BRONZE HIGHLAND is an espionage group primarily targeting human rights and pro-democracy advocates.
Analyst brief
BRONZE HIGHLAND likely operates on behalf of China, focusing on espionage against human rights and pro-democracy advocates. They primarily target entities in Hong Kong, Malaysia, Taiwan, and India. The actor uses spearphishing for initial access, deploying malware like MgBot, PlugX, and Cobalt Strike, and maintains presence via PowerShell, Scheduled Tasks, and DLL side-loading. Defenders should prioritize monitoring for unusual PowerShell execution, Web Protocols-based C2, evidence of code-signed malware, and credential access attempts targeting the SAM.
BRONZE HIGHLAND
Evasive Panda Daggerfly
unknown
BRONZE HIGHLAND has been observed using spearphishing as an initial infection vector to deploy the MgBot remote access trojan against targets in Hong Kong. Third party reporting suggests the threat group also targets India, Malaysia and Taiwan and leverages Cobalt Strike and KsRemote Android Rat. CTU researchers assess with moderate confidence that BRONZE HIGHLAND operates on behalf of China and has a remit covering espionage against domestic human rights and pro-democracy advocates and nations neighbouring China