Hacking

Evasive Panda Targets Taiwan with New CloudScout Toolset, Using Cookie-Theft for Cloud Data Exfiltration

Published  ·  3 min read

A government entity and a religious organization in Taiwan recently became targets of a China-linked cyber espionage group known as Evasive Panda, which used a previously undocumented post-compromise toolset called CloudScout to compromise their data.

"The CloudScout toolset is capable of retrieving data from various cloud services by leveraging stolen web session cookies," stated ESET security researcher Anh Ho. "Through a plugin, CloudScout works seamlessly with MgBot, Evasive Panda's signature malware framework."

The Slovak cybersecurity firm ESET observed that the .NET-based malware tool was active between May 2022 and February 2023. CloudScout contains ten distinct modules, written in C#, with three dedicated to extracting data from Google Drive, Gmail, and Outlook. The functions of the other modules remain undisclosed.

Evasive Panda, also referred to as Bronze Highland, Daggerfly, and StormBamboo, is a cyber espionage group known for targeting entities in Taiwan and Hong Kong. This group has previously executed watering hole and supply chain attacks, particularly against the Tibetan diaspora.

What sets this threat actor apart is its diverse initial access methods. It leverages newly disclosed security vulnerabilities and engages in supply chain attacks through DNS poisoning to breach victim networks and deploy MgBot and Nightdoor.

ESET noted that the CloudScout modules work by hijacking authenticated browser sessions, using stolen cookies to access Google Drive, Gmail, and Outlook. Each module operates via an MgBot plugin written in C++.

"At the heart of CloudScout is the CommonUtilities package, which provides all necessary low-level libraries for the modules to run," Ho explained.

This package includes custom libraries like:

  1. HTTPAccess: Manages HTTP communications
  2. ManagedCookie: Manages cookies for web requests between CloudScout and targeted services
  3. Logger and SimpleJSON

CloudScout gathers data, including mail folder listings, email content (with attachments), and specific files (.doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, .txt). This information is compressed into a ZIP archive for exfiltration via MgBot or Nightdoor.

However, new security features, such as Google’s Device Bound Session Credentials (DBSC) and App-Bound Encryption, are anticipated to counter cookie-theft malware like CloudScout.

"CloudScout is a .NET toolset used by Evasive Panda to steal data stored in cloud services," said Ho. "It operates as an MgBot extension and hijacks authenticated sessions through the pass-the-cookie technique."

This news comes alongside Canada’s recent accusation that a “sophisticated state-sponsored threat actor” from China conducted extensive reconnaissance across multiple Canadian domains, including government departments, federal political parties, and critical infrastructure sectors.

"The majority of targeted organizations were Canadian government departments and agencies, including the House of Commons and Senate," said the Canadian Government in a statement.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067