Daggerfly
Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa. Daggerfly is associated with exclusive use of MgBot malware and is noted for several potential supply chain infection campaigns.
Attribution signal
?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low0.8
Low signal strength
Mentions1
Sources1
High conf.1
Last seenMay 2026
First observed
2024-07-25
Last active
—
Origin
China
Aliases
3
Techniques
17
Campaigns
0
China
Attribution signals
1 mention · 1 source#1employed byhigh
TTP match
eset
May 2026
"adversary-in-the-middle technique for both initial access and lateral movement, employed by groups such as PlushDaemon, SinisterEye, Evasive Panda, and TheWizards."
Hedge terms observed
employed by