Sophos has identified a new PlugX USB worm variant spreading through removable media in outbreaks across Papua New Guinea, Ghana, Mongolia, Zimbabwe, and Nigeria, using DLL sideloading with legitimate AvastSvc.exe, a malicious wsc.dll, and an encrypted PlugX payload. The malware hides files on infected USB drives, gathers host reconnaissance, and steals Office and PDF documents up to 300 MB, storing them in encrypted form under RECYCLER.BIN with base64-obfuscated filenames before attempting exfiltration to infrastructure including 45.142.166[.]112.
The activity aligns with the long-running PKPLUG espionage cluster, which researchers have previously attributed with high confidence to a Chinese nation-state adversary targeting victims in and around Southeast Asia, including Xinjiang, Mongolia, Myanmar, and Taiwan. Earlier reporting tied PKPLUG to malware families including PlugX, Poison Ivy, 9002, Zupdax, Farseer, and the Android spyware HenBox, and documented overlapping infrastructure, DLL sideloading, registry-based persistence, and surveillance-focused collection against regional targets, reinforcing the assessment that the new worm is part of a broader intelligence-gathering campaign.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Sophos said the new PlugX USB worm variant was first observed in Papua New Guinea in August 2022. The malware used DLL sideloading and removable media propagation to spread and steal documents.
Sophos published research on a new APT campaign dubbed 'KilllSomeOne' that used DLL side-loading techniques. The report documented a distinct malware/tooling cluster not previously represented in the timeline.
Unit 42 previously mentioned command-and-control server 45.142.166[.]112 in 2019 as 'other PlugX' infrastructure, but did not directly tie it to Mustang Panda at that time. This later became relevant to attribution of the USB worm activity.
Unit 42 reported a PlugX variant discovered during a Black Basta-related incident response that spreads via removable USB media and infects subsequent systems using x32dbg DLL sideloading and hidden U+00A0-named directories with deceptive .lnk files. The researchers also identified a related sample that copies PDF and Microsoft Word documents from infected hosts into a hidden USB folder for later retrieval.
After analyzing the worm's methods and command-and-control traffic to 45.142.166[.]112, Sophos assessed the activity aligned with PKPLUG, also known as Mustang Panda. Sophos said this strengthened a previously tentative link between that infrastructure and the actor.
Sophos reported the PlugX USB worm variant reappeared in January in Papua New Guinea and Ghana. Additional infections were later observed in Mongolia, Zimbabwe, and Nigeria.
Unit 42 discovered the HenBox Android malware family in early 2018. The spyware targeted Uyghurs and Xiaomi/MIUI devices and stole extensive device, communications, and location data.
Unit 42 discovered the previously unknown Farseer Windows backdoor and traced its activity back to 2016. The malware used registry run keys and DLL sideloading via a signed Microsoft Visual Studio component for persistence and execution.
In May 2016, a HenBox APK masquerading as DroidVPN was downloaded from the Uyghur-focused third-party app store uyghurapps[.]net. Unit 42 assessed the legitimate app was likely replaced after the app store server was compromised.
Unit 42 tracked more than 400 HenBox Android malware samples dating back to late 2015. The malware masqueraded as legitimate apps and was used in PKPLUG espionage activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcenews.sophos.com
Open sourcelockheedmartin.com
Open sourceunit42.paloaltonetworks.com
Open sourcetrendmicro.com
Open sourceoasis-open.github.io
Open sourcevirusbulletin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.