PlugX is a long-running Windows remote access trojan widely used in targeted intrusion and cyber-espionage operations. It is also known by aliases including Korplug, Gulpix, Sogu, Thoper, and Destory RAT. The malware has been associated with multiple China-linked threat clusters and has appeared across campaigns attributed to actors such as Mustang Panda and menuPass/APT10, as well as other intrusion sets that reuse the family.
PlugX is typically deployed as a post-compromise backdoor and supports modular remote administration and surveillance functions. Documented capabilities include process enumeration, screenshot capture, keylogging, command execution, and Windows Registry modification. Technical analyses also describe variants that decrypt and decompress their payloads at runtime and inject components into other processes. Some PlugX variants support additional operator functions such as remote shell access and scanning-related behavior.
A well-established execution and evasion pattern for PlugX is DLL side-loading or DLL load-order abuse, in which a legitimate signed or trusted executable is used to load a malicious library and start the implant while reducing detection. Historical analyses describe PlugX loaders that decrypt and decompress embedded payloads and then execute or inject the final backdoor. Persistence has been observed through Windows Run key autostart entries.
PlugX has been used in spearphishing-led campaigns against government, academic, pharmaceutical, manufacturing, and high-technology targets, including operations focused on Japan and other parts of Asia. In more recent Mustang Panda activity, PlugX served as an initial implant used to deploy the CoolClient backdoor during intrusions affecting organizations in countries including Myanmar, Mongolia, Pakistan, and Russia. Across its many variants and campaigns, PlugX remains one of the most recognizable espionage RAT families in the China-linked intrusion ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
The Microsoft Word document attachments observed in this campaign utilized CVE-2012-0158 to exploit the client and implant the PlugX RAT. | The attacks employed PlugX malware, a Remote Access Trojan (RAT) widely used in targeted attacks.
It is assumed that the initial infection occurred due to an exploit of a vulnerability in MS Exchange: CVE-2021-26855 — Exploit Public-Facing Application T1190.
The Sanshiro series contains a vulnerability that allows arbitrary code execution (CVE-2014-0810), which was leveraged as a zero-day exploit by APT actors against Japanese government agencies. | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
The attacks observed in September 2013 leveraged another zero-day vulnerability in Internet Explorer (CVE-2013-3918). In these cases, the PlugX malware, a plug-in-based bot known as McRAT and a tunnelling tool, Htran, were later found in the victim’s environment. | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
They used various exploits such as Adobe Flash (CVE-2011-2462), Microsoft Office Word (CVE-2012-0158) and Ichitaro (CVE-2013-5990). | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
They used various exploits such as Adobe Flash (CVE-2011-2462), Microsoft Office Word (CVE-2012-0158) and Ichitaro (CVE-2013-5990). In the case of Ichitaro, the actor leveraged the vulnerability as a zero-day exploit. | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
CVE-2014-7247 was exploited as a zero-day vulnerability. The attack was carried out through targeted emails which were distributed to government agencies and enterprises in Japan. | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
On March 19, 2021, attackers were observed exploiting an Exchange Server via a chain of zero-days (CVE-2021-26855 and CVE-2021-27065), known as ProxyLogon, originating from IP 101.36.120[.]227. | Unit 42 researchers identified a PlugX variant delivered as a post-exploitation remote access tool (RAT) to one of the compromised servers. The variant observed by Unit 42 is unique in that it contains a change to its core source code: the replacement of its trademark word “PLUG” to “THOR.”
As per my analysis, this variant of Poison Ivy eventually launches the MS17-010 (Eternal Blue) attack against the machines located inside the victim’s LAN... Based on our analysis, this new Poison Ivy variant takes advantage of the EternalBlue exploit to spread.
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
Post-exploitation included credential dumping (Mimikatz) and privilege escalation using CVE-2017-0213... overall attribution remains unresolved (APT27 vs. Winnti remains plausible).
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
Associated Analytic Story Spearphishing Attachments ... CVE-2023-36884 Office and Windows HTML RCE Vulnerability ... PlugX ... NjRAT
In May 2024, CVE-2024-24919, an information disclosure vulnerability in Check Point Quantum Security Gateways was exploited in the wild and tied to NailaoLocker ransomware (distributed via ShadowPad and PlugX backdoors, as documented by Orange Cyberdefense CERT).
attackers opportunistically used spear-phishing emails with a Microsoft Word attachment exploiting the recently patched CVE-2017-0199 to deploy the ZeroT Trojan... In this campaign, attackers used a Microsoft Word document called 0721.doc, which exploits CVE-2017-0199. This vulnerability was disclosed and patched days prior to this attack.
