HenBox__2019__PKPLUG_Chinese_Cyber_Espionage_Group_Attacking_Asia.pdf
ID: ef6c88dd-bb43-47b8-a444-f7b9cf739715
STIX ID: report--ef6c88dd-bb43-47b8-a444-f7b9cf739715
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2019-10-04
Last Modified Date: 2019-10-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 profiles “PKPLUG,” a multi-year, Chinese-attributed cyber-espionage cluster targeting countries and regions across Asia (notably Myanmar, Taiwan, Vietnam, Indonesia, Mongolia, Tibet and Xinjiang) that deploys both public and bespoke malware — including PlugX, Poison Ivy, 9002, HenBox (Android) and Farseer (Windows) — via spear-phishing, DLL side‑loading and PowerShell techniques; the report maps infrastructure overlaps, documents TTPs and IoCs, and provides a STIX 2.0 Adversary Playbook for detection and sharing.
