UNC6384 Targets Diplomats with PlugX via Captive Portal Hijacks
Summary
Hide ▲
Show ▼
UNC6384, a China-nexus threat actor assessed to share tactical overlaps with Mustang Panda, continues targeted espionage campaigns leveraging advanced social engineering and indirect execution techniques. Recent reporting confirms Mustang Panda’s use of the FDMTP backdoor (version 3.2.5.1) in a months-long campaign against networks in the Asia-Pacific and Japan, involving CDN impersonation, DLL sideloading, and in-memory .NET execution. The group employs modular plugins for persistence, scheduled tasks, and remote file retrieval, with communication over a custom TCP protocol using DMTP. The campaign targeting U.S. government and policy entities via Venezuela-themed spear phishing to deliver the LOTUSLITE backdoor remains under investigation, with moderate-confidence attribution to Mustang Panda. Earlier phases described UNC6384’s captive portal hijacks to deploy PlugX variants (SOGU.SEC) and linked tooling overlaps with Mustang Panda’s Bookworm malware, highlighting the sophistication of PRC-nexus operators in evading detection.
Timeline
-
16.01.2026 12:27 1 articles · 3mo ago
Mustang Panda Targets U.S. Entities with LOTUSLITE Backdoor
A new campaign targets U.S. government and policy entities using Venezuela-themed spear phishing to deliver the LOTUSLITE backdoor. The LOTUSLITE backdoor is a bespoke C++ implant that communicates with a hard-coded command-and-control (C2) server using Windows WinHTTP APIs. The backdoor supports commands for remote CMD shell, file enumeration, file creation, data exfiltration, and beacon status checks, and establishes persistence by making Windows Registry modifications.
Show sources
- LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing — thehackernews.com — 16.01.2026 12:27
-
27.09.2025 15:06 3 articles · 7mo ago
PlugX Variant Linked to Mustang Panda and Bookworm Malware
Darktrace analysis links Mustang Panda to an updated FDMTP backdoor (version 3.2.5.1) used in a months-long espionage campaign targeting Asia-Pacific and Japan networks from September 2025 to April 2026. The campaign employed CDN impersonation, DLL sideloading via legitimate binaries (e.g., Sogou Pinyin’s biz_render.exe), and in-memory .NET execution to load the backdoor. The FDMTP framework includes modular plugins for persistence (scheduled tasks and registry entries), remote file retrieval, and process manipulation, with communication over a custom TCP protocol using DMTP and a persistent update channel polling icloud-cdn[.]net every five minutes.
Show sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
- LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing — thehackernews.com — 16.01.2026 12:27
- Mustang Panda Linked to Updated FDMTP Backdoor in Asia-Pacific Espionage Campaign — www.infosecurity-magazine.com — 14.05.2026 18:00
-
25.08.2025 21:11 4 articles · 8mo ago
UNC6384 Deploys PlugX via Captive Portal Hijacks Targeting Diplomats
The campaign targeted around two dozen victims, primarily Southeast Asian diplomats, between March and July 2025. The attack chain involved compromised edge devices intercepting captive portal checks and redirecting users to a malicious website. The malicious website used a valid TLS/SSL certificate issued by Let's Encrypt to avoid browser security warnings. The first-stage malware, STATICPLUGIN, dropped a launcher called CANONSTAGER, which used unconventional techniques to hide its activities. The final payload was a variant of the PlugX backdoor, tracked by Google as SOGU.SEC. The new PlugX variant overlaps with RainyDay and Turian backdoors, targeting telecommunications and manufacturing sectors in Central and South Asia. The campaign is linked to Mustang Panda, which also uses Bookworm malware.
Show sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
- LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing — thehackernews.com — 16.01.2026 12:27
Information Snippets
-
UNC6384 is assessed to share tactical and tooling overlaps with Mustang Panda, a known Chinese hacking group.
