Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • China-Linked APT15 developed a new version of MirageFox malware
  • Malware

China-Linked APT15 developed a new version of MirageFox malware

Do Son June 19, 2018 2 minutes read
Add Daily CyberSecurity as a preferred source on Google

The newly discovered APT15 hacker group associated with China, also known as Ke3chang, Mirage, Vixen Panda, Royal APT, Playful Dragon, has recently developed a new version of malware based on previous hacking tools outside of China. The organization’s hacking tools are the primary targets of most cybersecurity company product interceptions, including Mirage, BS2005, RoyalCLI, RoyalDNS, TidePool, BMW, MyWeb. The organization’s attack targets mainly concentrate in the defense sector, high-tech fields, energy, government agencies, aviation, and manufacturing industries.

The latest attack by the hacking organization took place in the United Kingdom last year for the NCC Group. The NCC Group provided a large number of information services to the British government. The purpose of that attack was to obtain information from the government and military departments. Later, when the NCC Group upgraded its network security, it discovered two new back door programs of the hacker group: RoyalCLI and RoyalDNS.

Another cyber security company, Intezer, also discovered last week that the hacker organization’s variant of Mirage malware based on the YARA rules was called MirageFox and that Reaver malware shared software code between the two.

MirageFox malware’s working mechanism is to first collect the infected computer information, such as username, CPU information, system architecture, etc., then transfer this information to the remote server, and then open the back door program on the host, waiting for the remote server’s instructions, such as Modify files, open/close processes, etc. It is still not known how this MirageFox spreads. According to the evidence currently available, this malicious software misuses a McAfee binary file to load malicious processes through DLL file hijacking.

This time also noticed that the IP address on the remote server is an IP address of the intranet. From this, it can determine that the attack directed against the internal network of the organization. After the hackers use the VPN to access the internal system of the organization, they obtain relevant permissions, hackers believed to be sponsored by China stole sensitive information from a US Navy contractor. It is very likely that this attack was also related to the Chinese government.

Source: securityweek

Related coverage

  • PyPI Poisoned: “Zebo” and “Cometlogger” Downloaded Hundreds of Times
  • Cybercriminals Exploit CrowdStrike Update Incident with New Stealer Malware, Connecio
  • Cybercriminals Target LatAm Banks: Mekotio, BBTok Lead the Charge
  • Black Myth: Wukong DDoS Attackers Return with New AIRASHI Botnet
  • Google Play installer for Windows 11 Subsystem for Android secretly installed malware
  • Medusa Ransomware: A Sinister Evolution in Cyber Extortion
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: APT15 MirageFox malware

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-93674CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 7, 2026
  • CVE-2026-104334CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 6, 2026
  • CVE-2026-106501CVSS 9.6
    Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend...
    📅 Updated: Oct 6, 2026
  • CVE-2026-106414CVSS 9.6
    Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker...
    📅 Updated: Oct 6, 2026
  • CVE-2026-106329CVSS 9.6
    Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to...
    📅 Updated: Oct 6, 2026
  • CVE-2026-106239CVSS 9.6
    Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to...
    📅 Updated: Oct 6, 2026
  • CVE-2026-102322CVSS 9.6
    Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code...
    📅 Updated: Oct 6, 2026
  • CVE-2024-46484CVSS 9.8
    TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.
    📅 Updated: Oct 6, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.