{
  "aliases": [
    "Bronze Highland",
    "Daggerfly"
  ],
  "attack_id": "G1034",
  "attack_name": "Daggerfly",
  "attack_url": "https://attack.mitre.org/groups/G1034/",
  "counts": {
    "domain": 3,
    "ipv4": 11
  },
  "first_seen": {
    "domain": {
      "flash.governmentmm.com": "2020-07-07",
      "governmentmm.com": "2020-07-21",
      "update.devicebug.com": "2024-03-07"
    },
    "ipv4": {
      "103.96.128.44:10001": "2024-07-24",
      "103.96.128.44:16564": "2024-07-24",
      "103.96.131.150:19876": "2024-07-24",
      "103.96.131.150:40020": "2024-07-24",
      "122.10.89.170:9552": "2020-07-21",
      "122.10.89.172:10560": "2020-07-21",
      "223.165.4.175:81": "2024-11-22",
      "45.125.64.200:33200": "2025-02-08",
      "45.125.64.200:33220": "2024-11-22",
      "45.125.64.200:33223": "2024-11-22",
      "45.77.140.81:81": "2020-08-21"
    }
  },
  "first_seen_precision": {
    "domain": {},
    "ipv4": {}
  },
  "first_seen_range": {
    "earliest": "2020-07-07",
    "latest": "2025-02-08"
  },
  "generated_at": "2026-08-08T03:26:30+00:00",
  "indicators": {
    "domain": [
      "flash.governmentmm.com",
      "governmentmm.com",
      "update.devicebug.com"
    ],
    "ipv4": [
      "103.96.128.44:10001",
      "103.96.128.44:16564",
      "103.96.131.150:19876",
      "103.96.131.150:40020",
      "122.10.89.170:9552",
      "122.10.89.172:10560",
      "223.165.4.175:81",
      "45.125.64.200:33200",
      "45.125.64.200:33220",
      "45.125.64.200:33223",
      "45.77.140.81:81"
    ]
  },
  "last_modified": "2026-01-02T23:10:15+00:00",
  "maltrail_groups": [
    "EVASIVEPANDA"
  ],
  "references": [
    "https://app.any.run/tasks/e5ad4dd0-32f7-45a6-8012-44711ed04f0e/",
    "https://blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-group-targets-india-and-hong-kong-using-new-variant-of-mgbot-malware/",
    "https://otx.alienvault.com/pulse/5f170c74a81587f5b2b6be5f",
    "https://symantec-enterprise-blogs.security.com/threat-intelligence/daggerfly-espionage-updated-toolset",
    "https://twitter.com/h2jazi/status/1296919948598673409",
    "https://www.bleepingcomputer.com/news/security/chinese-cyberspies-use-new-ssh-backdoor-in-network-device-hacks/",
    "https://www.virustotal.com/gui/domain/governmentmm.com/relations",
    "https://www.virustotal.com/gui/file/23acab55f533cad2471516d15f52a85d7f3a64e9589b6bfc76981dde39d1e0d4/detection",
    "https://www.virustotal.com/gui/file/5687b32cdd5c4d1b3e928ee0792f6ec43817883721f9b86ec8066c5ec2791595/detection",
    "https://www.virustotal.com/gui/file/5c52e41090cdd13e0bfa7ec11c283f5051347ba02c9868b4fddfd9c3fc452191/detection",
    "https://www.virustotal.com/gui/file/82a662cc06c49714efd8ed9086e20181659535718c515aa583efc70206256085/detection",
    "https://www.virustotal.com/gui/file/82c36fe8429b63c59d06d3741d1e4de7b60e196d1106a678fe052cc73909a997/detection",
    "https://www.virustotal.com/gui/file/94e8540ea39893b6be910cfee0331766e4a199684b0360e367741facca74191f/detection",
    "https://www.virustotal.com/gui/file/a0b125e69a8b3619b372fe363bd2cf2c2c3772c2eec39fa40f86c47b1a0d16d9/detection",
    "https://www.virustotal.com/gui/file/dfd28fa39cfa6a8e06ea897a6df78f9e27d36bba192b43e83790ff09879ac2bc/detection",
    "https://www.welivesecurity.com/en/eset-research/evasive-panda-leverages-monlam-festival-target-tibetans/",
    "https://x.com/TuringAlex/status/1859969605084823621"
  ],
  "related": [],
  "slug": "G1034",
  "timeline": [
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2025-02-08",
      "indicators": {
        "ipv4": [
          "45.125.64.200:33200"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/TuringAlex/status/1859969605084823621",
        "https://www.bleepingcomputer.com/news/security/chinese-cyberspies-use-new-ssh-backdoor-in-network-device-hacks/",
        "https://www.virustotal.com/gui/file/94e8540ea39893b6be910cfee0331766e4a199684b0360e367741facca74191f/detection"
      ],
      "total": 1
    },
    {
      "counts": {
        "ipv4": 3
      },
      "first_seen": "2024-11-22",
      "indicators": {
        "ipv4": [
          "223.165.4.175:81",
          "45.125.64.200:33220",
