Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionagephishing-campaign-intelligencegovernment-diplomatic-threatremote-access-implant

Chinese APT Spearphishing Campaign Using Fake Cloudflare Lures to Deploy PlugX Malware

Updated 3mo agoFirst seen Oct 7, 20252 sources

Chinese state-sponsored threat actors have launched a sophisticated spearphishing campaign targeting government and aviation agencies across Europe, including a Serbian aviation agency. The attackers crafted malicious emails that appeared to be related to European government business, enticing recipients to click on links that redirected them to fraudulent Cloudflare verification pages. These fake pages were designed to deliver malware payloads, specifically PlugX, Sogu, and Korplug, which are commonly associated with Chinese cyberespionage groups. The campaign began in late September and has affected organizations in Serbia, Italy, Belgium, Hungary, and the Netherlands. Security researchers have attributed the activity to Chinese APTs, with some overlap in tactics and malware families used by groups such as Mustang Panda and UNC6384. The PlugX malware, a remote access trojan, enables attackers to exfiltrate sensitive data and maintain persistent access within compromised networks. The campaign's use of legitimate-looking Cloudflare lures increases the likelihood of successful credential harvesting and malware deployment. In response to the widespread use of PlugX, U.S. law enforcement, including the Justice Department and FBI, conducted operations to remove the malware from thousands of infected computers in the United States. The campaign demonstrates a high level of operational security, leveraging tailored phishing lures and multi-stage infection chains to evade detection. Security researchers have noted that the attackers continuously adapt their techniques, making use of current events and trusted brands to increase the credibility of their phishing emails. The deployment of multiple malware families in a single campaign suggests a broad espionage objective, targeting both information theft and long-term access. The campaign's cross-border nature highlights the global reach of Chinese cyberespionage operations. Organizations are advised to implement robust email filtering, user awareness training, and endpoint detection to mitigate the risk of similar attacks. The incident underscores the persistent threat posed by Chinese APTs to critical infrastructure and government entities worldwide. Ongoing analysis by cybersecurity firms continues to reveal new indicators of compromise and evolving tactics associated with this campaign. The use of PlugX and related malware remains a hallmark of Chinese cyberespionage, with attackers refining their delivery methods to bypass traditional security controls. The campaign's discovery has prompted increased collaboration between international law enforcement and private sector security teams to disrupt the threat and protect targeted organizations.

Share:
Chinese APT Spearphishing Campaign Using Fake Cloudflare Lures to Deploy PlugX Malware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Oct 7, 20259mo ago

Attack on Serbian aviation agency attributed to suspected Chinese cyberespionage hackers

An attack against Serbia's aviation agency was publicly linked to suspected Chinese cyberespionage actors. The reporting ties the incident to the broader activity associated with the PlugX-delivering campaign.

Suspected Chinese APT launches PlugX spearphishing campaign with fake Cloudflare lure

A suspected Chinese cyberespionage group began a spearphishing campaign using a fake Cloudflare-themed lure to deliver PlugX malware to targets. The reporting indicates the operation was active by the time of publication, but no earlier specific start date is provided.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

1 LINKEDOpen in app
Malware
1 linked
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.