5mo ago · lab52
A recent PlugX RAT campaign leverages a spear-phishing email with the subject 'Meeting Invitation' to deliver malicious payloads via DLL side-loading. The infection chain uses a legitimate G DATA antivirus executable (Avk.exe) to load a malicious DLL (Avk.dll), which decrypts and executes the payload from AVKTray.dat. The malware establishes persistence through a registry Run key and communicates with the C2 server at decoorat[.]net over HTTPS on port 443. The campaign demonstrates continued use of trusted binaries, XOR-based obfuscation, and API hashing techniques consistent with China-aligned threat actors.