A sophisticated cyberespionage campaign has been uncovered targeting telecommunications and manufacturing organizations across Central and South Asia. The campaign is attributed to Chinese nation-state actors, specifically the Naikon and BackdoorDiplomacy groups, and leverages a combination of the RainyDay and Turian backdoors alongside a novel variant of the PlugX remote access Trojan. Researchers from Cisco Talos identified that the attackers are exploiting DLL search order hijacking vulnerabilities in Windows to deploy illicit loaders, allowing malicious DLLs to be executed under the guise of legitimate processes. This technique provides the attackers with a stealthy execution context, making detection by security systems more difficult. The malware payloads utilize the GetModuleFileNameA API to acquire executable paths and read encrypted data, employing consistent RC4 encryption keys and a unique XOR-RC4-RtlDecompressBuffer decryption algorithm across all samples. The PlugX variant observed in this campaign is configured in a way that suggests the attackers have access to its original source code, enabling novel deployment methods. The campaign has been active since at least 2022, with PlugX itself having a long history of use in high-profile attacks, including those against the U.S. Office of Personnel Management and European diplomatic agencies. The targeting patterns and malware configurations link this activity to the Naikon group, a unit believed to operate out of Chengdu, China, and associated with the People's Liberation Army. The campaign's focus on telecom and manufacturing sectors indicates a likely intent to gather intelligence and disrupt critical infrastructure in the region. U.S. federal law enforcement has also taken action against PlugX, recently deleting over 4,000 instances of the malware from computers in the United States, highlighting its widespread use. The attackers' use of multiple backdoors and advanced evasion techniques demonstrates a high level of sophistication and persistence. The campaign's reliance on DLL search order hijacking underscores the importance of securing application loading processes and monitoring for anomalous DLL activity. The use of shared encryption keys and decryption algorithms across different malware families suggests coordinated development and operational control. The involvement of both Naikon and BackdoorDiplomacy groups points to collaboration or shared resources among Chinese state-linked threat actors. The campaign's longevity and evolving tactics reflect the ongoing threat posed by Chinese cyberespionage operations to organizations in Asia and beyond. Organizations in targeted sectors are advised to review their security controls, especially around DLL loading and process monitoring, to detect and mitigate similar threats. The discovery of this campaign adds to the growing body of evidence of sustained, state-sponsored cyber operations targeting strategic industries in Asia.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Based on victimology and technical similarities in the new PlugX activity, Talos assessed there may be a relationship between the China-linked Lotus Panda and BackdoorDiplomacy clusters, though it did not make a definitive attribution. This represented a new analytical assessment tied to the campaign.
Cisco Talos reported an ongoing campaign targeting telecommunications and manufacturing organizations in Central and South Asia with a new PlugX variant. The malware was delivered through DLL side-loading and showed technical overlaps with the RainyDay and Turian backdoors.
Unit 42 said more recent Bookworm activity targeted ASEAN-affiliated countries and used DLL side-loading, with newer variants adopting UUID-encoded shellcode to hinder analysis. The exact start date was not specified in the references.
Palo Alto Networks Unit 42 reported that the China-linked Mustang Panda group has used the modular Bookworm malware since 2015. The malware functions as a RAT and has remained part of the group's long-running operations.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.