STATICPLUGIN
STATICPLUGIN is a digitally signed Windows downloader used in a multi-stage espionage infection chain attributed to UNC6384, which Google Threat Intelligence Group linked to the Chinese threat actor TEMP.Hex, also known as Mustang Panda and Silk Typhoon. In reported March 2025 activity targeting diplomats in Southeast Asia and globally, attackers used an adversary-in-the-middle technique involving captive portal hijacking and abuse of Chrome connectivity checks to redirect victims to a fake Adobe plugin update site. Victims were prompted to execute a signed file such as AdobePlugins.exe, meaning the malware required user execution. STATICPLUGIN used the Windows COM Installer Object to download an MSI package; the MSI was disguised as a BMP file to hide its true MSI extension. The downloaded package contained components including a legitimate Canon printer tool and CANONSTAGER, which used DLL side-loading to decrypt and execute the final SOGU.SEC backdoor, a PlugX variant, entirely in memory. Reporting states STATICPLUGIN was signed with a valid Certificate Authority-issued certificate to help circumvent endpoint defenses, and campaign samples were signed by Chengdu Nuoxin Times Technology Co., Ltd., though it was unclear whether that entity was complicit or compromised. The broader infection chain ultimately deployed PlugX/SOGU.SEC, which was described as capable of collecting system information, uploading and downloading files, and providing a remote command shell. Detection references in the content include published YARA rules for STATICPLUGIN and CANONSTAGER.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC6384 ... delivered a downloader dubbed STATICPLUGIN, and ultimately deployed a variant of the PlugX back-door...
"...delivering a signed downloader (STATICPLUGIN) that installed the PlugX backdoor (SOGU.SEC)."
Techniques & procedures
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniques
Initial Access
Execution
3 techniques
Execution
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Examples include: "Sandworm Team leveraged Microsoft Office attachments which contained malicious macros..."; "Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs"; "Lumma Stealer has gained initial execution through victims opening malicious executable files embedded in zip archives, and MSI files within RAR files."
Stealth
3 techniques
Stealth
Defense Impairment
1 technique
Defense Impairment
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
Credential Access
1 technique
Credential Access
Recent activity
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Digitally signed downloader used to deliver PlugX payloads, including via DLL side-loading techniques.
Digitally signed downloader used to deliver PlugX payloads, including via DLL side-loading techniques.
Downloader used in UNC6384 campaigns to deliver subsequent payloads, including in-memory deployment of a PlugX variant.
... STATICPLUGIN ... (v1.0) ...
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.