logo

Chinese APT Launches Spearphishing Campaign, Using Fake Cloudflare Lure to Deliver PlugX Malware

ID: b395daf8-c3b3-512c-bdba-5c9e05543696

STIX ID: report--b395daf8-c3b3-512c-bdba-5c9e05543696

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2025-10-07

Date Updated: 2026-04-22

Author: Ddos

...
...

StrikeReady Labs details a sophisticated spear-phishing campaign targeting European government and aviation entities that delivers PlugX (Sogu/Korplug) malware via specially crafted ZIP archives and malicious LNKs; the attack chain uses PowerShell carving, DLL sideloading of a legitimate Canon binary, Azure-hosted C2 domains, and decoy documents, with forensic links to PRC-aligned espionage clusters and reusable artifacts observed across prior campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.