Also known as: Evasive Panda, BRONZE HIGHLAND, Daggerfly
Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa. Daggerfly is associated with exclusive use of MgBot malware and is noted for several potential supply chain infection campaigns.(Citation: Symantec Daggerfly 2023)(Citation: ESET EvasivePanda 2023)(Citation: Symantec Daggerfly 2024)(Citation: ESET EvasivePanda 2024)
Targeted Sectors
Executive Summary
Daggerfly, also known as Evasive Panda and BRONZE HIGHLAND, is a People's Republic of China-linked Advanced Persistent Threat (APT) group active since at least 2012. Known for targeting government entities, NGOs, and telecommunications companies in Asia and Africa, Daggerfly primarily uses the MgBot malware and has been associated with supply chain infection campaigns. The group employs sophisticated tactics, including code signing abuse and malicious scripts, to maintain persistence and exfiltrate data.
Goals & Targeting
Daggerfly's strategic objectives appear to focus on espionage and intelligence collection, targeting sectors that align with Chinese strategic interests in Asia and Africa. The group's selection of government entities suggests a focus on political and diplomatic intelligence. Their targeting of telecommunication companies may aim to disrupt critical infrastructure or gather sensitive information. The geographic concentration in Asia and Africa likely reflects both regional interests and accessibility to targets.
Enhanced Description
Daggerfly is a state-sponsored APT group attributed to China, operating since at least 2012. The group primarily targets government agencies, non-governmental organizations (NGOs), and telecommunication companies across Asia and Africa. Daggerfly's activity has been linked to several high-profile incidents involving supply chain compromises, where the group seeks to infiltrate systems through third-party software providers. The group is known for using MgBot malware, a versatile backdoor tool designed for long-term persistence and data exfiltration. Additionally, Daggerfly employs various techniques to maintain stealth and evade detection, including the use of legitimate utilities and code signing certificates to disguise malicious activities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Daggerfly has been involved in several long-term campaigns targeting government and telecommunication sectors. The group's operations suggest a patient, strategic approach with a focus on maintaining persistence within targeted networks. Campaign patterns include supply chain infections, where the group compromises third-party vendors to infiltrate downstream customers. Notable past operations involve malicious scripts delivered via spear-phishing emails and legitimate-looking executables.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence provides a comprehensive understanding of Daggerfly's tactics, techniques, and procedures (TTPs). However, specific details about its recent campaigns and exact victimology remain limited. The data is reliable but could benefit from additional context on the group's operational timeline in targeted countries and sectors.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
17
Techniques
4
Tools
0
Campaigns
0
IOCs
0
Observed Data
9
Tactics