Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Daggerfly

Also known as: Evasive Panda, BRONZE HIGHLAND, Daggerfly

Description

Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa. Daggerfly is associated with exclusive use of MgBot malware and is noted for several potential supply chain infection campaigns.(Citation: Symantec Daggerfly 2023)(Citation: ESET EvasivePanda 2023)(Citation: Symantec Daggerfly 2024)(Citation: ESET EvasivePanda 2024)

Goals & Targeting

Targeted Sectors

Government

AI Analysis

· 1 week ago

Executive Summary

Daggerfly, also known as Evasive Panda and BRONZE HIGHLAND, is a People's Republic of China-linked Advanced Persistent Threat (APT) group active since at least 2012. Known for targeting government entities, NGOs, and telecommunications companies in Asia and Africa, Daggerfly primarily uses the MgBot malware and has been associated with supply chain infection campaigns. The group employs sophisticated tactics, including code signing abuse and malicious scripts, to maintain persistence and exfiltrate data.

Goals & Targeting

Daggerfly's strategic objectives appear to focus on espionage and intelligence collection, targeting sectors that align with Chinese strategic interests in Asia and Africa. The group's selection of government entities suggests a focus on political and diplomatic intelligence. Their targeting of telecommunication companies may aim to disrupt critical infrastructure or gather sensitive information. The geographic concentration in Asia and Africa likely reflects both regional interests and accessibility to targets.

Enhanced Description

Daggerfly is a state-sponsored APT group attributed to China, operating since at least 2012. The group primarily targets government agencies, non-governmental organizations (NGOs), and telecommunication companies across Asia and Africa. Daggerfly's activity has been linked to several high-profile incidents involving supply chain compromises, where the group seeks to infiltrate systems through third-party software providers. The group is known for using MgBot malware, a versatile backdoor tool designed for long-term persistence and data exfiltration. Additionally, Daggerfly employs various techniques to maintain stealth and evade detection, including the use of legitimate utilities and code signing certificates to disguise malicious activities.

Key Capabilities

  • Use of MgBot malware for long-term persistence
  • Supply chain infection campaigns
  • Code signing abuse
  • Abuse of legitimate tools (e.g., rundll32)
  • Malicious scripts delivered via PowerShell
  • DLL injection techniques
  • Scheduled task creation

MITRE ATT&CK Tactics

Persistence
Defense Evasion
Credential Access
Discovery
Lateral Movement
Exfiltration
Collection
Impact
Reconnaissance
Initial Access

ATT&CK Techniques

T1053.005
T1218.011
T1003.002
T1574.001
T1553.002
T1587.002
T1082
T1136.001
T1059.001
T1195.002
T1036.003
T1012
T1189
T1071.001
T1584.004
T1105
T1204.001

Software / Tooling

MgBot
Nightdoor
PlugX
MacMa

Campaigns & Victims

Daggerfly has been involved in several long-term campaigns targeting government and telecommunication sectors. The group's operations suggest a patient, strategic approach with a focus on maintaining persistence within targeted networks. Campaign patterns include supply chain infections, where the group compromises third-party vendors to infiltrate downstream customers. Notable past operations involve malicious scripts delivered via spear-phishing emails and legitimate-looking executables.

IOC Patterns

  • Malware distribution through supply chain infections
  • Use of rundll32 for execution
  • Scheduled task creation with legitimate tools
  • DLL injection techniques
  • Abuse of code signing certificates

Recommended Actions

  • Implement supply chain security measures to detect and mitigate third-party compromises.
  • Monitor network traffic for unusual script executions (e.g., PowerShell, CMD).
  • Deploy endpoint detection and response (EDR) solutions to identify and block known Daggerfly TTPs.
  • Conduct regular audits of scheduled tasks and legitimate utilities for signs of unauthorized activity.

Suggested Tags

APT
China-linked
Government targeting
Espionage
Supply chain attacks

Confidence Assessment

The available intelligence provides a comprehensive understanding of Daggerfly's tactics, techniques, and procedures (TTPs). However, specific details about its recent campaigns and exact victimology remain limited. The data is reliable but could benefit from additional context on the group's operational timeline in targeted countries and sectors.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. ESET EvasivePanda 2024 — Ahn Ho, Facundo Muñoz, & Marc-Etienne M.Léveillé. (2024, March 7). Evasive Panda leverages Monlam Festival to target Tibetans. Retrieved July 25, 2024.
  2. ESET EvasivePanda 2023 — Facundo Muñoz. (2023, April 26). Evasive Panda APT group delivers malware via updates for popular Chinese software. Retrieved July 25, 2024.
  3. Symantec Daggerfly 2023 — Threat Hunter Team. (2023, April 20). Daggerfly: APT Actor Targets Telecoms Company in Africa. Retrieved July 25, 2024.
  4. Symantec Daggerfly 2024 — Threat Hunter Team. (2024, July 23). Daggerfly: Espionage Group Makes Major Update to Toolset. Retrieved July 25, 2024.

Intel Summary

17

Techniques

4

Tools

0

Campaigns

0

IOCs

0

Observed Data

9

Tactics

Tags

APT
Critical Infrastructure
Supply Chain Attack
Government Targeting
China-linked
Government targeting
Espionage
Supply chain attacks

Details

MITRE ID
G1034
Type
Unknown
Country of Origin
C
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--f3be6240-f68e-47e1-90d2-ad8f3b3bb8a6
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.