UNC6384 Targets Diplomats with PlugX via Captive Portal Hijacks
Summary
Hide ▲
Show ▼
UNC6384, a China-nexus threat actor, has been targeting diplomats in Southeast Asia and other entities globally to advance Beijing's strategic interests. The group employs a multi-stage attack chain leveraging advanced social engineering, valid code signing certificates, adversary-in-the-middle (AitM) attacks, and indirect execution techniques to evade detection. The campaign, detected in March 2025, uses captive portal redirections to deliver a PlugX variant called SOGU.SEC. The attacks involve redirecting web traffic through a captive portal to a threat actor-controlled website, downloading a digitally signed downloader (STATICPLUGIN), and deploying the SOGU.SEC backdoor in memory. The malware supports commands to exfiltrate files, log keystrokes, and launch remote command shells. The campaign highlights the sophistication of PRC-nexus threat actors and their evolving operational capabilities. The campaign targeted around two dozen victims, primarily Southeast Asian diplomats, between March and July 2025. The attack chain involved compromised edge devices intercepting captive portal checks and redirecting users to a malicious website. The malicious website used a valid TLS/SSL certificate issued by Let's Encrypt to avoid browser security warnings. The first-stage malware, STATICPLUGIN, dropped a launcher called CANONSTAGER, which used unconventional techniques to hide its activities. The final payload was a variant of the PlugX backdoor, tracked by Google as SOGU.SEC. In September 2025, new information revealed that the PlugX variant overlaps with RainyDay and Turian backdoors, targeting telecommunications and manufacturing sectors in Central and South Asia. The campaign is linked to Mustang Panda, which also uses Bookworm malware. Bookworm has been used since 2015 and includes capabilities to execute commands, upload/download files, exfiltrate data, and establish persistent access.
Timeline
-
27.09.2025 15:06 1 articles · 6d ago
PlugX Variant Linked to Mustang Panda and Bookworm Malware
The new PlugX variant overlaps with RainyDay and Turian backdoors in its use of legitimate applications for DLL side-loading, encryption/decryption algorithms, and RC4 keys. The PlugX variant uses a configuration structure similar to RainyDay, associated with Lotus Panda (Naikon APT). The campaign targets telecommunications and manufacturing sectors in Central and South Asia. The attack chains involve abusing a legitimate executable associated with Mobile Popup Application to sideload a malicious DLL for payload execution. The PlugX variant includes an embedded keylogger plugin. The campaign is linked to Mustang Panda, which also uses Bookworm malware. Bookworm malware has been used since 2015 and includes capabilities to execute commands, upload/download files, exfiltrate data, and establish persistent access. Bookworm utilizes legitimate-looking domains or compromised infrastructure for C2 purposes. Bookworm variants share overlaps with TONESHELL, another backdoor associated with Mustang Panda. Bookworm employs a modular architecture that makes static analysis challenging.
Show sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
25.08.2025 21:11 3 articles · 1mo ago
UNC6384 Deploys PlugX via Captive Portal Hijacks Targeting Diplomats
The campaign targeted around two dozen victims, primarily Southeast Asian diplomats, between March and July 2025. The attack chain involved compromised edge devices intercepting captive portal checks and redirecting users to a malicious website. The malicious website used a valid TLS/SSL certificate issued by Let's Encrypt to avoid browser security warnings. The first-stage malware, STATICPLUGIN, dropped a launcher called CANONSTAGER, which used unconventional techniques to hide its activities. The final payload was a variant of the PlugX backdoor, tracked by Google as SOGU.SEC. The new PlugX variant overlaps with RainyDay and Turian backdoors, targeting telecommunications and manufacturing sectors in Central and South Asia. The campaign is linked to Mustang Panda, which also uses Bookworm malware.
Show sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
Information Snippets
-
UNC6384 is assessed to share tactical and tooling overlaps with Mustang Panda, a known Chinese hacking group.
