Wednesday , September 24 2025
PlugX

Cisco Unveils New PlugX Backdoor Linked to Chinese APTs

Cisco Talos researchers have discovered an ongoing espionage campaign since 2022, targeting telecom and manufacturing sectors in Central and South Asia. The campaign uses a new variant of the PlugX backdoor, closely related to the RainyDay and Turian malware families linked to Chinese-speaking APT groups.

Cisco Unveils New PlugX Backdoor Linked to Chinese APTs

Cisco Talos researchers have discovered an ongoing espionage campaign since 2022, targeting telecom and manufacturing sectors in Central and South...
Read More
Cisco Unveils New PlugX Backdoor Linked to Chinese APTs

Malaysia: Submarine Cable to Strengthen APAC Digital Backbone

A submarine cable project will enhance the digital infrastructure of the Asia-Pacific region. Covering around 8,000 kilometers underwater, it's set...
Read More
Malaysia: Submarine Cable to Strengthen APAC Digital Backbone

U.S. Secret Service Seizes 100K Cards and 300 SIM Servers network

The U.S. Secret Service dismantled a network of electronic devices located throughout the New York tristate area that were used...
Read More
U.S. Secret Service Seizes 100K Cards and 300 SIM Servers network

Massive 22.2 Tbps DDoS Attack Sets New World Record

Cloudflare announced today that it has successfully defended against the largest recorded DDoS attack, which peaked at 22.2 terabits per...
Read More
Massive 22.2 Tbps DDoS Attack Sets New World Record

Microsoft to Build the “World’s Most Powerful AI Data Center”

Microsoft has announced a new $4 billion investment in Wisconsin for a second hyperscale AI data center. This adds to...
Read More
Microsoft to Build the “World’s Most Powerful AI Data Center”

Fraudsters swipe Tk 27 lakh from SCB cardholders

An organised racket has reportedly siphoned off lakhs from Standard Chartered Bangladesh's (SCB) credit card holders, raising serious cybersecurity concerns....
Read More
Fraudsters swipe Tk 27 lakh from SCB cardholders

EDR-Freeze: A Tool That Puts EDRs And Antivirus Into A Coma State

A new proof-of-concept tool named EDR-Freeze has been developed, capable of placing Endpoint Detection and Response (EDR) and antivirus solutions...
Read More
EDR-Freeze: A Tool That Puts EDRs And Antivirus Into A Coma State

First-ever AI-powered ‘MalTerminal’ Malware Uses OpenAI GPT-4 to Generate Code

AI-driven malware called 'MalTerminal' utilizes OpenAI's GPT-4 to create harmful code like ransomware and reverse shells, indicating a major change...
Read More
First-ever AI-powered ‘MalTerminal’ Malware Uses OpenAI GPT-4 to Generate Code

Gmail Data exposes via ChatGPT Deep Research Agent dubbed “ShadowLeak Zero-Click” Flaw

Cybersecurity researchers revealed a zero-click vulnerability in OpenAI ChatGPT's Deep Research agent that lets attackers leak sensitive Gmail inbox data...
Read More
Gmail Data exposes via ChatGPT Deep Research Agent dubbed “ShadowLeak Zero-Click” Flaw

Cyber attack disrupts several European airports: check-in and boarding systems affected

Several European airports are experiencing flight delays and cancellations due to a cyber attack on a check-in and boarding systems...
Read More
Cyber attack disrupts several European airports: check-in and boarding systems affected

According to the report, “Cisco Talos discovered a new campaign active since 2022, targeting the telecommunications and manufacturing sectors in Central and South Asian countries, delivering a new variant of PlugX.”

The newly discovered PlugX variant isn’t just another fork of the notorious RAT — it borrows heavily from other espionage toolkits. Talos notes that, “the new variant’s features overlap with both the RainyDay and Turian backdoors, including abuse of the same legitimate applications for DLL sideloading, the XOR-RC4-RtlDecompressBuffer algorithm used to encrypt/decrypt payloads and the RC4 keys used.”

These similarities imply either a common source providing services to different groups or that Naikon and BackdoorDiplomacy might be one and the same.

Figure 14. Loader for each malware family that includes a PDB., source: CISCO Talos

The campaign’s unique PlugX configuration format provided key attribution clues. Unlike standard PlugX builds, this variant mirrors the RainyDay configuration structure, leading Talos to assess “with medium confidence that this variant of PlugX can be attributed to Naikon.”

Naikon, a Chinese espionage group active since 2010, has often targeted government, military, and telecom sectors in Asia. The PlugX variant is part of Naikon’s tools.

The most interesting finding is the overlap between Naikon and BackdoorDiplomacy, another APT group that uses the Turian backdoor.

Talos researchers explain: “Our analysis of the victimology and technical malware implementation has uncovered evidence that indicates a potential connection between the two threat actors and suggests that they are the same group or that both are sourcing their tools from the same vendor.”

Both groups continue to prioritize telecom targets in South and Central Asia, with campaigns sometimes hitting adjacent countries — a pattern consistent with long-term, regionally focused espionage.

Check Also

EDR-Freeze

EDR-Freeze: A Tool That Puts EDRs And Antivirus Into A Coma State

A new proof-of-concept tool named EDR-Freeze has been developed, capable of placing Endpoint Detection and …