NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / Daggerfly

Daggerfly

G1034 China Espionage MITRE ATT&CK →

Also known as: Evasive Panda · BRONZE HIGHLAND

Overview

Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa. Daggerfly is associated with exclusive use of MgBot malware and is noted for several potential supply chain infection campaigns.

Targets

Government · Individuals · Universities

Regions

Hong Kong · India · Macao · Malaysia · Nigeria · Taiwan

Capabilities

  • Supply-chain compromise — ATT&CK T1195.002
  • Custom malware/implant development — ATT&CK: 4 attributed custom malware families

TTPs — 17 techniques across 9 tactics

Resource Development

Initial Access

Execution

Persistence

Stealth

Defense Impairment

Credential Access

Command and Control

Tools & malware (6)

PlugX · MgBot · BITSAdmin · MacMa · Nightdoor · Reg

Reporting (3)