Mgbot

Malware updated 4 days ago (2024-11-29T14:04:41.610Z)
Download STIX
Preview STIX
MgBot is a malicious software (malware) discovered by ESET, designed to exploit and damage computer systems. It can infiltrate systems via suspicious downloads, emails, or websites, often unbeknownst to the user. Once inside, it's capable of stealing personal information, disrupting operations, and potentially holding data hostage for ransom. The malware's operations spanned from 2022 to 2023, during which time it demonstrated several advanced capabilities, such as self-uninstallation, file deletion, system information collection, registry modification for persistence, User Account Control (UAC) bypassing, and replacing the existing Application Management service DLL path with its own. MgBot's installer uses Windows APIs to create processes, and it operates as a Windows service. The malware's loader components inject themselves into svchost.exe, from where they load either Nightdoor or MgBot backdoors. These backdoors allow the malware to exfiltrate collected data to its Command and Control (C&C) servers via UDP communication protocol. Furthermore, MgBot has been observed exploiting session cookies stolen by its plugins to access Google Drive, Gmail, and Outlook accounts without the need for direct authentication, revealing an intricate integration with CloudScout's operations. Evasive Panda, another cyber threat actor, seamlessly integrated with MgBot, further expanding the malware's reach and effectiveness. This entity acquired servers for the C&C infrastructure of Nightdoor, MgBot, and the macOS downloader component, highlighting the broad spectrum of threats posed by this collaboration. Given the sophistication and potential harm caused by MgBot, it's crucial for organizations to implement robust cybersecurity measures to detect and mitigate such threats promptly.
Description last updated: 2024-10-29T20:13:18.313Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Nightdoor is a possible alias for Mgbot. Nightdoor is a sophisticated malware developed by the threat group Evasive Panda. This malicious software, designed to exploit and damage computer systems, was first detected in 2022 alongside MgBot, another custom implant developed by the same group. The primary function of Nightdoor is to infiltra
4
MacMa is a possible alias for Mgbot. Macma is a malware, first detailed by Google in 2021, that has been used since at least 2019. It is a modular backdoor that supports multiple functionalities such as device fingerprinting, executing commands, screen capture, keylogging, audio capture, and uploading and downloading files. Macma, ofte
4
Pocostick is a possible alias for Mgbot. Pocostick, also known as MGBot, is a type of malware that exploits and damages computer systems. This malicious software infiltrates systems through suspicious downloads, emails, or websites, often unbeknownst to the user. Once inside, it can steal personal information, disrupt operations, or even h
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Backdoor
Apt
Evasive
Windows
Macos
Dropper
Downloader
Chinese
Eset
Tool
Symantec
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The Evasive Panda Threat Actor is associated with Mgbot. Evasive Panda, also known as StormBamboo, Daggerfly, or Bronze Highland, is a threat actor group linked to China that has been operating since at least 2012. The group primarily focuses on cyber espionage against civil society targets and has demonstrated significant technical capabilities. They havUnspecified
5
The Daggerfly Threat Actor is associated with Mgbot. DaggerFly, also known as Evasive Panda and StormBamboo, is a Chinese-speaking Advanced Persistent Threat (APT) group that has been active since at least 2012. The group is recognized for its cyber espionage activities against individuals and organizations in mainland China, Hong Kong, Macao, NigeriaUnspecified
4
The Bronze Highland Threat Actor is associated with Mgbot. Bronze Highland, also known as Evasive Panda and Daggerfly, is a China-linked Advanced Persistent Threat (APT) group that has been active since at least 2012. The group primarily conducts cyber espionage against individuals in mainland China, Hong Kong, Macao, and Nigeria, as well as certain organizUnspecified
3
Source Document References
Information about the Mgbot Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
DARKReading
a month ago
InfoSecurity-magazine
a month ago
ESET
a month ago
Securityaffairs
2 months ago
DARKReading
4 months ago
InfoSecurity-magazine
4 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago
DARKReading
4 months ago
InfoSecurity-magazine
4 months ago
BankInfoSecurity
4 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
CERT-EU
9 months ago
InfoSecurity-magazine
9 months ago
CERT-EU
9 months ago
DARKReading
9 months ago
CERT-EU
a year ago