China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks
An ongoing operation spreading a new version of a known malware named PlugX (also known as Korplug or SOGU) has targeted the manufacturing and telecommunications sectors in Central and South Asian nations.
According to an analysis published this week by Cisco Talos researchers Joey Chen and Takahiro Takeda, the new variant shares characteristics with both the RainyDay and Turian backdoors, such as the RC4 keys used, the XOR-RC4-RtlDecompressBuffer algorithm used to encrypt/decrypt payloads, and the misuse of the same legitimate applications for DLL side-loading.
The cybersecurity firm pointed out that the PlugX variant's configuration differs greatly from the standard PlugX configuration format, instead using the same structure as RainyDay, a backdoor connected to the Lotus Panda (a...

