#ControlPlug
Incident/Operation
2024-06-05 • Operation ControlPlug: MSCファイルを使った標的型攻撃キャンペーン
Operation ControlPlug was a targeted campaign observed in May 2024 and attributed to the group tracked as DarkPeony. Potential targets included military and government organizations in Myanmar, the Philippines, Mongolia, and Serbia. The campaign used Microsoft Common Console documents as its initial vector: a deceptive taskpad link launched PowerShell, which downloaded and executed an MSI package. A legitimate executable then performed DLL side-loading, decoded a data file, and launched PlugX. Access controls on payload-hosting infrastructure were apparently used to serve intended victims while blocking researchers and automated analysis.
-
2
Tagged Reports
-
1
Unique Authors
-
9
Active Days