logo

HenBox__2019__PKPLUG_Chinese_Cyber_Espionage_Group_Attacking_Asia.pdf

ID: ef6c88dd-bb43-47b8-a444-f7b9cf739715

STIX ID: report--ef6c88dd-bb43-47b8-a444-f7b9cf739715

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2019-10-04

Last Modified Date: 2019-10-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 profiles “PKPLUG,” a multi-year, Chinese-attributed cyber-espionage cluster targeting countries and regions across Asia (notably Myanmar, Taiwan, Vietnam, Indonesia, Mongolia, Tibet and Xinjiang) that deploys both public and bespoke malware — including PlugX, Poison Ivy, 9002, HenBox (Android) and Farseer (Windows) — via spear-phishing, DLL side‑loading and PowerShell techniques; the report maps infrastructure overlaps, documents TTPs and IoCs, and provides a STIX 2.0 Adversary Playbook for detection and sharing.