DOPLUGS Backdoor Employed by Chinese Hackers
Mustang Panda, a threat actor with ties to China, has focused its cyber-espionage efforts on several Asian nations by employing a modified version of the PlugX (also known as Korplug) backdoor, named DOPLUGS.
According to researchers, this customized PlugX malware differs from the typical variant by lacking a complete backdoor command module. Instead, it serves the sole purpose of downloading the said module. DOPLUGS primarily targets entities in Taiwan and Vietnam, with lesser instances in Hong Kong, India, Japan, Malaysia, Mongolia, and even China.
Mustang Panda, also identified as BASIN, Bronze President, Camaro Dragon, Earth Preta, HoneyMyte, RedDelta, Red Lich, Stately Taurus, TA416, and TEMP.Hex, has been utilizing PlugX since at least 2012, although its activities were first revealed in 2017.
Mustang Panda Uses Phishing as Initial Attack Vector
The threat actor's modus operandi involves executing sophisticated spear-phishing campaigns to deliver various custom malware. Since 2018, Mustang Panda has been deploying its own tailored versions of PlugX, such as RedDelta, Thor, Hodur, and DOPLUGS (disseminated through the SmugX campaign).
Compromise chains involve well-crafted spear-phishing messages, delivering an initial payload disguised as a decoy document. This payload secretly unpacks a legitimate, signed executable vulnerable to DLL side-loading. Subsequently, a dynamic-link library (DLL) is side-loaded, decrypting and executing PlugX.
The PlugX malware then fetches the Poison Ivy remote access trojan (RAT) or Cobalt Strike Beacon to establish a connection with a server controlled by Mustang Panda.
In December 2023, Lab52 discovered a Mustang Panda campaign targeting Taiwanese political, diplomatic, and governmental entities with DOPLUGS. Notably, this variant features a malicious DLL written in the Nim programming language and employs its own RC4 algorithm implementation for decrypting PlugX, deviating from previous versions that relied on the Windows Cryptsp.dll library.








