Security News > 2023 > April > Tencent QQ users hacked in mysterious malware attack, says ESET
A Chinese APT hacking group known as 'Evasive Panda' is linked to a mysterious attack that distributed the MsgBot malware as part of an automatic update for the Tencent QQ messaging app.
ESET reports that the malicious MsgBot malware payload was delivered to victims as a Tencent QQ software update from legitimate URLs and IP addresses belonging to the software developer.
This means there can be two possible scenarios for the attack - a supply chain attack or an adversary-in-the-middle attack.
BleepingComputer contacted both ESET and Tencent with further questions about the attack.
Stealing the content of the Tencent QQ database that stores the user's message history.
In conclusion, the Evasive Panda APT was found targeting users in China, aiming to steal data mostly from Chinese apps, leveraging an unclear method to perform a supply chain attack on Tencent QQ software.
News URL
Related news
- Cloudflare hacked using auth tokens stolen in Okta attack (source)
- Bumblebee malware attacks are back after 4-month break (source)
- Bumblebee malware wakes from hibernation, forgets what year it is, attacks with macros (source)
- Chinese Hackers Using Deepfakes in Advanced Mobile Banking Malware Attacks (source)
- ScreenConnect servers hacked in LockBit ransomware attacks (source)
- CISA warns of Microsoft Streaming bug exploited in malware attacks (source)
- Hacked WordPress Sites Abusing Visitors' Browsers for Distributed Brute-Force Attacks (source)
- DarkGate Malware Exploited Recently Patched Microsoft Flaw in Zero-Day Attack (source)
- From Deepfakes to Malware: AI's Expanding Role in Cyber Attacks (source)
- New BunnyLoader Malware Variant Surfaces with Modular Attack Features (source)