Daggerfly
Also reported as Evasive Panda, BRONZE HIGHLAND, Storm Cloud, TAG-112, Bronze Highland and 3 other names. Linked to China by three sources.
Reports per quarter
Techniques seen in the last two years
- T1189 2 reports in ATT&CK
- T1583.004 2 reports reports only
- T1027 1 report reports only
- T1036.005 1 report reports only
- T1041 1 report reports only
- T1082 1 report in ATT&CK
- T1091 1 report reports only
- T1095 1 report reports only
- T1106 1 report reports only
- T1112 1 report reports only
Show all 29 techniques Show fewer
- T1114.002 1 report reports only
- T1140 1 report reports only
- T1190 1 report reports only
- T1195 1 report reports only
- T1204.004 1 report reports only
- T1530 1 report reports only
- T1539 1 report reports only
- T1543.003 1 report reports only
- T1548.002 1 report reports only
- T1550.004 1 report reports only
- T1560.001 1 report reports only
- T1566.001 1 report reports only
- T1566.002 1 report reports only
- T1566.003 1 report reports only
- T1569.002 1 report reports only
- T1583.006 1 report reports only
- T1584.004 1 report in ATT&CK
- T1587.001 1 report reports only
- T1659 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2012-0158 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2019-8526 KEV
- CVE-2020-10189 KEV
- CVE-2020-14882 KEV
- CVE-2021-1879 KEV
- CVE-2021-21166 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26868
- CVE-2021-30551 KEV
Show all 32 CVEs Show fewer
- CVE-2021-30869 KEV
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2022-26134 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-49475
- CVE-2023-36033 KEV
- CVE-2023-36884 KEV ransomware
- CVE-2024-30051 KEV ransomware
- CVE-2024-42009 KEV
- CVE-2024-9680 KEV ransomware
- CVE-2025-8088 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SpyNote (Malware Family)
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
Show all 31 reports Show fewer
-
Evasive Panda leverages Monlam Festival to target Tibetans
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Evasive Panda leverages Monlam Festival to target Tibetans
-
Evasive Panda APT group delivers malware via updates for popular Chinese software
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evasive Panda APT group delivers malware via updates for popular Chinese software
-
Daggerfly- APT Actor Targets Telecoms Company in Africa
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Daggerfly- APT Actor Targets Telecoms Company in Africa
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Mac Malware of 2022
-
GIMMICK Malware Attacks macOS to Attack Organizations Across Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GIMMICK Malware Attacks macOS to Attack Organizations Across Asia
-
Storm Cloud on the Horizon- GIMMICK Malware Strikes at macOS
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Storm Cloud on the Horizon- GIMMICK Malware Strikes at macOS
-
Storm Cloud Unleashed- Tibetan Focus of Highly Targeted Fake Flash Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Storm Cloud Unleashed- Tibetan Focus of Highly Targeted Fake Flash Campaign
Newest first. Details opens the report in Explore.