By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: RedDelta Deploys PlugX Malware to Target Mongolia and Taiwan in Espionage Campaigns
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > RedDelta Deploys PlugX Malware to Target Mongolia and Taiwan in Espionage Campaigns
Tech News

RedDelta Deploys PlugX Malware to Target Mongolia and Taiwan in Espionage Campaigns

By Viral Trending Content 4 Min Read
Share
SHARE

Jan 10, 2025Ravie LakshmananCyber Espionage / Cyber Attack

PlugX Malware

Mongolia, Taiwan, Myanmar, Vietnam, and Cambodia have been targeted by the China-nexus RedDelta threat actor to deliver a customized version of the PlugX backdoor between July 2023 and December 2024.

“The group used lure documents themed around the 2024 Taiwanese presidential candidate Terry Gou, the Vietnamese National Holiday, flood protection in Mongolia, and meeting invitations, including an Association of Southeast Asian Nations (ASEAN) meeting,” Recorded Future’s Insikt Group said in a new analysis.

It’s believed that the threat actor compromised the Mongolian Ministry of Defense in August 2024 and the Communist Party of Vietnam in November 2024. It’s also said to have targeted various victims in Malaysia, Japan, the United States, Ethiopia, Brazil, Australia, and India from September to December 2024.

Cybersecurity

RedDelta, active since at least 2012, is the moniker assigned to a state-sponsored threat actor from China. It’s also tracked by the cybersecurity community under the names BASIN, Bronze President, Camaro Dragon, Earth Preta, HoneyMyte, Mustang Panda (and its closely related Vertigo Panda), Red Lich, Stately Taurus, TA416, and Twill Typhoon.

The hacking crew is known for continually refining its infection chain, with recent attacks weaponizing Visual Studio Code tunnels as part of espionage operations targeting government entities in Southeast Asia, a tactic that’s increasingly being adopted by various China-linked espionage clusters such as Operation Digital Eye and MirrorFace.

The intrusion set documented by Recorded Future entails the use of Windows Shortcut (LNK), Windows Installer (MSI), and Microsoft Management Console (MSC) files, likely distributed via spear-phishing, as the first-stage component to trigger the infection chain, ultimately leading to the deployment of PlugX using DLL side-loading techniques.

Select campaigns orchestrated late last year have also relied on phishing emails containing a link to HTML files hosted on Microsoft Azure as a starting point to trigger the download of the MSC payload, which, in turn, drops an MSI installer responsible for loading PlugX using a legitimate executable that’s vulnerable to DLL search order hijacking.

In a further sign of an evolution of its tactics and stay ahead of security defenses, RedDelta has been observed using the Cloudflare content delivery network (CDN) to proxy command-and-control (C2) traffic to the attacker-operated C2 servers. This is done so in an attempt to blend in with legitimate CDN traffic and complicate detection efforts.

Recorded Future said it identified 10 administrative servers communicating with two known RedDelta C2 servers. All the 10 IP addresses are registered to China Unicom Henan Province.

Cybersecurity

“RedDelta’s activities align with Chinese strategic priorities, focusing on governments and diplomatic organizations in Southeast Asia, Mongolia, and Europe,” the company said.

“The group’s Asia-focused targeting in 2023 and 2024 represents a return to the group’s historical focus after targeting European organizations in 2022. RedDelta’s targeting of Mongolia and Taiwan is consistent with the group’s past targeting of groups seen as threats to the Chinese Communist Party’s power.”

The development comes amid a report from Bloomberg that the recent cyber attack targeting the U.S. Treasury Department was perpetrated by a fellow hacking group known as Silk Typhoon (aka Hafnium), which was previously attributed to the zero-day exploitation of four security flaws in Microsoft Exchange Server (aka ProxyLogon) in early 2021.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Photographers from all over the country encouraged to explore the night sky for ‘Reach for the Stars’ Competition

EA Tried to Stop an ‘Anti-DEI Mod’ for ‘The Sims 4’—but More Keep Surfacing

Top 5 career routes for automation experts

Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit

125,000 Homes, Farms, and Businesses Already Connected to High-speed Fibre – NBI

TAGGED: Cyber Attack, cyber espionage, Cyber Security, Cybersecurity, DLL side-loading, Internet, phishing, PlugX
Share This Article
Facebook Twitter Copy Link
Previous Article U.S. has skirted a recession, but watch for big shifts in trade and immigration policies, economist advises
Next Article He's better than Kolo Muani: Spurs join race to sign "unstoppable" PL star
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Ethereum security push targets trillions in on-chain value with new 1TS plan
Crypto
Is Chris Brown in Jail? Find Out Amid His Reported 2025 Arrest
Celebrity
Grand Theft Auto 5 Sells Over 215 Million Units, Red Dead Redemption 2 Crosses 74 Million
Gaming News
Photographers from all over the country encouraged to explore the night sky for ‘Reach for the Stars’ Competition
Tech News
Tax dodging by rich could be ‘much greater than thought’, says UK audit office
Business
7.4% yield! Here’s the dividend forecast for Aviva shares through to 2027!
Business
Jim Chanos shorting Strategy while backing Bitcoin raises red flags on crypto stocks
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Ethereum security push targets trillions in on-chain value with new 1TS plan

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Ethereum security push targets trillions in on-chain value with new 1TS plan
May 16, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?