Chinese APT UNC6384 Pivots to Europe, Exploits Windows LNK Flaw to Deploy PlugX via Canon DLL Sideloading

Chinese APT UNC6384 Pivots to Europe, Exploits Windows LNK Flaw to Deploy PlugX via Canon DLL Sideloading

Arctic Wolf Labs uncovered a sophisticated cyber espionage campaign by Chinese-affiliated UNC6384 targeting European diplomatic targets using new Windows exploits and stealth malware. The campaign signifies a strategic shift from Southeast Asia to Europe, aiming to monitor EU defense, infrastructure, and diplomatic activities. #UNC6384 #PlugX

Keypoints

  • UNC6384 has shifted its focus from Southeast Asia to European diplomatic targets.
  • The campaign exploits the ZDI-CAN-25373 Windows vulnerability to deploy malware.
  • Attackers use spearphishing emails with malicious shortcut files and legitimate software for stealth.
  • The malware used, PlugX, provides remote access and data exfiltration capabilities.
  • New variants of the malware loader are rapidly optimized for detection evasion.

Read More: https://securityonline.info/chinese-apt-unc6384-pivots-to-europe-exploits-windows-lnk-flaw-to-deploy-plugx-via-canon-dll-sideloading/