The provided items do not describe a single shared incident or disclosure. Two references are substantive threat-intelligence writeups: one analyzes a PlugX RAT infection chain delivered via a “Meeting Invitation” phish and leveraging DLL side-loading (using G DATA’s Avk.exe to load a malicious Avk.dll), and another details APT37’s Ruby Jumper campaign that uses malicious LNK files to drop and execute staged payloads (batch + PowerShell + shellcode) and ultimately run RESTLEAF, including Zoho WorkDrive abuse for C2 token-based API access.
A third reference is a conference write-up from JSAC2026 Day 2 describing a digital forensics technique and tool (FJTA – Forensic Journal Timeline Analyzer) for reconstructing file operations from ext4/XFS journal structures to improve timelines when MACB timestamps are unreliable (e.g., timestomping). While technically relevant to DFIR, it is not connected to the PlugX or APT37 reporting and reads primarily as an event/session summary rather than a specific threat event report.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
LAB52 reported that the PlugX loader downloaded components from onedow[.]gesecole[.]net and communicated over HTTPS with decoraat[.]net:443. The analysis also detailed XOR and RC4-based decryption routines and API hashing used by the loader and payload to hinder static analysis.
The PlugX deployment chain used a legitimate G DATA antivirus executable, Avk.exe, to side-load a malicious Avk.dll, which decrypted and injected a payload stored in the encrypted AVKTray.dat file. The loader also established persistence through a Run key named "G DATA" and created temporary artifacts under %TEMP%.
A recent PlugX intrusion began with a spear-phishing email themed as a meeting invitation that delivered a ZIP archive containing an executable and an MSBuild project file. The .csproj file abused MSBuild as a LOLBIN to download additional components and start the infection chain.
APT37 deployed additional tools including SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, and BLUELIGHT to persist, spread via removable media, relay commands across air-gapped systems, and exfiltrate data. These components expanded the campaign's capability to bridge segmented networks and use multiple cloud services for command and control.
In the Ruby Jumper campaign, APT37 used the RESTLEAF malware to download shellcode, inject it into processes, and communicate through Zoho WorkDrive using timestamped files in a cloud folder. ThreatLabz assessed this as the first observed use of Zoho WorkDrive as a C2 channel by APT37.
APT37 conducted the Ruby Jumper campaign, delivering malicious Windows shortcut files that launched PowerShell, extracted embedded components, and executed the RESTLEAF malware in memory. The operation targeted segmented or air-gapped environments and used staged shellcode loaders for stealth.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.