Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers also use the 9002 Trojan, which is believed to be shared among a small subset of attack groups.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Considering all the malware related to PKPLUG that Unit 42 has analyzed, the use of such exploits appears to be less common than a spear-phishing technique making use of social engineering to lure victims into running their malware.
The actors still use spear phishing as their primary attack method... The use of a URL shortening service and a redirection server further aids the chances of a successful attack, as it becomes more challenging to determine the validity of the link within an email due to the way link shorteners obfuscate link content.
The attack relies on a shortened link (in this case using the URL shortening service TinyURL) to deliver the 9002 payload. | The executable uses the PowerPoint icon... to trick the victim into launching the executable by making the user think the file is a PowerPoint presentation.
The Trojan uses the path stored in this registry key to locate its configuration, which it decrypts using a multiple-byte XOR algorithm and a key of “1pKFmjw”.
The contents of the file, assuming a victim clicked on the URL in the spear-phishing email, resembles the structure used in a technique known as AppLocker Bypass whereby trusted Windows executables can be used to execute malicious payloads.
Using the configuration file above, the 9002 Trojan communicates with the following domain that acts as its command and control (C2) server: logitechwkgame[.]com
The second beacon method also uses TCP port 80, but this method uses HTTP requests to communicate with its C2 server.
The first method... uses a custom protocol on TCP port 80 that begins with the string ‘9002’.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
9002 is a trojan/backdoor used by PKPLUG and delivered through spear-phishing, shortened URLs, Google Drive-hosted ZIP files, and DLL side-loading packages.
A modular trojan/backdoor delivered via spear-phishing links, URL shorteners, a redirection server, and a Google Drive-hosted ZIP. It uses DLL sideloading for execution, establishes persistence via a Run registry key, decrypts configuration data, beacons to a C2 over a custom protocol and HTTP on TCP port 80, and loads plugins from the C2 via an exported function named CreatePluginObj.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.