Chinese Hacking Group StormBamboo Strikes Again: Malware Hidden in Software Updates

StormBamboo, also known as Evasive Panda, has hijacked an ISP to poison software updates with malware. By exploiting insecure update mechanisms, they delivered malware like MACMA and POCOSTICK to victims’ devices. This Chinese hacking group has been targeting organizations across multiple countries since at least 2012.

Pro Dashboard

Hot Take:

When life gives you lemons, make lemonade. When cyber-espionage groups give you malware, make sure your DNS requests aren’t being poisoned!

Key Points:

  • StormBamboo, aka Evasive Panda, Daggerfly, and StormCloud, compromised an ISP to deliver malware through poisoned software updates.
  • The group has been active since at least 2012, targeting organizations across various regions, including China, Hong Kong, Macao, and Southeast Asia.
  • Malware such as MACMA and POCOSTICK (MGBot) was deployed by exploiting insecure HTTP update mechanisms lacking digital signature validation.
  • DNS requests were intercepted and malicious IP addresses were injected to deliver payloads from command-and-control servers.
  • Further attacks in 2023 and 2024 targeted international NGOs and organizations in Taiwan using new malware versions.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?