Cyber Team (@cyberteam008) 's Twitter Profile Photo

#PlugX / #KorPlug Activity File: DXSETUP.ZIP abe098329cacc452714a6e8e632dcfdb C2: 149.104.2[.]7:443 File: DSETUP.dll 02613d0cfa2863efeda0508b5118ebf9 File: DXSETUP.exe 11dd6e8ab9759d1ac91ffe0d0e4949cb Persistence via SCH Task: "DXUpdate" #APT #Malware #ioc

#PlugX / #KorPlug Activity

File: DXSETUP.ZIP
abe098329cacc452714a6e8e632dcfdb
C2: 149.104.2[.]7:443

File: DSETUP.dll
02613d0cfa2863efeda0508b5118ebf9

File: DXSETUP.exe
11dd6e8ab9759d1ac91ffe0d0e4949cb

Persistence via SCH Task: "DXUpdate"

#APT #Malware #ioc
The Daily Tech Feed (@dailytechonx) 's Twitter Profile Photo

Chinese APT group Mustang Panda escalates cyber espionage in Europe using Korplug loaders and malicious USB drives. Stay vigilant! #CyberSecurity #APT #MustangPanda #Korplug #USBThreats thedailytechfeed.com/chinese-apt-gr…

Cyber Team (@cyberteam008) 's Twitter Profile Photo

#PlugX #RAT/ #KorPlug Trinity Sample File: mm[.]zip (0-VT) 8a197d4fd4982a158b53944341b5ae35 C2: 103.56.18[.]101: {53 & 443} File: arphaDump64.dll 24f470a75493bb99a2c957ba2f9f45ad File: arphaCrashReport.exe 33f5251edb3fff756692087ecb8ddfdf #Malware #ioc #MustangPanda #APT

#PlugX #RAT/ #KorPlug Trinity Sample

File: mm[.]zip (0-VT)
8a197d4fd4982a158b53944341b5ae35
C2: 103.56.18[.]101: {53 & 443}

File: arphaDump64.dll
24f470a75493bb99a2c957ba2f9f45ad

File: arphaCrashReport.exe
33f5251edb3fff756692087ecb8ddfdf

#Malware #ioc #MustangPanda #APT
Cyber Team (@cyberteam008) 's Twitter Profile Photo

#Plugx #RAT / #KorPlug Activity File: Squadcloud.zip 93c358440e05d5faf54a1ce628364684 File: CoreFoundation.dll 5afe443ddabb1ade4e5bb4b0eb80894b File: iTunesHelper.exe 6ce6784df5fc5b8550c44f90382c2cdd POST C2: 43.230.9[.]230:53 / cisco.893yakuza[.]com #Malware #ioc

#Plugx #RAT / #KorPlug Activity

File: Squadcloud.zip
93c358440e05d5faf54a1ce628364684

File: CoreFoundation.dll 
5afe443ddabb1ade4e5bb4b0eb80894b

File: iTunesHelper.exe
6ce6784df5fc5b8550c44f90382c2cdd

POST C2: 43.230.9[.]230:53 / cisco.893yakuza[.]com

#Malware #ioc
Yogesh Londhe (@suyog41) 's Twitter Profile Photo

Korplug / PlugX Meeting Invitation.msc 026a6ed068b12ea1447ca20d4f82452f drops 6aa266.msi 7c23b3eb95d4f5be3dae181c2c473573 hid.dll 1fdae36641f385b30541331611105598 C2 : loginge[.]com #Korplug #PlugX #GrimResource #IOC

Yogesh Londhe (@suyog41) 's Twitter Profile Photo

Korplug / PlugX ADSOM-Plus - Meeting Programme.msc 512e26cf94f44c2a80d8fed73995c778 drops 5ec990.msi 7f23b0377c7ca504fa18d04c14d8f617 hid.dll 9f57211facd9ce7e600da450bcb9aa2a #Korplug #PlugX #GrimResource #IOC

Korplug / PlugX

ADSOM-Plus - Meeting Programme.msc
512e26cf94f44c2a80d8fed73995c778

drops 

5ec990.msi
7f23b0377c7ca504fa18d04c14d8f617

hid.dll
9f57211facd9ce7e600da450bcb9aa2a

#Korplug #PlugX  #GrimResource #IOC
Cyber Team (@cyberteam008) 's Twitter Profile Photo

#China's #Korplug / #PlugX Targeting #Indonesian Govt. Intelligence agency National Cyber and Crypto Agency (Indonesian: Badan Siber dan Sandi Negara [BSSN], lit. 'State Cyber and Signal Agency'). Infra: bssn-gov[.]id 45.133.239[.]183 38.60.171[.]133 Mikhail Kasimov #Malware #ioc

twelvesec (@twelvesec) 's Twitter Profile Photo

China-linked APT group #MustangPanda targeted various Asian countries with the #DOPLUGS variant of the #PlugX (aka #Korplug) #backdoor. #CyberSecurity #infosec #cybercrime buff.ly/48sqD79

China-linked APT group #MustangPanda targeted various Asian countries with the #DOPLUGS variant of the #PlugX (aka #Korplug) #backdoor.
#CyberSecurity #infosec #cybercrime
buff.ly/48sqD79
Brier & Thorn México (@brierandthornmx) 's Twitter Profile Photo

El actor de amenazas vinculado a China conocido como Mustang Panda se ha dirigido a varios países asiáticos utilizando una variante de la puerta trasera #PlugX (también conocida como #Korplug) denominada #DOPLUGS. #2024 #Infosec #BT thehackernews.com/2024/02/mustan… brierandthorn.com/?utm_campaign=…

Brier & Thorn, Inc. (@brierandthorn) 's Twitter Profile Photo

The China-linked threat actor known as #MustangPanda has targeted various Asian countries using a variant of the #PlugX (aka #Korplug) backdoor dubbed #DOPLUGS. #2024 #Infosec #BT thehackernews.com/2024/02/mustan… brierandthorn.com/?utm_campaign=…

Fletch (Acquired by F5) (@fletch_ai) 's Twitter Profile Photo

Fletch Top Threat Alert: Exploitation Methods Used by PlugX Malware Revealed by Splunk Research - #PlugX #FletchScore = Medium/Mainstream #CyberSecurity #ThreatIntel #InfoSec #PlugX #RedDelta #KORPLUG #Hodur hubs.li/Q02czTPg0