Security News > 2023 > April > Tencent QQ users hacked in mysterious malware attack, says ESET

Tencent QQ users hacked in mysterious malware attack, says ESET
2023-04-26 18:16

A Chinese APT hacking group known as 'Evasive Panda' is linked to a mysterious attack that distributed the MsgBot malware as part of an automatic update for the Tencent QQ messaging app.

ESET reports that the malicious MsgBot malware payload was delivered to victims as a Tencent QQ software update from legitimate URLs and IP addresses belonging to the software developer.

This means there can be two possible scenarios for the attack - a supply chain attack or an adversary-in-the-middle attack.

BleepingComputer contacted both ESET and Tencent with further questions about the attack.

Stealing the content of the Tencent QQ database that stores the user's message history.

In conclusion, the Evasive Panda APT was found targeting users in China, aiming to steal data mostly from Chinese apps, leveraging an unclear method to perform a supply chain attack on Tencent QQ software.


News URL

https://www.bleepingcomputer.com/news/security/tencent-qq-users-hacked-in-mysterious-malware-attack-says-eset/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Eset 19 4 20 11 4 39
Tencent 19 0 14 5 1 20