
A malicious campaign, first spotted in November 2022 and orchestrated by a China-linked threat actor Daggerfly, has hit major Telecommunication services providers in Africa.
Tracked by the broader cybersecurity community as Bronze Highland and Evasive Panda, Daggerfly uses previously unseen plugins from the MgBot malware framework, a new advisory published by Symantec said.
The advisory said that the plugins developed and deployed by the threat actors have several information-gathering capabilities, including a network scanner, a Chrome and Firefox info stealer, a logging module, a QQ keylogger and messages info stealer, an Active Directory enumeration tool, a password dumper, a screen and clipboard grabber, an Outlook and Foxmail credentials stealer, an audio capture tool, and a process watchdog script.
These capabilities would have allowed the attackers to gather much data from victim machines. According to Symantec, the capabilities of these plugins also indicate that the attackers’ primary goal during this campaign was information gathering.
In addition, the attackers were seen using a PlugX loader and abusing the legitimate AnyDesk remote desktop software. Symantec said the team first noticed the attack via AnyDesk connections on a Microsoft Exchange mail server. The legitimate, free Rising antivirus software was also used to side-load the PlugX loader onto victim machines.
Malwarebytes highlighted Daggerfly’s use of the MgBot loader (aka BLame or MgmBot) in July 2020 as part of phishing attacks targeting Indian government personnel and individuals in Hong Kong.
The threat actor employs spear-phishing as the initial infection vector for MgBot and other tools such as Cobalt Strike, a legitimate adversary simulation software, and KsRemote, an Android-based remote access trojan (RAT).
Symantec’s analysis of attack chains revealed the use of living-off-the-land (LotL) tools such as BITSAdmin and PowerShell to deliver next-stage payloads such as a legitimate AnyDesk executable and a credential harvesting utility. The threat actor then proceeds to establish persistence on the victim system by creating a local account and deploying the MgBot modular framework, which includes a variety of plugins for harvesting browser data, logging keystrokes, capturing screenshots, recording audio, and enumerating the Active Directory service.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543