Security researchers have discovered a new variant of the PlugX malware that can hide malicious files on removable USB devices and infect Windows hosts they connect to. The malware uses a novel technique to remain undetected for longer periods and has the potential to spread to air-gapped systems. The variant was found by Palo Alto Network’s Unit 42 team during a response to a Black Basta ransomware attack that relied on GootLoader and the Brute Ratel post-exploitation toolkit. The threat actor uses a Windows debugging tool and a poisoned version of a DLL file to load the PlugX payload. This variant is notable for using a Unicode character called non-breaking space to hide files on USB devices. It also copies itself to any removable device connected to an infected host by disguising itself in a recycle bin folder. The researchers concluded that the discovery of this variant indicates that the development of PlugX is still active among some attackers and it remains a significant threat.
#PlugXmalware #USBdevices #infection #windowshosts #securityresearchers #malwarevariant #removableUSBdevices #hidesmaliciousfiles#Windowshost #remainundetected #spread #airgappedsystems #paloalto #Network #unit42 #blackbastaransomware #GootLoader #bruteratel #post-exploitation #toolkit #threatactor #windows #debugging #tool #poisoned #DLL #PlugX #payload #hide #infected #recyclebin #activethreat #malware #development #tsa #TSA #aficionado #cybercrime #cybersecurity #aficionados #cybernews #informationsecuritynews #hacker #malware