216.73.217.22

PlugX Meeting Invitation via MSBuild and GDATA

· Published 01/03/2026 05:26 · Modified 02/03/2026 11:42

Export JSON

Essential information

Published
01/03/2026 05:26
Modified
02/03/2026 11:42
Tags
2026-03-01 api hashing dll side-loading g data antivirus korplug phishing plugx rat xor encryption
Related entities
8 observables, 9 techniques (mitre), 2 malware, 4 others

Description

A recent campaign utilized emails with a 'Meeting Invitation' lure to deploy malware through . The infection chain begins with a zip file containing a malicious .csproj file and MSBuild executable. The .csproj file downloads three components: a legitimate executable, a malicious Avk.dll ( variant), and an encrypted AVKTray.dat file. The malware uses , , and for obfuscation. It establishes persistence via the Run registry key and communicates with a command and control server. The campaign showcases 's continued evolution while maintaining its core characteristics, highlighting its ongoing relevance in cyber-espionage operations.

External references