          "45.125.64.200:33223"
        ]
      },
      "precision": "exact",
      "references": [
        "https://x.com/TuringAlex/status/1859969605084823621",
        "https://www.bleepingcomputer.com/news/security/chinese-cyberspies-use-new-ssh-backdoor-in-network-device-hacks/",
        "https://www.virustotal.com/gui/file/94e8540ea39893b6be910cfee0331766e4a199684b0360e367741facca74191f/detection"
      ],
      "total": 3
    },
    {
      "counts": {
        "ipv4": 4
      },
      "first_seen": "2024-07-24",
      "indicators": {
        "ipv4": [
          "103.96.128.44:10001",
          "103.96.128.44:16564",
          "103.96.131.150:19876",
          "103.96.131.150:40020"
        ]
      },
      "precision": "exact",
      "references": [
        "https://symantec-enterprise-blogs.security.com/threat-intelligence/daggerfly-espionage-updated-toolset",
        "https://www.virustotal.com/gui/file/5c52e41090cdd13e0bfa7ec11c283f5051347ba02c9868b4fddfd9c3fc452191/detection",
        "https://www.virustotal.com/gui/file/5687b32cdd5c4d1b3e928ee0792f6ec43817883721f9b86ec8066c5ec2791595/detection",
        "https://www.virustotal.com/gui/file/23acab55f533cad2471516d15f52a85d7f3a64e9589b6bfc76981dde39d1e0d4/detection",
        "https://www.virustotal.com/gui/file/dfd28fa39cfa6a8e06ea897a6df78f9e27d36bba192b43e83790ff09879ac2bc/detection",
        "https://www.virustotal.com/gui/file/a0b125e69a8b3619b372fe363bd2cf2c2c3772c2eec39fa40f86c47b1a0d16d9/detection",
        "https://www.virustotal.com/gui/file/82c36fe8429b63c59d06d3741d1e4de7b60e196d1106a678fe052cc73909a997/detection",
        "https://www.virustotal.com/gui/file/82a662cc06c49714efd8ed9086e20181659535718c515aa583efc70206256085/detection"
      ],
      "total": 4
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2024-03-07",
      "indicators": {
        "domain": [
          "update.devicebug.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://www.welivesecurity.com/en/eset-research/evasive-panda-leverages-monlam-festival-target-tibetans/"
      ],
      "total": 1
    },
    {
      "counts": {
        "ipv4": 1
      },
      "first_seen": "2020-08-21",
      "indicators": {
        "ipv4": [
          "45.77.140.81:81"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/h2jazi/status/1296919948598673409",
        "https://blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-group-targets-india-and-hong-kong-using-new-variant-of-mgbot-malware/",
        "https://otx.alienvault.com/pulse/5f170c74a81587f5b2b6be5f",
        "https://www.virustotal.com/gui/domain/governmentmm.com/relations",
        "https://app.any.run/tasks/e5ad4dd0-32f7-45a6-8012-44711ed04f0e/"
      ],
      "total": 1
    },
    {
      "counts": {
        "domain": 1,
        "ipv4": 2
      },
      "first_seen": "2020-07-21",
      "indicators": {
        "domain": [
          "governmentmm.com"
        ],
        "ipv4": [
          "122.10.89.170:9552",
          "122.10.89.172:10560"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/h2jazi/status/1296919948598673409",
        "https://blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-group-targets-india-and-hong-kong-using-new-variant-of-mgbot-malware/",
        "https://otx.alienvault.com/pulse/5f170c74a81587f5b2b6be5f",
        "https://www.virustotal.com/gui/domain/governmentmm.com/relations",
        "https://app.any.run/tasks/e5ad4dd0-32f7-45a6-8012-44711ed04f0e/"
      ],
      "total": 3
    },
    {
      "counts": {
        "domain": 1
      },
      "first_seen": "2020-07-07",
      "indicators": {
        "domain": [
          "flash.governmentmm.com"
        ]
      },
      "precision": "exact",
      "references": [
        "https://twitter.com/h2jazi/status/1296919948598673409",
        "https://blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-group-targets-india-and-hong-kong-using-new-variant-of-mgbot-malware/",
        "https://otx.alienvault.com/pulse/5f170c74a81587f5b2b6be5f",
        "https://www.virustotal.com/gui/domain/governmentmm.com/relations",
        "https://app.any.run/tasks/e5ad4dd0-32f7-45a6-8012-44711ed04f0e/"
      ],
      "total": 1
    }
  ]
}