First reported: 25.08.2025 21:113 sources, 5 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
- LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing — thehackernews.com — 16.01.2026 12:27
- Mustang Panda Linked to Updated FDMTP Backdoor in Asia-Pacific Espionage Campaign — www.infosecurity-magazine.com — 14.05.2026 18:00
-
The campaign uses a captive portal redirect to hijack web traffic and deliver the STATICPLUGIN downloader.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
STATICPLUGIN retrieves an MSI package from the same website and deploys the SOGU.SEC backdoor in memory.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The malware supports commands to exfiltrate files, log keystrokes, and launch remote command shells.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The captive portal hijack is used to deliver malware masquerading as an Adobe Plugin update.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The AitM attack is facilitated by compromised edge devices on the target networks.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The STATICPLUGIN downloader is signed by Chengdu Nuoxin Times Technology Co., Ltd with a valid certificate issued by GlobalSign.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The campaign was detected by Google Threat Intelligence Group (GTIG) in March 2025.
First reported: 25.08.2025 21:112 sources, 2 articlesShow sources
- UNC6384 Deploys PlugX via Captive Portal Hijacks and Valid Certificates Targeting Diplomats — thehackernews.com — 25.08.2025 21:11
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The campaign targeted around two dozen victims, primarily Southeast Asian diplomats, between March and July 2025.
First reported: 27.08.2025 22:311 source, 1 articleShow sources
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The attack chain involved compromised edge devices intercepting captive portal checks and redirecting users to a malicious website.
First reported: 27.08.2025 22:311 source, 1 articleShow sources
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The malicious website used a valid TLS/SSL certificate issued by Let's Encrypt to avoid browser security warnings.
First reported: 27.08.2025 22:311 source, 1 articleShow sources
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The first-stage malware, STATICPLUGIN, dropped a launcher called CANONSTAGER, which used unconventional techniques to hide its activities.
First reported: 27.08.2025 22:311 source, 1 articleShow sources
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
-
The final payload was a variant of the PlugX backdoor, tracked by Google as SOGU.SEC.
First reported: 27.08.2025 22:312 sources, 2 articlesShow sources
- China Hijacks Captive Portals to Spy on Asian Diplomats — www.darkreading.com — 27.08.2025 22:31
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
The new PlugX variant overlaps with RainyDay and Turian backdoors in its use of legitimate applications for DLL side-loading, encryption/decryption algorithms, and RC4 keys.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
The PlugX variant uses a configuration structure similar to RainyDay, associated with Lotus Panda (Naikon APT).
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
The campaign targets telecommunications and manufacturing sectors in Central and South Asia.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
The attack chains involve abusing a legitimate executable associated with Mobile Popup Application to sideload a malicious DLL for payload execution.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
The PlugX variant includes an embedded keylogger plugin.
First reported: 27.09.2025 15:061 source, 2 articlesShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
- LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing — thehackernews.com — 16.01.2026 12:27
-
The campaign is linked to Mustang Panda, which also uses Bookworm malware.
First reported: 27.09.2025 15:061 source, 2 articlesShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
- LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing — thehackernews.com — 16.01.2026 12:27
-
Bookworm malware has been used since 2015 and includes capabilities to execute commands, upload/download files, exfiltrate data, and establish persistent access.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
Bookworm utilizes legitimate-looking domains or compromised infrastructure for C2 purposes.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
Bookworm variants share overlaps with TONESHELL, another backdoor associated with Mustang Panda.
First reported: 27.09.2025 15:061 source, 2 articlesShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
- LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing — thehackernews.com — 16.01.2026 12:27
-
Bookworm employs a modular architecture that makes static analysis challenging.
First reported: 27.09.2025 15:061 source, 1 articleShow sources
- China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks — thehackernews.com — 27.09.2025 15:06
-
A new campaign targets U.S. government and policy entities using Venezuela-themed spear phishing to deliver the LOTUSLITE backdoor.
