CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2112

As cited

Copy frozen at (site build).

threat intel

StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms

StormBamboo, a Chinese-linked threat actor, compromised an internet service provider's DNS infrastructure to redirect software update requests to malware-hosting servers. The attacks targeted applications with insecure update mechanisms that use HTTP and lack signature validation, allowing attackers to distribute malware families including MACMA and POCOSTICK to Windows and macOS systems across victim organizations.

Why it matters: Organizations relying on software with HTTP-based update mechanisms and weak signature validation face direct infection risk from DNS-level attacks; practitioners should audit third-party applications for secure update practices and network monitoring for unexpected update traffic.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms

StormBamboo, a Chinese-linked threat actor, compromised an internet service provider's DNS infrastructure to redirect software update requests to malware-hosting servers. The attacks targeted applications with insecure update mechanisms that use HTTP and lack signature validation, allowing attackers to distribute malware families including MACMA and POCOSTICK to Windows and macOS systems across victim organizations.

Why it matters: Organizations relying on software with HTTP-based update mechanisms and weak signature validation face direct infection risk from DNS-level attacks; practitioners should audit third-party applications for secure update practices and network monitoring for unexpected update traffic.

VendorsMicrosoftAppleSophos
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary