216.73.217.22

Operation ControlPlug: Targeted attack campaign using MSC files

· Published 06/06/2024 14:55 · Modified 06/06/2024 15:07

Export JSON

Essential information

Published
06/06/2024 14:55
Modified
06/06/2024 15:07
Tags
2024-06-06 apt campaign destroyrat kaba korplug malware plugx sogu stealthy thoper tvt
Related entities
14 observables, 1 intrusion sets (apt), 10 techniques (mitre), 7 malware

Description

An investigation revealed that the threat group DarkPeony, also known as Operation ControlPlug, employed a novel technique involving MSC (Microsoft Common Console Document) files to initiate their malicious activities. These files, generally unfamiliar, leveraged the Console Taskpad feature to execute PowerShell scripts that downloaded and executed , ultimately leading to the deployment of . Access control measures, including the use of Cloudflare, were implemented to restrict access to the distribution sites hosting the MSI payload files. Although instances involving MSC files are currently limited, this tactic may gain traction among multiple threat groups due to its nature.

External references