PlugX USB Worm Goes Global DLL Sideloading Fuels Multi-Continent Rampage
ID: 461bc709-e97e-5d03-b0ab-72d010333b03
STIX ID: report--461bc709-e97e-5d03-b0ab-72d010333b03
Feed Name: Cyber Press
Threat Score
**Executive summary:** Researchers observed a new PlugX variant propagating across multiple countries by abusing DLL sideloading and removable USB media to spread stealthily, collect system information and exfiltrate files (artifacts include AvastSvc.exe, wsc.dll, encrypted.dat and hidden RECYCLER.BIN structures); defenders are advised to monitor for DLL sideloading, USB activity, hidden directories, suspicious shortcuts, and batch scripts that perform system discovery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