First reported: 25.08.2025 21:112 sources, 3 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
The campaign uses a captive portal redirect to hijack web traffic and deliver the STATICPLUGIN downloader.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
STATICPLUGIN retrieves an MSI package from the same website and deploys the SOGU.SEC backdoor in memory.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The malware supports commands to exfiltrate files, log keystrokes, and launch remote command shells.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The captive portal hijack is used to deliver malware masquerading as an Adobe Plugin update.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The AitM attack is facilitated by compromised edge devices on the target networks.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The STATICPLUGIN downloader is signed by Chengdu Nuoxin Times Technology Co., Ltd with a valid certificate issued by GlobalSign.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The campaign was detected by Google Threat Intelligence Group (GTIG) in March 2025.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The campaign targeted around two dozen victims, primarily Southeast Asian diplomats, between March and July 2025.
First reported: 27.08.2025 22:311 source, 1 articleShow sources
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The attack chain involved compromised edge devices intercepting captive portal checks and redirecting users to a malicious website.
First reported: 27.08.2025 22:311 source, 1 articleShow sources
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The malicious website used a valid TLS/SSL certificate issued by Let's Encrypt to avoid browser security warnings.
First reported: 27.08.2025 22:311 source, 1 articleShow sources
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The first-stage malware, STATICPLUGIN, dropped a launcher called CANONSTAGER, which used unconventional techniques to hide its activities.
First reported: 27.08.2025 22:311 source, 1 articleShow sources
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The final payload was a variant of the PlugX backdoor, tracked by Google as SOGU.SEC.
First reported: 27.08.2025 22:312 sources, 2 articlesShow sources
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
The new PlugX variant overlaps with RainyDay and Turian backdoors in its use of legitimate applications for DLL side-loading, encryption/decryption algorithms, and RC4 keys.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
The PlugX variant uses a configuration structure similar to RainyDay, associated with Lotus Panda (Naikon APT).
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
The campaign targets telecommunications and manufacturing sectors in Central and South Asia.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
The attack chains involve abusing a legitimate executable associated with Mobile Popup Application to sideload a malicious DLL for payload execution.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
The PlugX variant includes an embedded keylogger plugin.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
The campaign is linked to Mustang Panda, which also uses Bookworm malware.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
Bookworm malware has been used since 2015 and includes capabilities to execute commands, upload/download files, exfiltrate data, and establish persistent access.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
Bookworm utilizes legitimate-looking domains or compromised infrastructure for C2 purposes.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
Bookworm variants share overlaps with TONESHELL, another backdoor associated with Mustang Panda.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
Bookworm employs a modular architecture that makes static analysis challenging.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
Similar Happenings
Confucius Targets Pakistan with WooperStealer and Anondoor Malware
The threat actor Confucius has launched a new phishing campaign targeting Pakistan, deploying WooperStealer and Anondoor malware. The campaign has targeted government agencies, military organizations, defense contractors, and critical industries since at least December 2024. The attacks use spear-phishing and malicious documents to deliver malware that steals sensitive data and exfiltrates device information. Confucius has shifted from document-focused stealers to more advanced Python-based backdoors like Anondoor, which provides long-term persistence and command execution capabilities. The group employs DLL side-loading, obfuscated PowerShell scripts, scheduled tasks, and stealthy exfiltration routines to achieve persistence and evade detection. Anondoor is capable of full host profiling, collecting system details, geolocating public IPs, and inventoring disk volumes before receiving tasking from its command-and-control (C2) servers.
Phantom Taurus Targets Government and Telecommunications Organizations
Government and telecommunications organizations in Africa, the Middle East, and Asia have been targeted by a China-aligned nation-state actor known as Phantom Taurus over the past two-and-a-half years. The group focuses on espionage, targeting ministries of foreign affairs, embassies, geopolitical events, and military operations. Phantom Taurus employs custom-developed tools and techniques, including a bespoke malware suite named NET-STAR, to maintain long-term intelligence collection and obtain confidential data from targets of strategic interest to China. The group's activities coincide with major global events and regional security affairs, demonstrating stealth, persistence, and adaptability in their tactics, techniques, and procedures (TTPs). Phantom Taurus has been observed using a .NET malware suite named NET-STAR to breach IIS web servers, which operates almost entirely in memory and includes a fileless backdoor that establishes encrypted command-and-control (C2) sessions. The suite includes a backdoor named IIServerCore that accepts commands and encoded .NET payloads, enabling arbitrary code execution on compromised systems. The suite also includes two AssemblyExecuter loaders (v1 and v2) that allow dynamic loading of additional .NET malware, with v2 featuring advanced evasion techniques such as AMSI and ETW bypass. The group uses custom SQL queries to search for specific tables and keywords on compromised systems, exporting all matching results. Additionally, Phantom Taurus's operational methods are supported by other custom malware, including TunnelSpecter and SweetSpecter, which are used for email exfiltration.
