Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatphishing-campaign-intelligenceremote-access-implant

PKPLUG Linked to Chinese Espionage Campaigns Across Southeast Asia

Updated 27d agoFirst seen May 26, 20261 source

Palo Alto Networks Unit 42 reported that the PKPLUG intrusion set conducted long-running cyber espionage operations across Asia, particularly in Southeast Asia, and assessed with high confidence that the activity is tied to Chinese nation-state adversaries. The group was described as active for at least six years and focused on targets in Myanmar, Taiwan, Vietnam, Indonesia, Mongolia, Tibet, and Xinjiang, indicating intelligence collection against politically and geopolitically sensitive organizations and communities.

The campaigns used a combination of public and custom malware, including PlugX, Poison Ivy, Zupdax, 9002, HenBox, and the previously unknown Windows backdoor Farseer, with DLL side-loading and spear-phishing repeatedly used for delivery and execution. Unit 42 said overlapping infrastructure, malware characteristics, and shared tactics connected multiple previously reported operations under the PKPLUG umbrella, while HenBox expanded the threat to Android devices—especially targeting Uyghurs and Xiaomi devices—and the researchers released a STIX 2.0 adversary playbook consolidating indicators, campaigns, and ATT&CK-mapped techniques.

Share:
PKPLUG Linked to Chinese Espionage Campaigns Across Southeast Asia
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Oct 3, 20197y ago

Unit 42 publishes PKPLUG report and STIX playbook

Unit 42 publicly released its analysis of PKPLUG and published a PKPLUG Adversary Playbook in STIX 2.0 format. The playbook consolidated indicators, campaigns, and ATT&CK-mapped TTPs associated with the intrusion set.

Unit 42 links PKPLUG to Chinese nation-state adversaries

In its report, Unit 42 consolidated multiple previously published campaigns under the PKPLUG cluster and assessed with high confidence that the group had ties to Chinese nation-state adversaries. The report highlighted targeting in Myanmar, Taiwan, Vietnam, Indonesia, Mongolia, Tibet, and Xinjiang.

HenBox campaigns target Android devices and Uyghur victims

PKPLUG-linked activity expanded to Android through the HenBox malware, with targeting that included Uyghurs and Xiaomi devices. This indicated the group's operations extended beyond Windows systems to mobile espionage.

Oct 3, 201610y ago

Unit 42 starts tracking PKPLUG activity

Unit 42 reported that it had tracked PKPLUG for three years prior to publication, observing campaigns linked by overlapping infrastructure, malware characteristics, and tactics. This tracking connected activity involving tools such as PlugX, Poison Ivy, Zupdax, 9002, HenBox, and Farseer.

Oct 3, 201313y ago

PKPLUG begins cyber espionage activity across Asia

Unit 42 assessed that the PKPLUG intrusion set had been active for at least six years, conducting cyber espionage operations across Asia with a focus on Southeast Asia. The group used spear-phishing, DLL side-loading, and a mix of public and custom malware in its operations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

26 LINKEDOpen in app
Threat actors
2 linked
Affected products
8 linked
WindowsTrapsRealplayerAndroidWinrarGoogle DriveMicrosoft OfficeWildfire
Organizations
9 linked
RealNetworksArbor NetworksPalo Alto NetworksXiaomiMicrosoft CorporationGoogleDroidVPNBlue Coat LabsVKRL
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.