Threats Tagged 'canonstager'
View all threats tagged with 'canonstager'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'canonstager'
Click on any threat for detailed analysis and mitigation recommendations
The Chinese-affiliated threat actor UNC6384 is exploiting the ZDI-CAN-25373 Windows vulnerability to deploy PlugX malware targeting European diplomatic entities, specifically in Hungary and Belgium. The attack vector involves spearphishing emails with malicious LNK files themed around diplomatic conferences. The campaign uses DLL side-loading of legitimate Canon printer utilities to evade detection and maintain persistence. UNC6384’s operations have expanded from Southeast Asia to Europe, focusing on espionage related to foreign policy, defense, and economic matters. This campaign demonstrates advanced social engineering and rapid exploitation of new vulnerabilities. The malware provides persistent remote access for intelligence gathering. No known public exploits exist yet, but the threat is active and targeted. The medium severity rating reflects the targeted nature and complexity of the attack. European diplomatic organizations should prioritize mitigation to protect sensitive information and maintain operational security. Join the discussion | AlienVault OTX General | 10/31/2025, 08:35:27 UTC Added: 10/31/2025, 09:08:46 UTC |
A sophisticated cyber espionage campaign attributed to the PRC-nexus threat actor UNC6384 targeted diplomats in Southeast Asia and other global entities. The attack chain involved hijacking web traffic through a captive portal redirect to deliver malware disguised as software updates. The multi-stage attack utilized advanced social engineering, adversary-in-the-middle techniques, and evasion tactics. The malware payload, SOGU.SEC backdoor, was deployed through a digitally signed downloader (STATICPLUGIN) and a side-loaded DLL (CANONSTAGER). The campaign demonstrated the evolving capabilities of PRC-nexus threat actors, employing stealthy tactics to avoid detection and leveraging legitimate Windows features for malicious purposes. Join the discussion | AlienVault OTX General | 08/26/2025, 00:06:08 UTC Added: 08/26/2025, 07:47:43 UTC |
Showing 1 to 2 of 2 results