Skip to content
September 16, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • China-Linked APT15 developed a new version of MirageFox malware
  • Malware

China-Linked APT15 developed a new version of MirageFox malware

Do Son June 19, 2018 2 minutes read
Add Daily CyberSecurity as a preferred source on Google

The newly discovered APT15 hacker group associated with China, also known as Ke3chang, Mirage, Vixen Panda, Royal APT, Playful Dragon, has recently developed a new version of malware based on previous hacking tools outside of China. The organization’s hacking tools are the primary targets of most cybersecurity company product interceptions, including Mirage, BS2005, RoyalCLI, RoyalDNS, TidePool, BMW, MyWeb. The organization’s attack targets mainly concentrate in the defense sector, high-tech fields, energy, government agencies, aviation, and manufacturing industries.

The latest attack by the hacking organization took place in the United Kingdom last year for the NCC Group. The NCC Group provided a large number of information services to the British government. The purpose of that attack was to obtain information from the government and military departments. Later, when the NCC Group upgraded its network security, it discovered two new back door programs of the hacker group: RoyalCLI and RoyalDNS.

Another cyber security company, Intezer, also discovered last week that the hacker organization’s variant of Mirage malware based on the YARA rules was called MirageFox and that Reaver malware shared software code between the two.

MirageFox malware’s working mechanism is to first collect the infected computer information, such as username, CPU information, system architecture, etc., then transfer this information to the remote server, and then open the back door program on the host, waiting for the remote server’s instructions, such as Modify files, open/close processes, etc. It is still not known how this MirageFox spreads. According to the evidence currently available, this malicious software misuses a McAfee binary file to load malicious processes through DLL file hijacking.

This time also noticed that the IP address on the remote server is an IP address of the intranet. From this, it can determine that the attack directed against the internal network of the organization. After the hackers use the VPN to access the internal system of the organization, they obtain relevant permissions, hackers believed to be sponsored by China stole sensitive information from a US Navy contractor. It is very likely that this attack was also related to the Chinese government.

Source: securityweek

Related coverage

  • Acreed: The New Infostealer Using BNB Smart Chain and Steam Profiles for Stealthy C2
  • Snapekit Rootkit Unveiled: A Stealthy Threat Targeting Arch Linux
  • An oil factory in Saudi Arabia was damaged by malicious software
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: APT15 MirageFox malware

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-89026CVSS 9.8
    The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-58704
    In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
  • CVE-2026-87886
    Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-92397CVSS 9.1
    A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this...
  • CVE-2025-59953CVSS 9.8
    LMDeploy is a toolkit for compressing, deploying, and serving large language models....
  • CVE-2026-70416CVSS 10.0
    Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data...
  • CVE-2026-92395CVSS 9.1
    @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind...
  • CVE-2026-91843CVSS 9.8
    A stack overflow during the unauthenticated login process may allow an attacker...
  • CVE-2026-90049CVSS 9.3
    In the Linux kernel, the following vulnerability has been resolved: net: skbuff:...
  • CVE-2026-90048CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix...
  • CVE-2026-90042CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: ceph: properly...
  • CVE-2026-90038CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent...
  • CVE-2026-90037CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.