logo

PlugX USB Worm Goes Global DLL Sideloading Fuels Multi-Continent Rampage

ID: 461bc709-e97e-5d03-b0ab-72d010333b03

STIX ID: report--461bc709-e97e-5d03-b0ab-72d010333b03

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-04-15

Date Updated: 2026-04-15

Author: Varshini

...
...

**Executive summary:** Researchers observed a new PlugX variant propagating across multiple countries by abusing DLL sideloading and removable USB media to spread stealthily, collect system information and exfiltrate files (artifacts include AvastSvc.exe, wsc.dll, encrypted.dat and hidden RECYCLER.BIN structures); defenders are advised to monitor for DLL sideloading, USB activity, hidden directories, suspicious shortcuts, and batch scripts that perform system discovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.