First reported: 16.01.2026 12:271 source, 1 articleShow sources
- LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing — thehackernews.com — 16.01.2026 12:27
-
The LOTUSLITE backdoor is a bespoke C++ implant that communicates with a hard-coded command-and-control (C2) server using Windows WinHTTP APIs.
First reported: 16.01.2026 12:271 source, 1 articleShow sources
- LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing — thehackernews.com — 16.01.2026 12:27
-
LOTUSLITE supports commands for remote CMD shell, file enumeration, file creation, data exfiltration, and beacon status checks.
First reported: 16.01.2026 12:271 source, 1 articleShow sources
- LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing — thehackernews.com — 16.01.2026 12:27
-
LOTUSLITE establishes persistence by making Windows Registry modifications.
First reported: 16.01.2026 12:271 source, 1 articleShow sources
- LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing — thehackernews.com — 16.01.2026 12:27
-
The campaign is attributed with moderate confidence to Mustang Panda, known for using DLL side-loading techniques.
First reported: 16.01.2026 12:272 sources, 2 articlesShow sources
- LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing — thehackernews.com — 16.01.2026 12:27
- Mustang Panda Linked to Updated FDMTP Backdoor in Asia-Pacific Espionage Campaign — www.infosecurity-magazine.com — 14.05.2026 18:00
-
Darktrace identified an updated FDMTP backdoor (version 3.2.5.1) linked to Mustang Panda in a months-long espionage campaign targeting Asia-Pacific and Japan networks from September 2025 to April 2026
First reported: 14.05.2026 18:001 source, 1 articleShow sources
- Mustang Panda Linked to Updated FDMTP Backdoor in Asia-Pacific Espionage Campaign — www.infosecurity-magazine.com — 14.05.2026 18:00
Similar Happenings
BPFDoor Linux kernel implants leveraged by Red Menshen for stealthy telecom espionage
A China-nexus threat group, tracked as Red Menshen (aka Earth Bluecrow, DecisiveArchitect, Red Dev 18), has conducted a multi-year espionage campaign targeting telecom providers in the Middle East and Asia by deploying stealthy Linux kernel-level implants. The adversary abuses Berkeley Packet Filter (BPF) functionality to embed passive backdoors (BPFDoor) that activate via crafted network packets, avoiding detectable listeners or C2 channels. Initial access is obtained via internet-facing edge services (e.g., VPNs, firewalls) from vendors including Ivanti, Cisco, Juniper, Fortinet, VMware, Palo Alto, and Apache Struts. Post-exploitation includes deployment of frameworks like CrossC2 and Sliver, alongside credential harvesting tools, enabling lateral movement. BPFDoor’s functionality extends to telecom-native protocols (e.g., SCTP), potentially granting visibility into subscriber behavior, location tracking, and surveillance of high-value targets. A newly documented variant enhances evasion by concealing trigger packets within legitimate HTTPS traffic at fixed byte offsets and introducing ICMP-based lightweight communication between infected hosts.
China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking and Malware Delivery
Cybersecurity researchers have uncovered a China-linked adversary-in-the-middle (AitM) framework called DKnife, active since at least 2019. The framework targets routers and edge devices to perform deep packet inspection, manipulate traffic, and deliver malware. It primarily targets Chinese-speaking users by harvesting credentials and delivering malware via popular Chinese services and applications. DKnife comprises seven Linux-based implants that enable a wide range of malicious activities, including DNS hijacking, binary download hijacking, and real-time user activity monitoring. The framework is linked to the Earth Minotaur threat activity cluster and shares infrastructural connections with WizardNet, a Windows implant deployed by TheWizards APT group. DKnife's infrastructure overlaps with a campaign delivering WizardNet, suggesting a shared development or operational lineage. The framework uses a component called yitiji.bin to create a bridged TAP interface on the router at the private IP address 10.3.3.3, allowing the threat actor to intercept and rewrite network packets in transit to the intended host. Additionally, DKnife monitors WeChat activities more analytically, tracking voice and video calls, text messages, images sent and received, and articles read on the platform.
