Chinese Hacking Group StormBamboo Strikes Again: Malware Hidden in Software Updates
StormBamboo, also known as Evasive Panda, has hijacked an ISP to poison software updates with malware. By exploiting insecure update mechanisms, they delivered malware like MACMA and POCOSTICK to victims’ devices. This Chinese hacking group has been targeting organizations across multiple countries since at least 2012.

Hot Take:
When life gives you lemons, make lemonade. When cyber-espionage groups give you malware, make sure your DNS requests aren’t being poisoned!
Key Points:
- StormBamboo, aka Evasive Panda, Daggerfly, and StormCloud, compromised an ISP to deliver malware through poisoned software updates.
- The group has been active since at least 2012, targeting organizations across various regions, including China, Hong Kong, Macao, and Southeast Asia.
- Malware such as MACMA and POCOSTICK (MGBot) was deployed by exploiting insecure HTTP update mechanisms lacking digital signature validation.
- DNS requests were intercepted and malicious IP addresses were injected to deliver payloads from command-and-control servers.
- Further attacks in 2023 and 2024 targeted international NGOs and organizations in Taiwan using new malware versions.
Already a member? Log in here