COLDRIVER APT Group Uses ClickFix Tactics to Deliver BAITSWITCH and SIMPLEFIX Malware
The COLDRIVER APT group has launched a new campaign using ClickFix tactics to deliver two new malware families, BAITSWITCH and SIMPLEFIX. The campaign targets individuals and organizations connected to Russia, including NGOs, human rights defenders, and think tanks. BAITSWITCH acts as a downloader for SIMPLEFIX, a PowerShell backdoor. The attack chain involves tricking victims into running a malicious DLL via a fake CAPTCHA check, leading to the deployment of the SIMPLEFIX backdoor. The malware exfiltrates specific file types and establishes communication with a command-and-control server. The campaign aligns with COLDRIVER's known victimology, focusing on civil society members connected to Russia. The group has been active since 2019, using spear-phishing and custom tools like SPICA and LOSTKEYS. The latest campaign demonstrates the group's continued use of effective infection vectors, despite their lack of technical sophistication.
CISA Emergency Directive 25-03: Mitigation of Cisco ASA Zero-Day Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 25-03, mandating federal agencies to identify and mitigate zero-day vulnerabilities in Cisco Adaptive Security Appliances (ASA) exploited by an advanced threat actor. The directive requires agencies to account for all affected devices, collect forensic data, and upgrade or disconnect end-of-support devices by September 26, 2025. The vulnerabilities allow threat actors to maintain persistence and gain network access. Cisco identified multiple zero-day vulnerabilities (CVE-2025-20333, CVE-2025-20362, CVE-2025-20363, and CVE-2025-20352) in Cisco ASA, Firewall Threat Defense (FTD) software, and Cisco IOS software. These vulnerabilities enable unauthenticated remote code execution, unauthorized access, and denial of service (DoS) attacks. GreyNoise detected large-scale campaigns targeting ASA login portals and Cisco IOS Telnet/SSH services, indicating potential exploitation of these vulnerabilities. The campaign is widespread and involves exploiting zero-day vulnerabilities to gain unauthenticated remote code execution on ASAs, as well as manipulating read-only memory (ROM) to persist through reboot and system upgrade. CISA and Cisco linked these ongoing attacks to the ArcaneDoor campaign, which exploited two other ASA and FTD zero-days (CVE-2024-20353 and CVE-2024-20359) to breach government networks worldwide since November 2023. CISA ordered agencies to identify all Cisco ASA and Firepower appliances on their networks, disconnect all compromised devices from the network, and patch those that show no signs of malicious activity by 12 PM EDT on September 26. CISA also ordered that agencies must permanently disconnect ASA devices that are reaching the end of support by September 30 from their networks. The U.K. National Cyber Security Centre (NCSC) confirmed that threat actors exploited the recently disclosed security flaws in Cisco firewalls to deliver previously undocumented malware families like RayInitiator and LINE VIPER. Cisco began investigating attacks on multiple government agencies in May 2025, linked to the state-sponsored ArcaneDoor campaign. The attacks targeted Cisco ASA 5500-X Series devices to implant malware, execute commands, and potentially exfiltrate data. The threat actor modified ROMMON to facilitate persistence across reboots and software upgrades. The compromised devices include ASA 5500-X Series models running specific software releases with VPN web services enabled. The Canadian Centre for Cyber Security urged organizations to update to a fixed version of Cisco ASA and FTD products to counter the threat. Nearly 50,000 Cisco ASA and FTD appliances are vulnerable to actively exploited flaws. The vulnerabilities CVE-2025-20333 and CVE-2025-20362 enable arbitrary code execution and access to restricted URL endpoints. The Shadowserver Foundation discovered over 48,800 internet-exposed ASA and FTD instances still vulnerable to the flaws. The majority of vulnerable devices are located in the United States, followed by the United Kingdom, Japan, Germany, Russia, Canada, and Denmark. The Shadowserver Foundation's data is as of September 29, indicating a lack of response to the ongoing exploitation activity. Greynoise had warned on September 4 about suspicious scans targeting Cisco ASA devices, indicating upcoming undocumented flaws. CISA's emergency directive gave 24 hours to FCEB agencies to identify and upgrade vulnerable Cisco ASA and FTD instances. CISA advised that ASA devices reaching their end of support should be disconnected from federal networks by the end of September. The U.K. NCSC reported that the hackers deployed Line Viper shellcode loader malware and RayInitiator GRUB bootkit.