Asian State-Backed Group TGR-STA-1030 Targets 70 Government and Infrastructure Entities
A previously undocumented cyber espionage group, TGR-STA-1030, has compromised at least 70 government and critical infrastructure organizations across 37 countries over the past year. The group, assessed to be of Asian origin, leverages phishing emails and exploits N-day vulnerabilities to deploy malware and maintain long-term access for espionage purposes. Targets include national law enforcement, ministries of finance, and departments related to economic, trade, natural resources, and diplomatic functions. The group uses a variety of tools, including Cobalt Strike, Behinder, Godzilla, and a Linux kernel rootkit named ShadowGuard. The group conducted reconnaissance activity targeting government entities connected to 155 countries between November and December 2025 and showed increased interest in scanning entities across North, Central, and South America during the U.S. government shutdown in October 2025. The group also exploited at least 15 known vulnerabilities in SAP Solution Manager, Microsoft Exchange Server, D-Link, and Microsoft Windows.
China-Linked APTs Deploy PeckBirdy JScript C2 Framework Since 2023
China-aligned APT actors have been using the PeckBirdy JScript-based command-and-control (C2) framework since 2023 to target Chinese gambling industries, Asian government entities, and private organizations. The framework leverages living-off-the-land binaries (LOLBins) for execution across various environments. Two campaigns, SHADOW-VOID-044 and SHADOW-EARTH-045, have been identified, each employing different tactics, including credential harvesting and malware delivery. The framework's flexibility allows it to operate across web browsers, MSHTA, WScript, Classic ASP, Node JS, and .NET, using multiple communication methods like WebSocket and Adobe Flash ActiveX objects. Additional scripts for exploitation, social engineering, and backdoor delivery have been observed, along with links to known backdoors like HOLODONUT and MKDOOR. HOLODONUT disables security features such as AMSI before executing payloads in memory, while MKDOOR disguises its network traffic as legitimate Microsoft support or activation pages and attempts to evade Microsoft Defender by altering exclusion settings. Infrastructure overlaps and shared tooling suggest SHADOW-VOID-044 is linked with UNC3569, a China-aligned group previously associated with the GRAYRABBIT backdoor. Some samples used stolen code-signing certificates to legitimize malicious Cobalt Strike payloads, and SHADOW-EARTH-045 showed weaker but notable ties to activity previously attributed to Earth Baxia. The Shadow-Void-044 campaign used stolen code-signing certificates, Cobalt Strike payloads, and exploits, including CVE-2020-16040, to maintain persistent access. The Shadow-Earth-045 campaign targeted a Philippine educational institution in July 2024, using the GrayRabbit backdoor and the HoloDonut backdoor. The threat actor behind the Shadow-Earth campaign developed a .NET executable to launch PeckBirdy with ScriptControl.
PluggyApe Backdoor Targets Ukraine's Defense Forces in Charity-Themed Campaign
Ukraine's Defense Forces were targeted in a charity-themed malware campaign between October and December 2025, delivering the PluggyApe backdoor, likely deployed by the Russian threat group Void Blizzard (Laundry Bear). The attacks began with instant messages over Signal or WhatsApp, directing recipients to malicious websites posing as charitable foundations. These sites distributed password-protected archives containing PluggyApe payloads. The malware profiles the host, sends victim information to attackers, and waits for further commands. In February 2026, a new campaign targeting Ukrainian entities was observed, employing judicial and charity-themed lures to deploy a JavaScript-based backdoor codenamed DRILLAPP. This campaign is likely orchestrated by threat actors linked to Russia and shares overlaps with the prior PluggyApe campaign. The malware is capable of uploading and downloading files, leveraging the microphone, and capturing images through the webcam. The threat actor is believed to be active since at least April 2024.