Cyber Threat Report: 'Earth Preta Campaign Uses DOPLUGS to Target Asia'

Report Author Trend Micro
Publication Date 2024-02-20
Original Reporting Source
Related Intrusion Sets BRONZE PRESIDENT , Mustang Panda , Earth Preta

This blog post by researchers from Trend Micro describes the use of a customized PlugX backdoor which they name DOPLUGS. The DOPLUGS malware uses the 'KillSomeOne' module which is a USB worm. The researchers attribute the activity to the APT group Earth Preta. The blog post outlines TTPs used in the campaign and provides technical analysis and indicators of compromise.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques