logo

appbox1

ID: b029670b-d27c-4ef6-ab95-ea2ecbf370be

STIX ID: report--b029670b-d27c-4ef6-ab95-ea2ecbf370be

Threat Score

75/100

Uploaded: 2026-05-13

Published Date: 2026-05-13

Last Modified Date: 2026-05-13

Created by: team123

TLP:GREEN
...
...
SophosLabs (Feb 2015) describes evolution of the PlugX backdoor family: new P2P communication and a technique storing encrypted payloads in the Windows registry. The report details two classes of exploited RTF carrier documents (CVE-2012-0158), a multi-stage XOR/encrypted shellcode installer that drops loaders and payloads, multiple targeted campaigns (notably in India and Russia), persistence mechanisms, and numerous indicators (filenames, C2 domains, and sample hashes) useful for detection and response.