logo

PlugX USB Worm Hits Multiple Continents via DLL Sideloading

ID: 99b9e28b-ac20-50fb-bca3-29840145fb07

STIX ID: report--99b9e28b-ac20-50fb-bca3-29840145fb07

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A new PlugX USB worm variant is actively propagating across multiple countries by abusing DLL sideloading of a legitimate Avast executable (AvastSvc.exe) paired with a malicious wsc.dll and encrypted PlugX payload; it hides components in RECYCLER.BIN, uses renamed loaders and shortcut tricks to execute from removable media, collects discovery outputs and documents for exfiltration, and calls back to C2 infrastructure (notably 45.142.166.112) linked to PKPLUG/Mustang Panda.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.