216.73.217.22

How a new PlugX variant abuses DLL search order hijacking

· Published 25/09/2025 19:15 · Modified 25/09/2025 19:47

Export JSON

Essential information

Published
25/09/2025 19:15
Modified
25/09/2025 19:47
Tags
2025-09-23 2025-09-25 apt backdoordiplomacy chinese apt dll hijacking manufacturing naikon plugx rainyday telecommunications turian
Related entities
53 observables, 11 techniques (mitre)

Description

A new campaign targeting and sectors in Central and South Asian countries has been discovered, delivering a new variant of . The campaign, active since 2022, shows overlaps between and backdoors, including the abuse of legitimate applications for DLL sideloading and shared encryption methods. The new variant's configuration format resembles that of , suggesting attribution to . Analysis of victimology and technical implementation indicates a potential connection between and , possibly sourcing tools from the same vendor. The malware families use similar infection chains, loaders, and shellcode structures, with shared RC4 keys for payload decryption. This campaign highlights the evolving tactics of Chinese-speaking threat actors and the potential collaboration between previously distinct groups.

External references