Chinese UNC6384 Hackers Leverages Valid Code Signing Certificates to Evade Detection
ID: 88ab0c01-3c89-5a13-ac0f-26d07b15232f
STIX ID: report--88ab0c01-3c89-5a13-ac0f-26d07b15232f
Feed Name: cybersecurityNews.com
Threat Score
A sophisticated 2025 espionage campaign (attributed to UNC6384/PRC-nexus) uses captive-portal hijacking to serve a signed downloader (STATICPLUGIN) masquerading as an Adobe plugin update; it retrieves an MSI containing CANONSTAGER which DLL side-loads and executes an encrypted SOGU.SEC backdoor entirely in memory, evading disk-based forensics and blending C2 traffic over HTTPS (notable IOCs include signing certificates and C2 166.88.2.90).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
