Find notable cyber news and cases, enriched with sources, timelines, and signals.

PlugX DLL sideloading campaign targeting Central and South Asian telecom and manufacturing sectors

Campaign
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

PlugX is being distributed in an ongoing campaign that is targeting telecommunications and manufacturing sectors across Central and South Asian countries, raising the risk of repeated intrusion attempts and post-compromise access. The operation uses DLL sideloading and overlaps with tradecraft seen in RainyDay and Turian backdoors. Analysts say the similarities suggest a medium-confidence link to a Chinese-speaking actor. The campaign matters because it combines a broad regional target set with stealthy payload loading that can help evade detection.

Related Happenings

Mustang Panda Asia-Pacific and Japan CDN impersonation espionage campaign

Campaign
H score40 First: 14.05.2026 18:00 Last: 14.05.2026 18:00 Sources 1

About this happening: A Mustang Panda espionage campaign used CDN impersonation and DLL sideloading to target Asia-Pacific and Japan networks, extending from late September 2025 throu...

Mustang Panda spear-phishing campaign targeting Indian banks and US-Korea policy circles

Campaign
H score32 First: 21.04.2026 15:00 Last: 21.04.2026 15:00 Sources 1

About this happening: Mustang Panda launched a newly identified spear-phishing campaign that is aimed largely at financial organizations in India and also reaches US-Korea public policy c...

LotusLite backdoor delivered via DLL sideloading

Malware Activity
H score22 First: 21.04.2026 15:00 Last: 21.04.2026 15:00 Sources 1

About this happening: The Mustang Panda campaign spans an April 2026 wave against India's banking sector and US-Korea policy circles and a later June 12–22, 2026 wave against Indi...

Latest development: 29.06.2026 18:03

Acronis observed Mustang Panda campaigns against Indian government and hydropower targets using SHARDLOADER, MINIRECON, and ZOHOMURK, with Zoho WorkDrive abused as a command-and-control and exfiltration channel. The activity involved spear-phishing ZIP archives, DLL sideloading through signed binaries such as Solid PDF Creator and Citrix Receiver, and active beaconing from June 12 to June 22, 2026; Acronis also found active compromises inside Indian government networks and worked with CERT-In on notification and cleanup.

Dohdoor backdoor activity on Windows endpoints

Malware Activity
H score23 First: 26.02.2026 17:17 Last: 26.02.2026 17:17 Sources 1

About this happening: A new Dohdoor backdoor is being used to provide DNS-over-HTTPS (DoH) C2 and reflective payload execution on Windows endpoints, increasing stealth and post-compromi...

DKnife gateway-monitoring malware framework

Malware Activity
H score23 First: 06.02.2026 19:00 Last: 06.02.2026 19:00 Sources 1

About this happening: The discovery of DKnife exposes a long-running malware framework that has remained active since at least 2019, raising the risk of gateway-level traffic interception...

Timeline

  1. 27.09.2025 15:06 2 articles · 9mo ago

    Ongoing PlugX campaign targets Central and South Asian telecom and manufacturing sectors

    Initial Disclosure

    Analysts reported an ongoing PlugX campaign against telecommunications and manufacturing sectors in Central and South Asia, using a legitimate Mobile Popup Application executable to sideload a malicious DLL that decrypts and launches PlugX, RainyDay, and Turian payloads in memory. The PlugX variant's configuration diverges from the usual format and instead matches RainyDay structure, with overlapping DLL side-loading, XOR-RC4-RtlDecompressBuffer encryption and decryption, RC4 key reuse, and an embedded keylogger plugin, supporting a medium-confidence link to a Chinese-speaking actor.

    Show sources