BRONZE PRESIDENT Targets Government Officials

Bronze President targeted government officials using PlugX payloads across multiple documents and delivery methods. The campaign involved malicious archives, shortcuts, DLLs, and encrypted payloads linked to PlugX, with identified C2 servers associated to the activity. Hashtags: #PlugX #BronzePresident #BosniaAndHerzegovina

Keypoints

  • Bronze President is a threat actor group targeting government officials with PlugX implants.
  • Delivery and execution used a mix of weaponized archives (RARs), shortcut files (.lnk), PDFs, and DLLs to drop and run PlugX.
  • The campaign relies on encrypted payloads (e.g., operaDB.dat, AvastDB.dat) and multiple DLLs (e.g., opera_browser.dll, Adobe_Caps.dll, goopdate.dll) to load PlugX.
  • DLL-related techniques include loading and possibly side-loading PlugX components from legitimate-looking binaries.
  • Command-and-control infrastructure is evidenced by specific IPs acting as C2 servers: 64.34.205.41, 69.90.190.110, and 104.255.174.58.
  • A large set of artifact hashes (MD5, SHA1, SHA256) are associated with the PlugX components and related payloads, indicating a broad collection of samples used in the campaign.
  • Targets include documents and topics such as embassy reports and EU/UN-related materials, reflecting espionage-focused objectives.

MITRE Techniques

  • [T1566.001] Phishing: Attachment – Malicious RAR file containing PlugX. Quote: “Malicious RAR file containing PlugX (Predlog termina zvanicne posjete zamjenice predsjedavajuceg Vijeca ministara i ministarke vanjskih poslova BiH.rar)”
  • [T1204.002] User Execution – Malicious shortcut file that executes PlugX. Quote: “Malicious shortcut file that executes PlugX (Predlog termina zvanicne posjete zamjenice predsjedavajuceg Vijeca ministara i ministarke vanjskih poslova BiH.pdf.lnk)”
  • [T1574.002] DLL Side-Loading – Malicious DLL that loads PlugX (opera_browser.dll). Quote: “Malicious DLL that loads PlugX (opera_browser.dll)”
  • [T1027] Obfuscated/Compressed Files and Information – Encrypted PlugX payloads (operaDB.dat, AvastDB.dat). Quote: “Encrypted PlugX payload (operaDB.dat)”; “Encrypted PlugX payload (AvastDB.dat)”
  • [T1071.001] Web Protocols – PlugX C2 server communications via IP addresses. Quote: “PlugX C2 server” for the listed IPs and their use as command-and-control.

Indicators of Compromise

  • [IP Address] PlugX C2 server – 64.34.205.41, 69.90.190.110, and 104.255.174.58
  • [MD5 hash] – c285eaea0fe441f550479f7ef85a3dd0, 3a94449d664033955012edac0161b2b8
  • [SHA1 hash] – 41d61af1d61d6e1c4718132e64268005, 81e8fb5149fda8e1231c9f0f22001cea
  • [SHA256 hash] – 4cd7d84e464a2786446df623629aa7e2e6c776c9a870278eb39b54c5fba05044, d556d7603178a7e4242c01fa5e490ea4589707eeeab2f3c6c4966bd9b912bd59
  • [File name] – opera_browser.dll, operaDB.dat

Read more: https://www.secureworks.com/blog/bronze-president-targets-government-officials