP to deliver malware through poisoned software updates.
  • The group has been active since at least 2012, targeting organizations across various regions, including China, Hong Kong, Macao, and Southeast Asia.
  • Malware such as MACMA and POCOSTICK (MGBot) was deployed by exploiting insecure HTTP update mechanisms lacking digital signature validation.
  • DNS requests were intercepted and malicious IP addresses were injected to deliver payloads from command-and-control servers.
  • Further attacks in 2023 and 2024 targeted international NGOs and organizations in Taiwan using new malware versions.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here