Cisco Talos has uncovered a sophisticated cyber espionage campaign targeting telecommunications and manufacturing sectors across Central and South Asian countries, revealing that the Chinese-speaking Naikon APT group has deployed a new variant of the notorious PlugX backdoor since 2022.
The campaign exhibits advanced technical overlaps with previously identified malware families, indicating possible coordinated tool sharing or operational connections between threat actors.
The research reveals that three distinct malware families, RainyDay, Turian, and the new PlugX variant, all exploit the same legitimate Mobile Popup Application through DLL search order hijacking techniques (MITRE ATT&CK T1574.001).
This sophisticated approach allows malicious loaders to execute within the context of trusted applications, significantly reducing detection rates and bypassing security controls.
Technical Convergence Across Malware Families
Talos analysts discovered remarkable technical similarities across the three malware families, indicating either shared development resources or coordinated operations.
All three variants utilize identical RC4 encryption keys, specifically “8f-2;g=3/c?1wf+c92rv.a” and “jfntv`1-m0vt801tyvqaf_)U89chasv”, for payload decryption processes.

The malware employs a sophisticated XOR-RC4-RtlDecompressBuffer algorithm combined with LZNT1 compression to obfuscate and compress payloads.
The loaders follow a consistent pattern: they read encrypted shellcode from hardcoded filenames “rdmin.src” for RainyDay, “Mcsitesdvisor.afx” for PlugX, and “winslivation.dat” for Turian, then decrypt and execute the payloads using identical XOR encryption routines.
The decrypted shellcode contains RC4-encrypted and LZNT1-compressed data that ultimately deploys the final backdoor components.
Analysis of Program Database (PDB) paths embedded within the loaders reveals development insights, with Turian samples containing references to “icmpsh-master” (ICMP Shell) and Chinese text translating to “provide web version,” suggesting web-based command and control modifications.
The consistent shellcode structures across all three malware families indicate shared development frameworks or tool vendors.
Attribution and Operational Connections
Talos assesses this campaign with medium confidence as being connected to Naikon, a Chinese-speaking APT group active since 2010.
The attribution is based on the PlugX variant adopting the same configuration structure as RainyDay, previously associated with Naikon operations.

This configuration similarity suggests access to the original PlugX source code, enabling custom modifications to match preferred operational frameworks.
The investigation also uncovered potential connections between Naikon and BackdoorDiplomacy, with both groups targeting similar industries and geographic regions.
Keylogger artifacts indicate persistent compromise spanning from 2022 through December 2024, with one victim environment showing nearly two years of continuous access.
The campaign’s focus on telecommunications infrastructure aligns with historical Chinese cyber espionage objectives, particularly in strategically significant Central and South Asian markets.
This research highlights the evolution of established threat actors, who adapt proven techniques while maintaining operational security through the abuse of legitimate applications and the use of sophisticated encryption methods.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates