<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/china-linked-hackers-compromise-isp-to-deploy-malware-via-software-updates-09xwc6tm6" -->

---
title: China-Linked Hackers Compromise ISP to Deploy Malware...
description: China-linked hacker group Evasive Panda compromised an ISP in mid-2023 to deploy malicious software updates through manipulated DNS query responses. By...
canonical: https://daily.dev/posts/china-linked-hackers-compromise-isp-to-deploy-malware-via-software-updates-09xwc6tm6
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: China-Linked Hackers Compromise ISP to Deploy Malware via Software Updates | daily.dev
og:description: China-linked hacker group Evasive Panda compromised an ISP in mid-2023 to deploy malicious software updates through manipulated DNS query responses. By...
og:url: https://daily.dev/posts/china-linked-hackers-compromise-isp-to-deploy-malware-via-software-updates-09xwc6tm6
og:image: https://api.daily.dev/og/posts/09XwC6Tm6.png
og:image:alt: China-Linked Hackers Compromise ISP to Deploy Malware via Software Updates
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# China-Linked Hackers Compromise ISP to Deploy Malware via Software Updates

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 3 upvotes · 0 comments

## Summary

China-linked hacker group Evasive Panda compromised an ISP in mid-2023 to deploy malicious software updates through manipulated DNS query responses. By targeting insecure software update mechanisms, they delivered malware to systems running macOS and Windows. This event highlights the vulnerabilities of non-secured update systems and underscores the importance of secure update practices to counter such advanced cyber espionage activities.

## Content

# China-Linked Hackers Compromise ISP to Deploy Malicious Software Updates

A cyber espionage group linked to China, known as Evasive Panda, also referred to as Bronze Highland and StormBamboo, has executed a sophisticated attack by compromising an Internet Service Provider (ISP) in mid-2023. This breach aimed at pushing malicious software updates to targeted companies via manipulated DNS query responses. 

## Exploitation Method

The attackers leveraged insecure software update mechanisms to alter DNS responses, redirecting users to malicious IP addresses. This allowed them to deliver malware strains such as MgBot and MACMA to user systems. The manipulation of DNS queries is a significant highlight, demonstrating the group's advanced capabilities in launching precise and effective cyberattacks.

## Targeted Software

The primary focus of the cyber espionage campaign was on software that relies on HTTP for updates, showcasing the vulnerabilities of non-secured update mechanisms. By exploiting these vulnerabilities, Evasive Panda successfully injected malware into both macOS and Windows devices.

## Historical Context and Impact

Evasive Panda has a history of deploying complex malware across different platforms. Their targets have included entities such as Tibetan users and various NGOs, indicating a broader geopolitical motive behind their attacks. The exposure of this campaign underlines the persistent threat posed by such groups and the importance of secure software update practices.

## Broader Threat Landscape

Evasive Panda is not the only China-linked group engaging in such activities. Other groups, such as Bloody Wolf, have also been known to target businesses in countries like Kazakhstan, selling malware and evading Western law enforcement through methods like IP verification and the use of digital currencies.

## Recommendations

In light of these findings, organizations are advised to review provided indicators of compromise (IOCs) and strengthen their software update mechanisms by ensuring secure protocols are in place. This proactive approach is crucial in detecting and mitigating the potential impact of such sophisticated cyber espionage activities.

By securing update mechanisms and maintaining vigilance, entities can better protect themselves against the evolving threat landscape posed by advanced persistent threat groups like Evasive Panda and their contemporaries.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/china-linked-hackers-compromise-isp-to-deploy-malware-via-software-updates-09xwc6tm6)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"China-Linked Hackers Compromise ISP to Deploy Malware via Software Updates","url":"https://daily.dev/posts/china-linked-hackers-compromise-isp-to-deploy-malware-via-software-updates-09xwc6tm6","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/china-linked-hackers-compromise-isp-to-deploy-malware-via-software-updates-09xwc6tm6"},"datePublished":"2024-08-05T15:57:01.283Z","dateModified":"2024-08-05T19:00:02.213Z","description":"China-linked hacker group Evasive Panda compromised an ISP in mid-2023 to deploy malicious software updates through manipulated DNS query responses. By...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/991503170ffdaa5df7aaaca641b7ad73?_a=AQAEuiZ","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/991503170ffdaa5df7aaaca641b7ad73?_a=AQAEuiZ","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/china-linked-hackers-compromise-isp-to-deploy-malware-via-software-updates-09xwc6tm6","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":3},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,malware","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"China-Linked Hackers Compromise ISP to Deploy Malware via Software Updates"}]}
```

