Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
SHA256MediumSignal 91/100
3299866538aff40ca85276f87dd0cefe4eafe167bd64732d67b06af4f3349916
First Seen
Aug 27, 2025
Last Seen
Jul 20, 2026
Found in 8 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
SHA-256 Hash
SHA-256 file hash — primary identifier for malware samples.
MISP Category
Artifacts Dropped
Hash Algorithm
SHA256
Confidence
91%
Signal Score
91 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
8 reports91% confidence
8
Source reports
91%
Confidence score
Category tags
abuseactive scanningadversary-in-the-middleaitm attackaptauthentication attacksbackdoorbackdoor implantblockbotnetbrute forcebrute force attackc2 communicationc2 ipc2 ip ioccaptive portalcaptive portal hijackcaptive portal hijackingcaptive portal redirectionchecks-usb-buscivil servicescommand and controlcompromise attemptcredential accesscredential stuffingcredential theftdata exfiltrationdigital signature abusedigital signaturesdigitally signeddiplomat targetingdistributed attacksdll side-loadingdll sideloadingespionage campaignexecutable filefile-hashftp brute forcegovernment technologyhosting infrastructurehosting iphosting ip iochttps traffichttps traffic interceptionin-memory executionindicatorknbgxngds rc4landing pagelanding page iocloopmalicious softwaremalwaremalware deliverymalware infectionman-in-the-middleman-in-the-middle attackmemory injectionmessage queuemessage queuesmonitor yaramsimsi packagemsi package iocmsi payload deliverymsiemustang pandamutex namemutex name iocname iocnetwork intrusionnetwork scanningnexus espionageoperating systempage httpspassword attacksplugxplugx malwareplugx variantprc-nexus aptprocess injectionpublic administrationpublic infrastructurepublic policyqueue windowsreconnaissanceregion: southeast asiaregulatory agenciesremote accessremote servicesresearchedrulessecurity operationssignedsigned malwaresocial engineeringsogu.secsoutheast asiaspearphishingssh attacksyn scant1012t1016t1021t1021.001t1027t1033t1036t1041t1048t1055t1055.001t1057t1059t1059.001t1059.003t1069.001t1071t1071.001t1076t1078t1078.001t1078.003t1082t1083t1095t1105t1110t1110.001t1110.002t1110.003t1110.004t1113t1124t1132t1132.001t1133t1140t1189t1190t1195t1195.002t1199t1202t1204t1204.002t1218t1218.011t1486t1496t1497t1499.002t1499.003t1546t1553t1553.002t1556t1563t1565t1566t1566.001t1566.002t1574t1574.002t1583t1583.001t1588t1588.002t1595t1595.001t1595.002t1595.003threat actorthreat actor: unc6384threat intelligencetyposquattingudp port scanunc6384valid certificate abuseweb hijackingweb traffic hijackingweb traffic redirectionwindowswindows messagewindows message queueswindows ntwindows systemwindows systems
Activity Timeline
Jul 20Jul 20
Threat Activity Heatmap
· Peak: 2026-07-20LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreHigh Risk
91
SIGNAL
Signal Score
91%
Confidence
8
Reports
First seenAug 27, 2025
Last seenJul 20, 2026
VirusTotal
Not checked
WHOIS
- references
- https://cloud.google.com/blog/topics/threat-intelligence/prc-nexus-espionage-targets-diplomats, https://cloud.google.com/blog/topics/threat-intelligence/prc-nexus-espionage-targets-diplomats/
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 1 month ago
Appeared in 8 threat reports