{"id":7100,"date":"2025-09-27T16:05:47","date_gmt":"2025-09-27T16:05:47","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=7100"},"modified":"2025-09-27T16:05:47","modified_gmt":"2025-09-27T16:05:47","slug":"china-linked-plugx-and-bookworm-malware-assaults-goal-asian-telecom-and-asean-networks","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=7100","title":{"rendered":"China-Linked PlugX and Bookworm Malware Assaults Goal Asian Telecom and ASEAN Networks"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 27, 2025<\/span><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><\/span><span class=\"p-tags\">Malware \/ Community Safety<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEguYYSthetRned7BJluVsTwZpaYHxn97hK7zhcV-0wUQL0w8S-hBL08eJ_yO300oWmb68pkiUZSJ4V9XLg-MpNz3sTZ72jK1EWu-LO_cdmMtDRqZ5SJYGiDbyIMTVPWOiixGvAReC7RLnCQD36Y0hL4WOOvqGCDq27SF1w_rHwljhq9Qo5UEsmWwN5Htrym\/s728-rw-e365\/chinese-hackers.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEguYYSthetRned7BJluVsTwZpaYHxn97hK7zhcV-0wUQL0w8S-hBL08eJ_yO300oWmb68pkiUZSJ4V9XLg-MpNz3sTZ72jK1EWu-LO_cdmMtDRqZ5SJYGiDbyIMTVPWOiixGvAReC7RLnCQD36Y0hL4WOOvqGCDq27SF1w_rHwljhq9Qo5UEsmWwN5Htrym\/s728-rw-e365\/chinese-hackers.jpg\" alt=\"\" border=\"0\" data-original-height=\"380\" data-original-width=\"728\"\/><\/a><\/div>\n<p>Telecommunications and manufacturing sectors in Central and South Asian nations have emerged because the goal of an ongoing marketing campaign distributing a brand new variant of a identified malware referred to as <b>PlugX <\/b>(aka Korplug or SOGU).<\/p>\n<p>&#8220;The brand new variant&#8217;s options overlap with each the <b>RainyDay <\/b>and <b>Turian <\/b>backdoors, together with abuse of the identical authentic functions for DLL side-loading, the XOR-RC4-RtlDecompressBuffer algorithm used to encrypt\/decrypt payloads and the RC4 keys used,&#8221; Cisco Talos researchers Joey Chen and Takahiro Takeda <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blog.talosintelligence.com\/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking\/\" rel=\"noopener\" target=\"_blank\">stated<\/a> in an evaluation printed this week.<\/p>\n<p>The cybersecurity firm famous that the configuration related to the PlugX variant diverges considerably from the same old PlugX configuration format, as an alternative adopting the identical construction utilized in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2021\/04\/chinese-hackers-attacking-military.html\" rel=\"noopener\" target=\"_blank\">RainyDay<\/a>, a backdoor related to a China-linked risk actor often called <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2024\/06\/chinese-cyber-espionage-targets-telecom.html\" rel=\"noopener\" target=\"_blank\">Lotus Panda<\/a> (aka Naikon APT). It is also seemingly tracked by Kaspersky as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2021\/04\/hackers-from-china-target-vietnamese.html\" rel=\"noopener\" target=\"_blank\">FoundCore<\/a> and attributed to a Chinese language-speaking risk group it calls Cycldek.<\/p>\n<div class=\"dog_two clear\"><center class=\"cf\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.uk\/exec-guide-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"DFIR Retainer Services\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi9iVdehXfY5Lf2w6kHiSBvqBKObMNz5qOYJvvPLalbmwhZW9mhD8jq_JewI31BqUKa3JMLdcUhUraSDagTpDMl0VW5P1C4gNgCxbSqDoiiTW9iaDgYxUvhONhIYQS4fu4KrujwpOUlgDAztJqmrJorS5Aj2nK83_0vay5a1BlYJQXlhCF72VPBTYLyodaZ\/s728-rw-e100\/desktop-1.png\" width=\"729\" height=\"91\"\/><\/a><\/center><\/div>\n<p>PlugX is a modular distant entry trojan (RAT) broadly utilized by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2024\/06\/china-linked-hackers-infiltrate-east.html\" rel=\"noopener\" target=\"_blank\">many China-aligned hacking<\/a> teams, however most prominently by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/08\/unc6384-deploys-plugx-via-captive.html\" rel=\"noopener\" target=\"_blank\">Mustang Panda<\/a> (aka BASIN, Bronze President, Camaro Dragon, Earth Preta, HoneyMyte, RedDelta, Pink Lich, Stately Taurus, TEMP.Hex, and Twill Hurricane).