logo

China-nexus Group Targets Arabian Gulf Region

ID: bd20a63d-ea87-5cb0-ba1d-4d0283f12117

STIX ID: report--bd20a63d-ea87-5cb0-ba1d-4d0283f12117

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2026-04-09

Date Updated: 2026-05-01

...
...

This technical analysis describes a March 1, 2026 multi-stage PlugX campaign that delivered a PlugX backdoor via a ZIP archive containing LNK and CHM artifacts; the report details the shellcode loader, control-flow-flattened PlugX loader, reflective DLL injection, multiple anti-forensics and obfuscation techniques, decrypted configuration (including C2 https://91.193.17.117:443), persistence methods, supported plugins, and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.