PULSE NAME
PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats
WHITE UNC6384 AlienVault 2025-08-26 Modified: 2025-09-25
15
IOCs
MEDIUM VOLUME
A sophisticated cyber espionage campaign attributed to the PRC-nexus threat actor UNC6384 targeted diplomats in Southeast Asia and other global entities. The attack chain involved hijacking web traffic through a captive portal redirect to deliver malware disguised as software updates. The multi-stage attack utilized advanced social engineering, adversary-in-the-middle techniques, and evasion tactics. The malware payload, SOGU.SEC backdoor, was deployed through a digitally signed downloader (STATICPLUGIN) and a side-loaded DLL (CANONSTAGER). The campaign demonstrated the evolving capabilities of PRC-nexus threat actors, employing stealthy tactics to avoid detection and leveraging legitimate Windows features for malicious purposes.
Indicators of Compromise (15)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0538e73fc195c3b4441721d4c60d0b96 2025-08-26
FileHash-MD5 52f42a40d24e1d62d1ed29b28778fc45 2025-08-26
FileHash-MD5 fa71d60e43da381ad656192a41e38724 2025-08-26
FileHash-SHA1 baa569318144905563b469a5a006ad54eb616a02 2025-08-26
FileHash-SHA1 c8744b10180ed59bf96cf79d7559249e9dcf0f90 2025-08-26
FileHash-SHA1 eca96bd74fb6b22848751e254b6dc9b8e2721f96 2025-08-26
FileHash-SHA256 3299866538aff40ca85276f87dd0cefe4eafe167bd64732d67b06af4f3349916 2025-08-26
FileHash-SHA256 4ed76fa68ef9e1a7705a849d47b3d9dcdf969e332bd5bcb68138579c288a16d3 2025-08-26
FileHash-SHA256 65c42a7ea18162a92ee982eded91653a5358a7129c7672715ce8ddb6027ec124 2025-08-26
FileHash-SHA256 cc4db3d8049043fa62326d0b3341960f9a0cf9b54c2fbbdffdbd8761d99add79 2025-08-26
FileHash-SHA256 d1626c35ff69e7e5bde5eea9f9a242713421e59197f4b6d77b914ed46976b933 2025-08-26
FileHash-SHA256 e787f64af048b9cb8a153a0759555785c8fd3ee1e8efbca312a29f2acb1e4011 2025-08-26
FileHash-SHA1 95a89dff5e42614e30ba6aab6623133043f6f122 2025-08-26
FileHash-SHA1 9e82021ffd943c51b1a164832ea5a6d28b16dec7 2025-08-26
domain mediareleaseupdates.com 2025-08-26