<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2022\/12\/chinese-hackers-target-middle-east.html\" rel=\"noopener\" target=\"_blank\">Turian<\/a> (aka Quarian or Whitebird), however, is assessed to be a backdoor completely employed in cyber assaults focusing on the Center East by one other superior persistent risk (APT) group with ties to China known as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2023\/01\/iranian-government-entities-under.html\" rel=\"noopener\" target=\"_blank\">BackdoorDiplomacy<\/a> (aka <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/01\/new-eagerbee-variant-targets-isps-and.html\" rel=\"noopener\" target=\"_blank\">CloudComputating<\/a> or Faking Dragon).<\/p>\n<p>The victimology patterns \u2013 significantly the give attention to telecommunications corporations \u2013 and technical malware implementation had yielded proof suggesting seemingly connections between Lotus Panda and BackdoorDiplomacy, elevating the chance that both the 2 clusters are one and the identical, or that they&#8217;re acquiring their instruments from a standard vendor.<\/p>\n<p>In a single incident detected by the corporate, Naikon is claimed to have focused a telecom agency in Kazakhstan, a rustic that shares its borders with Uzbekistan, which has been beforehand singled out by BackdoorDiplomacy. What&#8217;s extra, each hacking crews have been discovered to zero in on South Asian nations.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" name=\"more\"\/><\/p>\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh_6kBZjMxU_YycMJXx2b12dNoVrzLpdv02kBStyc4rYqOnCul507pbONPTtFwXQRYBR6sQTeb1fGNS1jn6xtALRk1yjeGCWSJUwqlxUjVB6Uw1kXJ8dzQSoWEbIweFftJXiU0d463yDpPMPbDn7z3zGZN535aJEgN7zD19K8QhvB5hxKl3qE-Tt5NfLQtv\/s728-rw-e365\/Turian.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh_6kBZjMxU_YycMJXx2b12dNoVrzLpdv02kBStyc4rYqOnCul507pbONPTtFwXQRYBR6sQTeb1fGNS1jn6xtALRk1yjeGCWSJUwqlxUjVB6Uw1kXJ8dzQSoWEbIweFftJXiU0d463yDpPMPbDn7z3zGZN535aJEgN7zD19K8QhvB5hxKl3qE-Tt5NfLQtv\/s728-rw-e365\/Turian.jpg\" alt=\"\" border=\"0\" data-original-height=\"633\" data-original-width=\"1000\"\/><\/a><\/div>\n<p>The assault chains basically contain abusing a authentic executable related to Cell Popup Utility to sideload a malicious DLL that is then used to decrypt and launch PlugX, RainyDay, and Turian payloads in reminiscence. Current assault waves orchestrated by the risk actor have closely leaned on PlugX, which makes use of the identical configuration construction as RainyDay and consists of an embedded keylogger plugin.<\/p>\n<p>&#8220;Whereas we can not conclude that there&#8217;s a clear connection between Naikon and BackdoorDiplomacy, there are vital overlapping features \u2013 comparable to the selection of targets, encryption\/decryption payload strategies, encryption key reuse and use of instruments supported by the identical vendor,&#8221; Talos stated. &#8220;These similarities recommend a medium confidence hyperlink to a Chinese language-speaking actor on this marketing campaign.&#8221;<\/p>\n<h3>Mustang Panda&#8217;s Bookworm Malware Detailed<\/h3>\n<p>The disclosure comes as Palo Alto Networks Unit 42 sheds mild on the inside workings of the Bookworm malware utilized by the Mustang Panda actor <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/unit42.paloaltonetworks.com\/attack-campaign-on-the-government-of-thailand-delivers-bookworm-trojan\/\" rel=\"noopener\" target=\"_blank\">since 2015<\/a> to achieve in depth management over compromised programs. The superior RAT comes fitted with capabilities to execute arbitrary instructions, add\/obtain recordsdata, exfiltrate knowledge, and set up persistent entry.