logo

Chinese APT Campaign Uses Middle East Lures to Target Qatar With PlugX

ID: 01a1e824-f533-5495-b86f-6e02b120bdfd

STIX ID: report--01a1e824-f533-5495-b86f-6e02b120bdfd

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-03-10

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Chinese state-linked cyber espionage groups rapidly targeted Qatari organizations after a Middle East escalation, using conflict-themed and AI-generated lure archives to deliver PlugX and a novel Rust-based loader that installed Cobalt Strike. Attack chains abused DLL hijacking in legitimate binaries (Baidu NetDisk and NVDA components), included observable configuration/decryption keys and C2 infrastructure (Kaopu Cloud, Cloudflare), and reflect high operational maturity and rapid adaptation to geopolitical events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.