PlugX, also known as Korplug, Sogu, Destroy RAT, and Thoper, is a modular remote access Trojan targeting Windows systems. It is widely used in cyberespionage operations by multiple China-linked threat actors, including Mustang Panda, APT10/menuPass, Goblin Panda, Calypso, Winnti Group, and Space Pirates. Its use by numerous groups means that a PlugX infection alone does not establish actor attribution. Observed deployments span government and diplomatic institutions, defense organizations, manufacturing, aerospace, shipping, transportation, and other commercial sectors.
PlugX provides remote command execution, file enumeration, upload and download operations, system discovery, and persistent backdoor access. Its plugin-based architecture supports additional functionality that varies between builds, including process, service, registry, and network management, port forwarding, and keylogging. Some variants omit surveillance plugins present in other builds. Operators have used PlugX to enumerate remote systems in compromised Windows domains and collect sensitive documents for exfiltration. Persistence mechanisms include registry autorun entries, scheduled tasks, and Windows services. Command-and-control configurations support raw TCP or UDP; variants such as MetaRAT and Talisman additionally support HTTP, HTTPS, and ICMP.
Delivery includes spearphishing with weaponized documents or malicious Windows shortcuts, as well as deployment after exploitation of exposed server applications. PlugX has been installed following ProxyLogon exploitation of Microsoft Exchange and compromise of vulnerable HTTP File Server installations. Execution commonly involves DLL sideloading through legitimate applications. Analyzed variants use encrypted or compressed payloads, in-memory loading, string obfuscation, anti-debugging checks, and process injection to impede detection and analysis. Some PlugX builds also check for virtualization-related processes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2024년 5월 HFS의 원격 코드 실행 취약점인 CVE-2024-23692가 공개되었으며 이를 활용할 경우 공격자는 HFS에 명령이 포함된 패킷을 전송하여 HFS가 악성 명령을 실행하도록 할 수 있다.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
A Windows LNK (shortcut) UI-misrepresentation vulnerability (CVE-2025-9491, ZDI-CAN-25373) is being actively exploited by a China-linked threat actor tracked as UNC6384 to deliver the PlugX Remote Access Trojan (RAT) against European diplomatic and government targets.
The report attributes initial intrusion to likely exploitation of CVE-2024-21893 and CVE-2024-21887. Files detected by Ivanti's Integrity Checker Tool matched filenames associated with LITTLELAMB, WOOLTEA, PITSOCK, and PITFUEL, and the observed evidence resembled previously reported attacks exploiting these vulnerabilities.
The report identifies CVE-2024-21893 and CVE-2024-21887 as the likely initial-entry vulnerabilities in a campaign targeting Japanese shipping and transportation companies and their subsidiaries. Numerous ERR31093 critical errors, associated with processing malicious SAML payloads exploiting CVE-2024-21893, were recorded near the suspected intrusion time.
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
The Microsoft Word document attachments observed in this campaign utilized CVE-2012-0158 to exploit the client and implant the PlugX RAT. | The attacks employed PlugX malware, a Remote Access Trojan (RAT) widely used in targeted attacks.
The Sanshiro series contains a vulnerability that allows arbitrary code execution (CVE-2014-0810), which was leveraged as a zero-day exploit by APT actors against Japanese government agencies. | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
The attacks observed in September 2013 leveraged another zero-day vulnerability in Internet Explorer (CVE-2013-3918). In these cases, the PlugX malware, a plug-in-based bot known as McRAT and a tunnelling tool, Htran, were later found in the victim’s environment. | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
They used various exploits such as Adobe Flash (CVE-2011-2462), Microsoft Office Word (CVE-2012-0158) and Ichitaro (CVE-2013-5990). | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
They used various exploits such as Adobe Flash (CVE-2011-2462), Microsoft Office Word (CVE-2012-0158) and Ichitaro (CVE-2013-5990). In the case of Ichitaro, the actor leveraged the vulnerability as a zero-day exploit. | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
CVE-2014-7247 was exploited as a zero-day vulnerability. The attack was carried out through targeted emails which were distributed to government agencies and enterprises in Japan. | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
As per my analysis, this variant of Poison Ivy eventually launches the MS17-010 (Eternal Blue) attack against the machines located inside the victim’s LAN... Based on our analysis, this new Poison Ivy variant takes advantage of the EternalBlue exploit to spread.
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
Post-exploitation included credential dumping (Mimikatz) and privilege escalation using CVE-2017-0213... overall attribution remains unresolved (APT27 vs. Winnti remains plausible).
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
Associated Analytic Story Spearphishing Attachments ... CVE-2023-36884 Office and Windows HTML RCE Vulnerability ... PlugX ... NjRAT
In May 2024, CVE-2024-24919, an information disclosure vulnerability in Check Point Quantum Security Gateways was exploited in the wild and tied to NailaoLocker ransomware (distributed via ShadowPad and PlugX backdoors, as documented by Orange Cyberdefense CERT).
attackers opportunistically used spear-phishing emails with a Microsoft Word attachment exploiting the recently patched CVE-2017-0199 to deploy the ZeroT Trojan... In this campaign, attackers used a Microsoft Word document called 0721.doc, which exploits CVE-2017-0199. This vulnerability was disclosed and patched days prior to this attack.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
In one case, we could see that this variant was deployed following exploitation of the CVE-2020-0688 vulnerability on the network of a government entity. This vulnerability, which was publicly reported in February 2020, allows an authenticated user to run commands as SYSTEM on a Microsoft Exchange server. | Avira blogged about HoneyMyte PlugX variants... PlugX has been used by multiple APT groups over the past decade...
It appears to have started with CVE-2014-3393, a vulnerability in the Cisco Clientless SSL VPN portal... A vulnerability in the Clientless SSL VPN portal customization framework could allow an unauthenticated, remote attacker to modify the content of the Clientless SSL VPN portal... An exploit could allow the attacker to bypass Clientless SSL VPN authentication and modify the portal content.
Associated Analytic Story AgentTesla CVE-2023-21716 Word RTF Heap Corruption Compromised Windows Host FIN7 PlugX Warzone RAT
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
34 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
menuPass has also issued the command net view /domain to a PlugX implant to gather information about remote systems on the network.
Favorite methodologies of Goblin Panda include the use of remote access Trojans, including the infamous PlugX/Korplug, NewCore, and Sisfader RAT tools.
Calypso deployed "a variant of PlugX specific to the group (Win32/Korplug.ED)"; a separate Winnti Group intrusion also involved "a PlugX RAT sample (also known as Korplug)."
Calypso deployed "a variant of PlugX specific to the group (Win32/Korplug.ED)"; a separate Winnti Group intrusion also involved "a PlugX RAT sample (also known as Korplug)."
While HyperBro was frequently used, the attackers also used the PlugX/Korplug Trojan as a payload at times.
SSH tunnels were established to communicate with internal hosts infected with the group’s malware (named “PlugX”) and since the F5 devices were exposed to the Internet traffic was not blocked.
48 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
1,413 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family mentioned only to describe Korplug's linkage; it is not otherwise discussed in the reference.
Remote-access trojan mentioned as part of a separate 2025 U.S. disruption operation involving systems infected by Mustang Panda.
Mentioned only as background concerning an earlier FBI operation against China-linked infrastructure. The article does not describe its capabilities or connect it to QTFY.
The article cites the FBI disruption of PlugX in 2025 as a prior example of U.S. operations against China-linked malicious activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.