Brickstorm Malware Used in Long-Term Espionage Against U.S. Organizations
The UNC5221 activity cluster, attributed to suspected Chinese hackers, has been using the BRICKSTORM malware in long-term espionage operations against U.S. organizations in the technology, legal, SaaS, and BPO sectors. The malware, a Go-based backdoor, has been active for over a year, with an average dwell time of 393 days. It has been used to steal data from various sectors, including SaaS providers and BPOs. The attackers exploit vulnerabilities in edge devices and use anti-forensics techniques to avoid detection. The malware serves multiple functions, including web server, file manipulation, dropper, SOCKS relay, and shell command execution. It targets appliances without EDR support, such as VMware vCenter/ESXi, and uses legitimate traffic to mask its C2 communications. The attackers aim to exfiltrate emails and maintain stealth through various tactics, including removing the malware post-operation to hinder forensic investigations. The attackers use a malicious Java Servlet Filter (BRICKSTEAL) on vCenter to capture credentials, and clone Windows Server VMs to extract secrets. The stolen credentials are used for lateral movement and persistence, including enabling SSH on ESXi and modifying startup scripts. The malware exfiltrates emails via Microsoft Entra ID Enterprise Apps, utilizing its SOCKS proxy to tunnel into internal systems and code repositories. UNC5221 focuses on developers, administrators, and individuals tied to China's economic and security interests. Mandiant has released a free scanner script to help defenders detect BRICKSTORM. The BRICKSTORM backdoor is under active development, with a variant featuring a delay timer for C2 communication. The attackers have exploited Ivanti Connect Secure zero-day vulnerabilities (CVE-2023-46805 and CVE-2024-21887) for initial access. The attackers have used a custom dropper to install a malicious Java Servlet filter (BRICKSTEAL) in memory, avoiding detection. The attackers have modified init.d, rc.local, or systemd files to ensure persistence on appliances. The attackers have targeted Windows environments in Europe since at least November 2022. The attackers have been linked to other related Chinese threat actors besides UNC5221. The campaign has been monitored by Mandiant since March 2025. The attackers have targeted downstream customers of compromised SaaS providers. The attackers are believed to be analyzing stolen source code to identify zero-day vulnerabilities in enterprise technologies. The attackers use a delay timer to lie dormant on infected systems until a hard-coded date. The malware employs Garble, an open-source tool, for code obfuscation to hide function names, structures, and logic. Brickstorm has been found on VMware vCenter and ESXi hosts, often deployed prior to pivoting to these systems. The attackers use legitimate cloud services like Cloudflare Workers or Heroku for C2 communications. The attackers use dynamic domains like sslip.io or nip.io that point directly to the C2 server’s IP. The attackers favor appliance and management-plane compromise, per-victim obfuscated Go binaries, delayed-start implants, and Web/DoH C2 to preserve stealth. The attackers harvest and use valid high-privilege credentials to appear as routine administrator tasks. The attackers deploy in-memory servlet filters, remove installer artifacts, and embed delayed-start logic to limit forensic traces. The attackers abuse virtualization management capabilities, such as cloning VMs to extract credential stores offline. The attackers deploy an in-memory Java Servlet filter on vCenter to intercept and decode web authentication to harvest high-privilege credentials. The attackers use a SOCKS proxy on compromised appliances to tunnel into internal networks for interactive access and file retrieval.