TA416 Returns back with a Golang PlugX Malware Loader

 


TA416 Returns back with a Golang PlugX Malware Loader
 

APT group TA416 reemerges with new changes to its documented toolsets so it can continue launching espionage campaigns.
Chinese advanced persistent threat (APT) group TA416, whose previous activity has been attributed to "Mustang Panda" and "RedDelta," has resumed attack activity.
This new activity appears to be a continuation of previously reported campaigns that have targeted entities associated with diplomatic relations between the Vatican and the Chinese Communist Party, as well as entities in Myanmar and groups conducting diplomacy in Africa.

Based on the available information, the actor's tool set, which they used to deliver PlugX malware payloads is detected as a new Golang variant of TA416's PlugX malware loader and noticed the PlugX malware is consistently used in targeted campaigns. This signifies the group's persistence in changing its toolset to evade detection.

Indicators of Compromise

File Hash

930b7a798e3279b7460e30ce2f3a2deccbc252f3ca213cb022f5b7e6a25a0867
6a5b0cfdaf402e94f892f66a0f53e347d427be4105ab22c1a9f259238c272b60
0459e62c5444896d5be404c559c834ba455fa5cae1689c70fc8c61bc15468681
235752f22f1a21e18e0833fc26e1cdb4834a56ee53ec7acb8a402129329c0cdd
e3e3c28f7a96906e6c30f56e8e6b013e42b5113967d6fb054c32885501dfd1b7
afa06df5a2c33dc0bdf80bbe09dade421b3e8b5990a56246e0d7053d5668d917

IP
45.248.87[.]162

Comments

Popular posts from this blog

Revil Ransomware Targeted Kaseya

Buer Loader provides malware-as-a-service

BANDOOK(RAT)