logo

Chinese APT Campaign Targets Qatar With PlugX Lures Tied to Middle East Conflict

ID: 686abf0a-b8a8-5183-ab75-91c802470f7d

STIX ID: report--686abf0a-b8a8-5183-ab75-91c802470f7d

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-10

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A Chinese-linked APT known as Camaro Dragon conducted fast, conflict-themed phishing campaigns against targets in Qatar on 1 March 2026, leveraging archive lures to deliver a multi-stage PlugX infection (LNK -> remote payload -> DLL side-loading of Baidu NetDisk) and a separate campaign using a Rust-based loader abusing nvdaHelperRemote.dll to deploy Cobalt Strike; the report includes IoCs (185.219.220.73, 91.193.17.117, almersalstore.com), describes C2 through Kaopu Cloud/Cloudflare, and advises monitoring for DLL hijacking, blocking listed indicators, and updating EDR/endpoint defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.