APT10 (Stone Panda / Cicada) - PlugX Malware DLL Side-Loading via MSP Access

Detects DLL side-loading where a known legitimate signed executable, often associated with security utilities, loads a DLL from a non-standard, user-writable directory (such as Temp, AppData, or ProgramData). This behavior is characteristic of APT10's (Stone Panda/Cicada) historical tradecraft in MSP environments to execute modular PlugX RAT payloads.