• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • China-Linked APT15 developed a new version of MirageFox malware
  • Malware

China-Linked APT15 developed a new version of MirageFox malware

Ddos June 19, 2018 2 minutes read

The newly discovered APT15 hacker group associated with China, also known as Ke3chang, Mirage, Vixen Panda, Royal APT, Playful Dragon, has recently developed a new version of malware based on previous hacking tools outside of China. The organization’s hacking tools are the primary targets of most cybersecurity company product interceptions, including Mirage, BS2005, RoyalCLI, RoyalDNS, TidePool, BMW, MyWeb. The organization’s attack targets mainly concentrate in the defense sector, high-tech fields, energy, government agencies, aviation, and manufacturing industries.

The latest attack by the hacking organization took place in the United Kingdom last year for the NCC Group. The NCC Group provided a large number of information services to the British government. The purpose of that attack was to obtain information from the government and military departments. Later, when the NCC Group upgraded its network security, it discovered two new back door programs of the hacker group: RoyalCLI and RoyalDNS.

Another cyber security company, Intezer, also discovered last week that the hacker organization’s variant of Mirage malware based on the YARA rules was called MirageFox and that Reaver malware shared software code between the two.

MirageFox malware’s working mechanism is to first collect the infected computer information, such as username, CPU information, system architecture, etc., then transfer this information to the remote server, and then open the back door program on the host, waiting for the remote server’s instructions, such as Modify files, open/close processes, etc. It is still not known how this MirageFox spreads. According to the evidence currently available, this malicious software misuses a McAfee binary file to load malicious processes through DLL file hijacking.

This time also noticed that the IP address on the remote server is an IP address of the intranet. From this, it can determine that the attack directed against the internal network of the organization. After the hackers use the VPN to access the internal system of the organization, they obtain relevant permissions, hackers believed to be sponsored by China stole sensitive information from a US Navy contractor. It is very likely that this attack was also related to the Chinese government.

Source: securityweek

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. New North Korean Backdoor ‘Niki’ Targets Aerospace and Defense Sectors
  2. Unit 42 Research Exposes GootLoader’s Sophisticated Sandbox Evasion Tactics
  3. SparkCat Malware: Sneaky Crypto Stealer Found in Google Play and App Store Apps
  4. PostgreSQL Servers Hacked: 1,500+ Cloud Systems Mining Crypto via CPU_HU
  5. The SocGholish Malware Economy: Stealthy “Fake Updates” Fuel a Global Cybercrime Ecosystem
Tags: APT15 MirageFox malware

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-42773CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-42774CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.