SmugX is a Chinese-linked campaign targeting diplomatic entities using HTML Smuggling to deliver PlugX.
Analyst brief
SmugX is a campaign overlapping with previous Chinese APT activity from RedDelta and Mustang Panda, but with insufficient evidence to link it directly to the Camaro Dragon group. It likely targets diplomatic and political entities. The primary TTP involves novel delivery methods like HTML Smuggling to deploy a new PlugX variant, achieving low detection rates. Defenders should closely inspect HTML attachments in emails and monitor for suspicious script execution leading to PlugX C2 connections.
SmugX
unknown
The campaign, called SmugX, overlaps with previously reported activity by Chinese APT actors RedDelta and Mustang Panda. Although those two correlate to some extent with Camaro Dragon, there is insufficient evidence to link the SmugX campaign to the Camaro Dragon group.
The campaign uses new delivery methods to deploy (most notably – HTML Smuggling) a new variant of PlugX, an implant commonly associated with a wide variety of Chinese threat actors. Although the payload itself remains similar to the one found in older PlugX variants, its delivery methods results in low detection rates, which until recently helped the campaign fly under the radar.