Mustang Panda Targets Asia with Advanced PlugX Variant DOPLUGS
ID: b81b17d9-bb7e-5890-90e4-9485f534a99d
STIX ID: report--b81b17d9-bb7e-5890-90e4-9485f534a99d
Feed Name: The Hacker News
Trend Micro and other researchers report that the China-linked Mustang Panda (aka Earth Preta/BASIN/TA416 and other aliases) is actively deploying a customized PlugX variant called DOPLUGS across multiple Asian countries — primarily Taiwan and Vietnam — using spear-phishing lures, DLL sideloading of signed executables, and modules like KillSomeOne for USB spreading and data theft; recent samples show a Nim-written DLL and a custom RC4 implementation to decrypt PlugX, with follow-on payloads including Poison Ivy or Cobalt Strike for remote access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
