China-nexus Threat Actor Targets Persian Gulf Region With PlugX
March 16, 2026, 10:52 a.m.
Description
A China-nexus threat actor targeted countries in the Persian Gulf region using a multi-stage attack chain to deploy a PlugX backdoor variant. The campaign exploited the renewed Middle East conflict, using an Arabic-language document lure depicting missile attacks. The attack utilized a ZIP archive containing a malicious Windows shortcut file, which downloaded a CHM file leading to the deployment of PlugX. The malware employed various obfuscation techniques, including control flow flattening and mixed boolean arithmetic. The PlugX variant supported HTTPS for command-and-control communication and DNS-over-HTTPS for domain resolution. Based on the tools and tactics used, the activity is attributed to a China-nexus actor, possibly linked to Mustang Panda.
Tags
Date
- Created: March 16, 2026, 10:26 a.m.
- Published: March 16, 2026, 10:26 a.m.
- Modified: March 16, 2026, 10:52 a.m.
Indicators
- ef7a813124fd19d11bb5d944cb95779f5fe09ff5a18c26399002759d4b0d66e7
- fa3a1153018ac1e1a35a65e445a2bad33eac582c225cf6c38d0886802481cd43
- e50a4069e173256498e9e801b8f0dcda5a217290869300055ad8a854d4ea210c
- 10df3c46624c416f44764d7903b8079bc797c967284afc5bc333eeba0fdbba18
- c78eb1cecef5f865b6d150adcf67fa5712c5a16b94f1618c32191e61fbe69590
- 5adae26409c6576f95270ce9ca3877df3ee60849c18540fd92c0c9c974ba2f6d
- 1ddbed0328a60bb4f725b4ef798d5d14f29c04f7ffe9a7a6940cacb557119a1c
- 014192c07267294116115d867b1dd48d851f0fa4c011cd96e4c5a5f81a6d1de3
- 733a0a0ead4fc38173d7e30c7f2e14442ede32507e8adcbb8d3bd719fd2079d0
- 91.193.17.117
- www.360printsol.com
Attack Patterns
- PlugX - S0013
- Sogu
- Mustang Panda
Additional Informations
- Defense
- Government
- Bahrain