Attackers have been exploiting remote code execution flaws in the Sunlogin and AweSun remote-control tools to compromise exposed systems and install multiple malware families, including PlugX and Sliver. AhnLab reported that vulnerable Sunlogin versions—especially releases earlier than 11.0.0.33—were used in campaigns tied to CNVD-2022-10270 and CNVD-2022-03672, with additional payloads such as Gh0st RAT, XMRig, and Powercat also observed. In one intrusion, the attackers used a PowerShell-based chain and a bring-your-own-vulnerable-driver (BYOVD) technique leveraging mhyprot2.sys to disable security tools before launching a reverse shell and later deploying a Sliver implant configured for mTLS command-and-control.
In a separate but related campaign, attackers used Sunlogin and AweSun exploitation to deliver the PlugX backdoor through a DLL side-loading chain. A legitimate ESET executable, esetservice.exe, loaded a malicious http_dll.dll, which decrypted and executed PlugX from lang.dat directly in memory. AhnLab linked the activity to infrastructure at imango[.]ink, including api.imango[.]ink and cdn.imango[.]ink over ports 443 and 53. The PlugX sample matched the BackDoor.PlugX.38 family and supported UAC bypass, service installation, process injection, plugin execution, keylogging, clipboard theft, screenshot capture, remote shell access, and RDP-based propagation, underscoring continued abuse of remote-management software vulnerabilities for persistent backdoor deployment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
AhnLab found a WinRAR SFX PlugX dropper on VirusTotal that created esetservice.exe, http_dll.dll, and lang.dat, then executed the loader chain. The company assessed that the same threat actor likely conducted both the vulnerability exploitation and the dropper campaign because both used the imango[.]ink command-and-control infrastructure.
AhnLab reported that attackers were exploiting remote code execution weaknesses in Sunlogin and AweSun to install the PlugX backdoor. The observed chain used a legitimate ESET executable, a malicious http_dll.dll, and an encrypted lang.dat payload to launch PlugX in memory via DLL side-loading.
AhnLab published research describing ongoing exploitation of Sunlogin vulnerabilities to deploy malware including Sliver, Gh0st RAT, XMRig CoinMiner, and Powercat. The report also detailed a recent BYOVD-based attack chain using a modified Mhyprot2DrvControl and the vulnerable mhyprot2.sys driver to disable security tools before launching a reverse shell.
AhnLab reported that exploit code for Sunlogin remote code execution vulnerabilities CNVD-2022-10270 and CNVD-2022-03672 was publicly available in 2022, enabling later abuse in intrusion campaigns.
AhnLab stated that multiple attacks targeting vulnerable Sunlogin instances had been confirmed in ASD logs since early 2022. These attacks involved malware such as Gh0st RAT and XMRig CoinMiner delivered through Sunlogin remote code execution flaws.
MITRE ATT&CK published its software entry for PlugX (S0013), documenting the malware family in its knowledge base.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.