SYMBOLCOMMON_NAMEaka. SYNONYMS
win.staticplugin (Back to overview)

STATICPLUGIN

Actor(s): MUSTANG PANDA


According to Google, this is a digitally signed downloader written in Delphi, used for in-memory deployment of Mustang Panda's PlugX.

References
2025-08-25GoogleGoogle Threat Intelligence Group
Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats
STATICPLUGIN

There is no Yara-Signature yet.