← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats
A sophisticated cyber espionage campaign attributed to the PRC-nexus threat actor UNC6384 targeted diplomats in Southeast Asia and other global entities. The attack chain involved hijacking web traffic through a captive portal redirect to deliver malware disguised as software updates. The multi-stage attack utilized advanced social engineering, adversary-in-the-middle techniques, and evasion tactics. The malware payload, SOGU.SEC backdoor, was deployed through a digitally signed downloader (STATICPLUGIN) and a side-loaded DLL (CANONSTAGER). The campaign demonstrated the evolving capabilities of PRC-nexus threat actors, employing stealthy tactics to avoid detection and leveraging legitimate Windows features for malicious purposes.
MITRE ATT&CK & Malware Families
Indicators of Compromise (5 / 15 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | baa569318144905563b469a5a006ad54eb616a02 | — | 2025-08-26 | |
| FileHash-SHA1 | c8744b10180ed59bf96cf79d7559249e9dcf0f90 | — | 2025-08-26 | |
| FileHash-SHA1 | eca96bd74fb6b22848751e254b6dc9b8e2721f96 | — | 2025-08-26 | |
| FileHash-SHA1 | 95a89dff5e42614e30ba6aab6623133043f6f122 | — | 2025-08-26 | |
| FileHash-SHA1 | 9e82021ffd943c51b1a164832ea5a6d28b16dec7 | — | 2025-08-26 |