216.73.217.55

Threat Actor Targets Arabian Gulf Region With PlugX

· Published 13/04/2026 14:40 · Modified 13/04/2026 14:48

Export JSON

Essential information

Published
13/04/2026 14:40
Modified
13/04/2026 14:48
Tags
2026-04-13 arabian gulf china-nexus chm dropper control flow flattening destroyrat dll sideloading doplugs kaba korplug lnk file plugx reflective loading sogu thoper tvt
Related entities
13 observables, 1 intrusion sets (apt), 17 techniques (mitre), 2 malware

Description

In March 2026, a threat actor launched a sophisticated campaign targeting countries in the region, exploiting renewed Middle East conflict themes within 24 hours of escalation. The attack utilized Arabic-language lures depicting missile strikes and employed a multi-stage infection chain beginning with weaponized ZIP archives containing malicious LNK and CHM files. The campaign deployed a heavily obfuscated backdoor variant through , with components using and mixed boolean arithmetic techniques. The backdoor supports HTTPS command-and-control communications, DNS-over-HTTPS resolution, and multiple plugins for system manipulation. Based on tools, techniques, and procedures including specific RC4 decryption keys and rapid geopolitical weaponization, the activity is attributed with medium confidence to Mustang Panda.

External references