Trellix disclosed a newly identified PlugX malware variant dubbed Talisman that was used against telecommunications and defense organizations in South Asia. The malware is delivered through DLL sideloading with a signed benign executable, a modified malicious DLL, and an encrypted payload, ultimately deploying a backdoor that supports modular plug-ins. Researchers said the campaign aligns with Chinese geopolitical interests in the region and assessed with medium confidence that it is linked to the Chinese state-backed RedFoxtrot group, also known as Nomad Panda.
Talisman was reported as a distinct PlugX lineage, differing from previously documented samples such as BackDoor.PlugX.38 through a unique internal signature, altered decryption logic, and minor code changes while preserving core PlugX behavior. Trellix said the malware retains familiar capabilities including persistence, process injection, and plug-in extensibility, and identified command-and-control infrastructure using Dynamic DNS services and VPS hosting that overlaps with earlier RedFoxtrot and related PCShare activity.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Dr.Web published a malware description library entry for BackDoor.PlugX.38, documenting this PlugX family malware variant in its database.
Trellix reported that the embedded plug-ins found in the analyzed Talisman PlugX samples carried creation dates in 2018 in their metadata. This is the earliest explicit temporal anchor in the reference content.
Trellix disclosed a newly discovered PlugX variant dubbed Talisman, describing its DLL sideloading execution chain, modified decryption logic, and plug-in-enabled backdoor capabilities. The researchers assessed with medium confidence that the campaign was linked to the Chinese state-backed RedFoxtrot group based on infrastructure overlaps and victimology involving telecommunications and defense targets in South Asia.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 51 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.