At the end of the infection chain, hackers deployed a version of PlugX malware onto victim machines. PlugX is a remote access Trojan that's been a staple of Chinese nation-state hacking since 2008. | Microsoft has been aware of the flaw, tracked as CVE-2025-9491, at least since September 2024, when the Zero Day Initiative identified it as ZDI-25-148 and ZDI-CAN-25373 and notified Redmond. The vulnerability exists in how Windows processes .lnk files, which are desktop icons acting as a shortcut to another file or application.
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks."
"...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks." | Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
“PlugX often used by Chinese threat actors… PlugX is a variant of the BackDoor.PlugX.38…”
In one case, we could see that this variant was deployed following exploitation of the CVE-2020-0688 vulnerability on the network of a government entity. This vulnerability, which was publicly reported in February 2020, allows an authenticated user to run commands as SYSTEM on a Microsoft Exchange server. | Avira blogged about HoneyMyte PlugX variants... PlugX has been used by multiple APT groups over the past decade...
It appears to have started with CVE-2014-3393, a vulnerability in the Cisco Clientless SSL VPN portal... A vulnerability in the Clientless SSL VPN portal customization framework could allow an unauthenticated, remote attacker to modify the content of the Clientless SSL VPN portal... An exploit could allow the attacker to bypass Clientless SSL VPN authentication and modify the portal content.
Associated Analytic Story AgentTesla CVE-2023-21716 Word RTF Heap Corruption Compromised Windows Host FIN7 PlugX Warzone RAT
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
28 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CoolClient consistently deployed as a secondary backdoor following a PlugX infection ... HoneyMyte used PlugX as the initial post-compromise implant to deploy CoolClient.
In addition to using PlugX and Poison Ivy (PIVY), both known to be used by the group...
Additionally, the actors have now added the popular PlugX backdoor to their toolkit.
Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. PlugX has the ability to use DLL search order hijacking for installation on targeted systems.
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
34 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers spoofed several sender email addresses to send spear phishing emails, most notably public addresses associated with the Sasakawa Peace Foundation and The White House.
The actor copied the malware components into the directory, renamed a legitimate Sangfor executable to defender.exe for DLL sideloading, and established persistence through a scheduled task that launched the binary with SYSTEM privileges during system startup.
Functions – File/Registry operations – Keylogging, screenshot, remote shell
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
Windows API functions are called directly | If this is not the case, the auto-run registry key is created instead.
The actor copied the malware components into the directory, renamed a legitimate Sangfor executable to defender.exe for DLL sideloading, and established persistence through a scheduled task that launched the binary with SYSTEM privileges during system startup.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
Upon execution, the malware will install itself as a service with the following parameters: Service Name RasTls... Service Description Symantec 802.1x Supplicant
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The actor copied the malware components into the directory, renamed a legitimate Sangfor executable to defender.exe for DLL sideloading, and established persistence through a scheduled task that launched the binary with SYSTEM privileges during system startup.
create & inject code ... 1st injected process (e.g., svchost.exe) 2nd injected process (msiexec.exe) ... PlugX Payload (only resident in RAM)
Upon execution, the malware will install itself as a service with the following parameters: Service Name RasTls... Service Description Symantec 802.1x Supplicant
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
the shellcode constructs the names of the APIs... by using the stackstring technique | it can be seen that its code has been completely obfuscated by Obfuscator-LLVM, using the Control Flow Flattening technique
The actor copied the malware components into the directory, renamed a legitimate Sangfor executable to defender.exe for DLL sideloading... before injecting into a process named synchost.exe.
create & inject code ... 1st injected process (e.g., svchost.exe) 2nd injected process (msiexec.exe) ... PlugX Payload (only resident in RAM)
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content repeatedly describes malware and threat actors creating hidden folders, adding dot prefixes to filenames, and setting file attributes such as hidden/system to conceal files and directories from users and defenders.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
Functions – File/Registry operations – Keylogging, screenshot, remote shell – portscan, SQL command, etc…
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Supported Protocols – TCP, HTTP, UDP, ICMP (not implemented) ... Type III ... TCP & HTTP supported | Supported Protocols – TCP, HTTP, UDP, ICMP (not implemented) ... Type II ... More protocols • ICMP • DNS [5] (not sure) ... Type III ... TCP & HTTP supported
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
1,384 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A post-compromise implant/backdoor used by Mustang Panda to gain an initial foothold before deploying CoolClient as a secondary backdoor.
Remote access trojan used as the initial implant before deployment of CoolClient in the Myanmar campaign.
An initial post-compromise implant/backdoor used to deploy CoolClient in the described campaign.
Used as the initial post-compromise implant and foothold to deploy CoolClient as a secondary backdoor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.