appbox1
ID: b029670b-d27c-4ef6-ab95-ea2ecbf370be
STIX ID: report--b029670b-d27c-4ef6-ab95-ea2ecbf370be
Threat Score
75/100
Uploaded: 2026-05-13
Published Date: 2026-05-13
Last Modified Date: 2026-05-13
Created by: team123
TLP:GREEN
...
...
SophosLabs (Feb 2015) describes evolution of the PlugX backdoor family: new P2P communication and a technique storing encrypted payloads in the Windows registry. The report details two classes of exploited RTF carrier documents (CVE-2012-0158), a multi-stage XOR/encrypted shellcode installer that drops loaders and payloads, multiple targeted campaigns (notably in India and Russia), persistence mechanisms, and numerous indicators (filenames, C2 domains, and sample hashes) useful for detection and response.
