PlugX USB Worm Goes Global DLL Sideloading Fuels Multi-Continent Rampage

Researchers have tracked a new variant of the PlugX USB worm spreading across several regions, including Papua New Guinea, Ghana, Mongolia, Zimbabwe, and Nigeria.

The malware uses DLL sideloading to load its payload via a legitimate-looking executable, helping it hide on infected systems and move more quietly than typical malware.

The infection begins with a clean program that is abused as a loader, while a malicious DLL runs alongside it.

In the incident described, the malware used AvastSvc.exe, wsc.dll, and an encrypted .dat payload, then collected system details and stolen files into a hidden RECYCLER.BIN structure.

The worm also used a batch file to gather host data such as IP configuration, network state, running processes, and system information, which is a common way for malware to map a target before exfiltration.

The malware also used removable media to spread. It copied itself to USB drives, hid files with Windows attributes, and used shortcut tricks so the drive looked empty or harmless in Explorer.

That makes the worm especially useful for crossing isolated environments, because a USB stick can move from one system to another without needing a network connection.

An unusual distribution of infections is the hallmark of a new PlugX variant that relies on DLL sideloading to propagate (Source: sophos)
An unusual distribution of infections is the hallmark of a new PlugX variant that relies on DLL sideloading to propagate (Source: sophos)

The unusual part of this campaign is its geography. Infection activity was observed at distant locations over time, suggesting a worm-like propagation model rather than a single local outbreak.

Researchers also linked the new payload and command-and-control callbacks to an IP address that had appeared in earlier PlugX reporting, which strengthens the idea that this is an evolved PlugX family campaign rather than a totally new strain.

PlugX is a known remote access Trojan with a long history of DLL sideloading abuse, and security researchers have followed its variants for years.

Clean AvastSvc.exe executable (Source: sophos)
Clean AvastSvc.exe executable (Source: sophos)

The campaign described here shows that old tradecraft still works when malware is updated, and the delivery path is adapted to modern environments.

Defense Priorities

According to Sophos research, the main defense step is to watch for DLL sideloading, especially when a signed or trusted-looking executable loads an unexpected library from the same folder.

e07d58a12ceb3fde8bb6644b467c0a111b8d8b079b33768e4f1f4170e875bc00: AvastSvcpCP(2).zip

Security teams should also monitor USB activity, hidden directories, suspicious shortcut files on removable media, and batch scripts that run system discovery commands.

Blocking execution from removable drives and tightening endpoint controls can reduce the chance that an infected USB stick becomes a bridge into the network.

This campaign is a reminder that older malware techniques remain effective when combined with stealth and regional spread.

The combination of USB propagation, sideloading, and file theft makes PlugX a persistent threat to organizations that rely on removable media or have weak endpoint monitoring.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories