Unmasking the Shadows: A Global Hunt for PlugX Staging Infrastructure
ID: 59a92548-ff9e-51d0-8448-ad6a0c00c6dc
STIX ID: report--59a92548-ff9e-51d0-8448-ad6a0c00c6dc
Feed Name: securityonline.info
A threat researcher revealed a coordinated C2 procurement campaign used by PRC-linked groups Mustang Panda, UNC6384, and RedDelta involving PlugX; the investigation identified 14 previously unreported domains, a sample (Avk.dll) and IP (108.165.255.97). Operators pre-register expired domains, stage on VPS providers (ASN 149440/Evoxt Enterprise), then rapidly enable Cloudflare TLS/proxying and use generic “productivity”-themed sites to mask true hosting IPs, indicating a deliberate pre-staged deployment model to evade defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
