PULSE NAME
Chinese Cyber Espionage Group Attacking Asia
WHITE PKPLUG AlienVault 2019-10-04 Modified: 2019-10-04
531
IOCs
HIGH VOLUME
For three years, Unit 42 has tracked a set of cyber espionage attack campaigns across Asia, which used a mix of publicly available and custom malware. Unit 42 created the moniker “PKPLUG” for the threat actor group, or groups, behind these and other documented attacks referenced later in this report. We say group or groups as our current visibility doesn’t allow us to determine with high confidence if this is the work of one group, or more than one group which uses the same tools and has the same tasking. The name comes from the tactic of delivering PlugX malware inside ZIP archive files as part of a DLL side-loading package. The ZIP file format contains the ASCII magic-bytes “PK” in its header, hence PKPLUG.
Indicators of Compromise (6 / 531 total)
All URL hostname FileHash-SHA256 domain FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 7c9689e015563410d331af91e0a0be8c 2019-10-04
FileHash-MD5 0011fb4f42ee9d68c0f2dc62562f53e0 2019-10-04
FileHash-MD5 661d4e056c8c0f6804cac7e6b24a79ec 2019-10-04
FileHash-MD5 e798a7c33a58fc249965ac3de0fee67b 2019-10-04
FileHash-MD5 cb9a199fc68da233cec9d2f3d4deb081 2019-10-04
FileHash-MD5 b862a2cfe8f79bdbb4e1d39e0cfcae3a 2019-10-04