An espionage campaign (by the UNC6384 group) emerged in early 2025, targeting diplomats and government agencies in Southeast Asia and beyond. At the heart of this operation is STATICPLUGIN, a downloader carefully disguised as a legitimate Adobe plugin update.

Victims were confronted with what is known as a captive portal hijack, which redirected browsers to malicious domains, where an HTTPS-secured page urged users to 'Install Missing Plugins…'. This is a scam, which attempts to reduce suspicion and warnings browser
Chinese hacking group UNC6384: Complex multi-stage attack
Once executed, the binary developed a multi-stage chain that culminated in the launch of the SOGU.SEC backdoor in memory. After the initial breach, STATICPLUGIN retrieved an MSI package disguised as a BMP image. Inside this package is CANONSTAGER, which executes the encrypted payload cnmplog.dat. This side-loading technique exploits trusted Windows components to evade host-based defenses.
See also: Chinese APT group uses Proxy and VPN services
Google Cloud analysts have identified this new combination of captive portal hijacking and valid code signing as a development linked to China. Evidence shows that Chengdu Nuoxin Times Technology Co., Ltd.issued the signing certificates used for STATICPLUGIN, giving the downloader a false sense of legitimacy. These certificates, issued by GlobalSign and Let's Encrypt, allowed the malware to bypass many endpoint security solutions that trust digitally signed binaries.

Google Cloud researchers noted that although the original certificate expired on July 14, 2025, the Chinese UNC6384 is likely re-signing subsequent versions to maintain uninterrupted silent operation.
CANONSTAGER's detailed analysis reveals unusual evasion tactics. The launcher resolves Windows API addresses using a custom hashing algorithm and stores them in Thread Local Storage (TLS), an unusual location that can go unnoticed by monitoring tools.
By indirectly calling these functions through a hidden window procedure and sending a WM_SHOWWINDOW message, CANONSTAGER hides its actual control flow within legitimate Windows message queues.
See also: Phishing Attack Uses UpCrypter to Deliver RAT
One of the most notable innovations of the Chinese hackers UNC6384 is in the end-to-end in-memory execution. After creating the hidden window and API resolving, CANONSTAGER creates a new thread to decrypt cnmplog.dat via a hardcoded 16-byte RC4 key. Instead of writing the decrypted SOGU.SEC payload to disk, the launcher calls the EnumSystemGeoID function as a callback function to execute the backdoor directly in memory. This technique makes it difficult for network defenders to detect the threat, as there is no malicious binary file on disk.
Additionally, communications with the C2 server at 166.88.2.90 are conducted over HTTPS, resulting in confusion with legitimate web traffic and further complicating network-based detection.

The initial JavaScript triggers the download of AdobePlugins.exe, setting the stage for execution in memory. By avoiding disk writes and leveraging valid certificates, the Chinese UNC6384 group has raised the bar for silent malware operation.
See also: New Android malware mimics Russian FSB antivirus
Protection: What do security experts recommend?
As Google Cloud analysts continue to monitor this campaign, defenders are urged to inspect memory artifacts, enforce strict code signing policies , and enable Enhanced Safe Browsing to detect abnormal TLS certificates and captive portal hijacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
