A China-nexus threat actor, assessed with medium confidence to be Mustang Panda, conducted a multi-stage attack campaign targeting the Arabian Gulf region using Middle East conflict-themed social engineering lures. The attack chain delivered a PlugX backdoor variant through a ZIP archive containing a malicious LNK file that downloaded a CHM file via cURL, extracted a TAR archive using hh.exe, and used DLL sideloading to execute heavily obfuscated shellcode. The PlugX variant supports HTTPS and DNS-over-HTTPS (DOH) for C2 communication and employs advanced obfuscation including control flow flattening, mixed boolean arithmetic, corrupted MZ/PE headers, and reflective DLL injection.
CHM Dropper
1 post
China-nexus Group Targets Arabian Gulf Region | ThreatLabz