logo

Oops, they did it again: APT Targets Russia and Belarus with ZeroT and PlugX | Proofpoint

ID: 0e2116a2-ab0f-4961-9a35-9d525d4a0160

STIX ID: report--0e2116a2-ab0f-4961-9a35-9d525d4a0160

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2017-02-03

Last Modified Date: 2017-02-03

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** Proofpoint researchers describe a China-associated APT campaign that introduced a new downloader called ZeroT to deliver PlugX via spear-phishing (CHM/Word/RAR SFX), UAC bypass/sideload techniques, and BMP LSB steganography for stage-2 payloads; the report includes protocol details, C2 domains, IOCs, and sample PlugX configurations.