lab52 · Crawled Jul 31, 2026
PlugX Meeting Invitation via MSBuild and GDATA
15 IoCs 9 Actors 6 Malware
Read original article ↗
AI Summary
A recent PlugX RAT campaign leverages a spear-phishing email with the subject 'Meeting Invitation' to deliver malicious payloads via DLL side-loading. The infection chain uses a legitimate G DATA antivirus executable (Avk.exe) to load a malicious DLL (Avk.dll), which decrypts and executes the payload from AVKTray.dat. The malware establishes persistence through a registry Run key and communicates with the C2 server at decoorat[.]net over HTTPS on port 443. The campaign demonstrates continued use of trusted binaries, XOR-based obfuscation, and API hashing techniques consistent with China-aligned threat actors.
AI-extracted · verify before operational use
Extracted Entities 15 found
Malware PlugX → Threat Actor MUSTANG PANDA → Threat Actor APT41 → Threat Actor APT10 → Threat Actor APT19 → Threat Actor UNC6384 → Threat Actor APT29 → Threat Actor UNC2452 → Threat Actor OilRig → Threat Actor LOTUS PANDA → Malware EnvyScout → Malware WINELOADER → Malware GRAPELOADER → Malware TONEDEAF → Malware Emissary →
Indicators of Compromise 15 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | onedown[.]gesecole[.]net | Details → |
| Domain | decoraat[.]net | Details → |
| SHA-256 | 7ed0cd4115f3ff35c38d36cc50c6a13eba2d845554439a36108789cd1e05b176 | Details → |
| SHA-256 | 46314092c8d00ab93cbbdc824b9fc39dec9303169163b9625bae3b1717d70ebc | Details → |
| SHA-256 | 8421e7995778faf1f2a902fb2c51d85ae39481f443b7b3186068d5c33c472d99 | Details → |
| SHA-256 | 29cd44aa2a51a200d82cca578d97dc13241bc906ea6a33b132c6ca567dc8f3ad | Details → |
| SHA-256 | de8ddc2451fb1305d76ab20661725d11c77625aeeaa1447faf3fbf56706c87f1 | Details → |
| SHA-256 | 5f9af68db10b029453264cfc9b8eee4265549a2855bb79668ccfc571fb11f5fc | Details → |
| SHA-256 | d293ded5a63679b81556d2c622c78be6253f500b6751d4eeb271e6500a23b21e | Details → |
| SHA-256 | 6df8649bf4e233ee86a896ee8e5a3b3179c168ef927ac9283b945186f8629ee7 | Details → |
| Filename | Invitation_Letter_No.02_2026.csproj | Details → |
| Filename | Invitation_Letter_No.02_2026.exe | Details → |
| Filename | Avk.dll | Details → |
| Filename | AVK.exe | Details → |
| Filename | AVKTray.dat | Details → |
MITRE ATT&CK TTPs 65 techniques
T1001 Data Obfuscation · Command And Control T1001.002 Steganography · Command And Control T1001.003 Protocol or Service Impersonation · Command And Control T1003 OS Credential Dumping · Credential Access T1012 Query Registry · Discovery T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1027.002 Software Packing · Defense Evasion T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1041 Exfiltration Over C2 Channel · Exfiltration T1055 Process Injection · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1056.001 Keylogging · Collection T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1070.001 Clear Windows Event Logs · Defense Evasion T1070.002 Clear Linux or Mac System Logs · Defense Evasion T1070.003 Clear Command History · Defense Evasion T1070.004 File Deletion · Defense Evasion T1070.005 Network Share Connection Removal · Defense Evasion T1070.006 Timestomp · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1081 T1081 T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1090.001 Internal Proxy · Command And Control T1110 Brute Force · Credential Access T1133 External Remote Services · Persistence T1204.002 Malicious File · Execution T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access T1003.001 LSASS Memory · Credential Access T1018 Remote System Discovery · Discovery T1071.003 Mail Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1083 File and Directory Discovery · Discovery T1087.002 Domain Account · Discovery T1095 Non-Application Layer Protocol · Command And Control T1105 Ingress Tool Transfer · Command And Control T1129 Shared Modules · Execution T1135 Network Share Discovery · Discovery T1140 Deobfuscate/Decode Files or Information · Defense Evasion T1170 T1170 T1197 BITS Jobs · Defense Evasion T1205.001 Port Knocking · Defense Evasion T1210 Exploitation of Remote Services · Lateral Movement T1218.001 Compiled HTML File · Defense Evasion T1485 Data Destruction · Impact T1558 Steal or Forge Kerberos Tickets · Credential Access T1573.001 Symmetric Cryptography · Command And Control T1057 Process Discovery · Discovery T1124 System Time Discovery · Discovery T1071.004 DNS · Command And Control T1074 Data Staged · Collection T1074.001 Local Data Staging · Collection T1102 Web Service · Command And Control T1114 Email Collection · Collection T1583 Acquire Infrastructure · Resource Development T1588 Obtain Capabilities · Resource Development