logo

China-nexus Group Targets Persian Gulf Region

ID: 6aab750f-6910-5f89-a325-a8b234b0a709

STIX ID: report--6aab750f-6910-5f89-a325-a8b234b0a709

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2026-03-12

Date Updated: 2026-05-01

...
...

This technical report analyzes a March 1, 2026 multi-stage intrusion that used a ZIP archive with a malicious LNK to download a CHM, extract a TAR containing ShellFolder.exe and ShellFolderDepend.dll, and deploy an encrypted shellcode chain that reflectively loads a PlugX backdoor; the analysis documents DLL sideloading, inline API hooks, custom XOR/PRNG/RC4 decryption routines, control-flow-flattened shellcode, corrupted MZ/PE headers used as anti-forensics and a context structure for configuration, persistence mechanisms, supported C2 channels and commands, plugins, and IOCs including the C2 endpoint https://91.193.17.117:443.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.