PLUSDROP is a Windows DLL loader used in an APT41 cyber-espionage infection chain. It decrypts an embedded or staged payload and executes the next-stage component in memory, helping reduce on-disk evidence. In the documented chain, it precedes PLUSINJECT, which performs process hollowing in a legitimate Windows process, and the TOUGHPROGRESS backdoor, which uses Google Calendar for command-and-control communications. PLUSDROP has been delivered in spear-phishing operations using archive lures, malicious Windows shortcut files masquerading as documents, and decoy documents. The activity targeted government organizations as well as maritime and logistics, media and entertainment, technology, and automotive-sector entities. Its use of encrypted payloads and memory-resident execution supports defense evasion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PLUSDROP – a DLL that decrypts and executes the next payload stage in memory.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“each module [employed] advanced stealth techniques such as memory-only payloads, encryption, compression, process hollowing, control flow obfuscation.”
The archive contains an LNK file, masquerading as a PDF, and a directory. Within this directory we find what looks like seven JPG images... The files “6.jpg” and “7.jpg” are fake images.
The indicators include “申報物品清單.pdf.lnk,” a shortcut file presented with a PDF-looking filename.
When the payload is executed via the LNK, the LNK is deleted and replaced with a decoy PDF file that is displayed to the user.
The first file is actually an encrypted payload and is decrypted by the second file... TOUGHPROGRESS begins by using a hardcoded 16-byte XOR key to decrypt embedded shellcode... The shellcode then decompresses a DLL in memory using COMPRESSION_FORMAT_LZNT1.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a tool used alongside TOUGHPROGRESS in APT41 spear-phishing activity; specific functionality not described in the provided content.
Loader module that decrypts a malicious payload from a disguised image file and executes it in memory, used as part of the ToughProgress infection chain.
An in-memory DLL loader that decrypts and executes the subsequent infection-stage payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.