Researchers reported multiple intrusion campaigns adopting Golang-based malware loaders delivered through phishing to improve evasion and persistence. In one campaign, tracked as GO#WEBBFUSCATOR, attackers sent malicious Microsoft Office documents that abused an external template to retrieve a DOTM file, whose VBA macros downloaded a JPEG with appended Base64 data, decoded it with certutil, and launched a Golang executable named msdllupdate.exe. The malware used layered obfuscation including ROT25, XOR-obfuscated Go assemblies, and gobfuscation, then persisted by copying itself into LOCALAPPDATA and creating a Run key under HKCU.
A separate campaign tied to TA416/Mustang Panda used phishing lures themed around Vatican-China relations and spoofed journalist identities to target Catholic, diplomatic, Myanmar, and African organizations. Proofpoint said the actor deployed a Golang-based PlugX loader inside RAR archives, using a legitimate Adobe executable for DLL side-loading of hex.dll, which decrypted adobeupdate.dat and executed the PlugX payload. Across the campaigns, operators relied on stealthy command-and-control methods, including TXT DNS requests via nslookup to attacker-controlled domains such as xmlschemeformat.com, apiregis.com, and updatesagent.com, while TA416 infrastructure included command-and-control IP 45.248.87[.]162, underscoring a broader shift toward Golang tooling in espionage-focused malware operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Securonix reported that subdomains ns1.apiregis.com and ns2.apiregis.com began resolving to 139.28.36.222 on July 16, 2022, associated with the malware’s DNS-based C2 channel.
Securonix said www.xmlschemeformat.com resolved to 185.247.209.255 on May 30, 2022, supporting the malicious Office template delivery chain.
Securonix reported that www.xmlschemeformat.com and nameserver domains for updatesagent.com were registered on May 29, 2022 as part of infrastructure tied to the GO#WEBBFUSCATOR campaign.
After nearly a month of inactivity, TA416 resumed phishing activity on October 10, 2020, continuing espionage-themed targeting related to Vatican-China relations and other diplomatic entities.
Proofpoint said TA416 activity went quiet beginning September 16, 2020, starting a lull that overlapped with China’s National Day and Golden Week period.
Proofpoint reported that PlugX command-and-control IP 45.248.87[.]162, hosted by Anchnet Asia Limited, appeared active from at least August 24 through September 28, 2020.
Securonix Threat Labs disclosed a persistent Golang-based campaign tracked as GO#WEBBFUSCATOR that used phishing documents, malicious Office templates, image-steganography-like payload delivery, and DNS TXT-based command and control.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
securonix.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.