<\/p>\n<p>Earlier this March, the cybersecurity vendor <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/02\/chinese-hackers-exploit-mavinjectexe-to.html\" rel=\"noopener\" target=\"_blank\">stated<\/a> it recognized assaults focusing on nations affiliated with the Affiliation of Southeast Asian Nations (ASEAN) to distribute the malware.<\/p>\n<div class=\"dog_two clear\"><center class=\"cf\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.uk\/cis-security-suite\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"CIS Build Kits\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjgkDdKZ4cf4syb2qVDyt76MS6-Iq2eLoi0woZ-R0yota4fauhbh-Ro40IHQaAcKWPGCf_BGWQSZd2VSdPJGkMefmls9YYuzVlgZ-mcdepOR1mlwFMTj2gqiGP5jHrt1VgmX72osdiB6x5DG-Tz1js5zJktU0pbKWFWqcqytxwSQZR9bRWMa9CBjiUDqomg\/s728-rw-e100\/cis-d.png\" width=\"729\" height=\"91\"\/><\/a><\/center><\/div>\n<p>Bookworm makes use of legitimate-looking domains or compromised infrastructure for C2 functions in order to mix in with regular community site visitors. Choose variants of the malware have additionally been discovered to share overlaps with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/09\/mustang-panda-deploys-snakedisk-usb.html\" rel=\"noopener\" target=\"_blank\">TONESHELL<\/a>, a identified backdoor related to Mustang Pana since late 2022.<\/p>\n<p>Like PlugX and TONESHELL, assault chains distributing Bookworm depend on DLL side-loading for payload execution, though newer variants have embraced a method that includes packaging shellcode as universally distinctive identifier (UUID) strings, that are then decoded and executed.<\/p>\n<p>&#8220;Bookworm is understood for its distinctive modular structure, permitting its core performance to be expanded by loading extra modules instantly from its command-and-control (C2) server,&#8221; Unit 42 researcher Kyle Wilhoit <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/unit42.paloaltonetworks.com\/bookworm-to-stately-taurus\/\" rel=\"noopener\" target=\"_blank\">stated<\/a>. &#8220;This modularity makes static evaluation more difficult, because the Chief module depends on different DLLs to offer particular performance.&#8221;<\/p>\n<p>&#8220;This deployment and adaptation of Bookworm, working in parallel with different Stately Taurus operations, showcases its long-term function within the actor&#8217;s arsenal. It additionally factors to a sustained, long-term dedication to its growth and use by the group.&#8221;<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>\ue802Sep 27, 2025\ue804Ravie LakshmananMalware \/ Community Safety Telecommunications and manufacturing sectors in Central and South Asian nations have emerged because the goal of an ongoing marketing campaign distributing a brand new variant of a identified malware referred to as PlugX (aka Korplug or SOGU). &#8220;The brand new variant&#8217;s options overlap with each the RainyDay and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":7102,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[5580,5579,145,5578,536,216,667,5577,70,4976],"class_list":["post-7100","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-asean","tag-asian","tag-attacks","tag-bookworm","tag-chinalinked","tag-malware","tag-networks","tag-plugx","tag-target","tag-telecom"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/7100","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7100"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/7100\/revisions"}],"predecessor-version":[{"id":7101,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/7100\/revisions\/7101"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/7102"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7100"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7100"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7100"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-05-27 03:48:52 UTC -->