STATICPLUGIN is a threat cluster associated with deployment of the PlugX remote access trojan, also known as Korplug. The activity is consistent with China-aligned espionage tradecraft because PlugX has long been used by multiple China-linked intrusion sets and is commonly employed in intelligence collection operations against public-sector and strategic targets. STATICPLUGIN has been observed using spear-phishing lures themed as meeting invitations to initiate compromise, followed by abuse of MSBuild as a living-off-the-land binary, staged component download, and DLL side-loading through a legitimate security product executable to launch a malicious loader. The observed intrusion chain uses a malicious project file and executable delivered in an archive, displays a decoy document to the victim, and retrieves additional components that include a legitimate executable, a malicious side-loaded DLL, and an encrypted payload container. The loader decrypts and injects the final PlugX payload, establishes user-level persistence through an autorun mechanism, and communicates with command-and-control infrastructure over HTTPS. STATICPLUGIN also employs multiple anti-analysis and defense-evasion measures, including XOR- and RC4-based decryption routines, encrypted payload staging, transient artifact creation and cleanup, and API hashing in both the loader and injected payload to obscure function resolution. The malware family used by STATICPLUGIN, PlugX, is a long-running RAT publicly known since around 2008 and widely associated with espionage operations targeting government institutions, diplomatic entities, defense organizations, technology companies, energy providers, and non-governmental organizations across Europe, Asia, and North America. No distinct sub-groups or alternative aliases for STATICPLUGIN are established in the available information beyond the observed name itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.