Skip to main content
Mallory
MalwareUsed by 14 actorsExploits 15 CVEs

PlugX

Also known asDestroyRATKabaKorplugPlugX RATSoguSOGU.SECThoperTVT

PlugX is a remote access trojan (RAT) / backdoor widely used by Chinese state-linked and PRC-based espionage actors since at least 2008–2012. Aliases in the provided content include Korplug, SOGU, Kaba, Destroyrat, Thoper, TVT, and PlugX_RAT. It is repeatedly associated with Chinese threat groups including Mustang Panda (also tracked as RedDelta, Bronze President, Stately Taurus), APT41/Winnti, PKPLUG-related activity, and other China-linked clusters.

Across the cited reporting, PlugX is commonly delivered through phishing and archive-based lures, fake browser or software updates, trojanized installers, malicious documents, and especially DLL side-loading using legitimate signed executables. Observed side-loading hosts and package patterns include G DATA Avk.exe with Avk.dll and AVKTray.dat, AvastSvc.exe with wsc.dll and AvastAuth.dat, McAfee binaries such as scncgf32.exe/vsodscpl.dll and siteadv.exe/siteadv.dll, Cisco and VLC-related binaries, RealPlayer, and other legitimate applications. The malware is also referenced in USB-worm-enabled propagation scenarios and in campaigns using staged loaders, shellcode, or downloaders such as DOWNBAIT/PULLBAIT and PUBLOAD.

Capabilities directly described in the content include remote command execution and remote shell access, file upload/download, file enumeration and deletion, process launching, process and service management, screenshot capture, keylogging, registry enumeration and editing, SQL enumeration, port mapping, configurable network protocols, plugin-based capability expansion, collection and staging of victim files for exfiltration, and exfiltration of stolen data to command-and-control servers. PlugX can query the Windows Registry and collect system information from infected hosts.

The content describes multiple persistence and execution patterns: three-component installations consisting of a benign executable, malicious DLL loader, and encoded payload; manual mapping of the final payload into memory; registry Run key persistence; service-based persistence in some related campaigns; mutex creation; and in-memory execution designed to reduce static and behavioral detection. Some reporting notes command-and-control over TCP/HTTPS on port 443, including RC4-encrypted communications and traffic crafted to resemble legitimate browser activity; defenders are advised to watch for plaintext or otherwise non-SSL traffic over port 443 in some cases.

Targeting described in the content is consistent with long-running cyber-espionage operations against governments, diplomats, law enforcement, NGOs, telecoms, think tanks, Catholic/Vatican entities, software developers, and other strategic organizations, with notable geographic focus on Asia and Southeast Asia including Mongolia, Taiwan, Myanmar, Vietnam, Cambodia, Japan, and ASEAN-affiliated entities, as well as Europe and other regions. Specific indicators mentioned in the content for PlugX-related activity include fruitbrat[.]com, dalerocks[.]com:443, 45[.]251[.]243[.]210, sg3appstore[.]net, us3appstore[.]net, bz3appstore[.]info, maildantri[.]org, link.linkipv6[.]com, 192.225.226[.]123, 192.225.226[.]217, and 45.77.173[.]124:443, along with artifacts such as Avk.exe, Avk.dll, AVKTray.dat, AvastSvc.exe, wsc.dll, AvastAuth.dat, and registry paths including HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKCU\Software\Classes\ms-pu\CLSID in one observed chain.

The content also notes that PlugX remains in heavy use despite ShadowPad often being described as its successor or evolution.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

15 CVES
CVE-2025-9491Microsoft Windows LNK File UI Misrepresentation Remote Code Execution VulnerabilityExploited in the wild

At the end of the infection chain, hackers deployed a version of PlugX malware onto victim machines. PlugX is a remote access Trojan that's been a staple of Chinese nation-state hacking since 2008. | Microsoft has been aware of the flaw, tracked as CVE-2025-9491, at least since September 2024, when the Zero Day Initiative identified it as ZDI-25-148 and ZDI-CAN-25373 and notified Redmond. The vulnerability exists in how Windows processes .lnk files, which are desktop icons acting as a shortcut to another file or application.

via govinfosecuritygovinfosecurity.com
CVE-2012-0158MSCOMCTL.OCX ListView/TreeView ActiveX Remote Code ExecutionExploited in the wild

The name comes from the tactic of delivering PlugX malware inside ZIP archive files as part of a DLL side-loading package. | Blue Coat noted the DLL side-loading technique used to launch the malicious payload via legitimate, signed applications. Their report also documented the group’s use of an exploit against software vulnerabilities in Microsoft Office. In this case, using a weaponized Word document saved as a Single File Web Page format ... in order to exploit CVE-2012-0158 to drop and execute a signed WinRAR SFX archive containing the side-loading package and PlugX payload.

via palo alto networks unit 42 blogunit42.paloaltonetworks.com
CVE-2021-26855ProxyLogon SSRF in Microsoft Exchange ServerExploited in the wild

"...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks." | Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 ... Security firm Volexity spotted hackers targeting Exchange servers on Jan. 3, when it saw CVE-2021-26855 being exploited.

via bank info securitybankinfosecurity.com
CVE-2021-26857Microsoft Exchange Unified Messaging insecure deserialization RCEExploited in the wild

Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks."

via bank info securitybankinfosecurity.com
CVE-2021-27065ProxyLogon post-auth arbitrary file write in Microsoft Exchange ServerExploited in the wild

Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks."

via bank info securitybankinfosecurity.com
CVE-2021-26858Microsoft Exchange Server post-auth arbitrary file write (ProxyLogon)Exploited in the wild

"...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks." | Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065

via bank info securitybankinfosecurity.com
CVE-2025-55182React2ShellExploited in the wild

"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."

via f5 communitycommunity.f5.com
CVE-2024-23692Unauthenticated RCE in Rejetto HTTP File Server via Template InjectionExploited in the wild

“PlugX often used by Chinese threat actors… PlugX is a variant of the BackDoor.PlugX.38…”

via ahnlab asec blogasec.ahnlab.com
CVE-2020-0688Microsoft Exchange Server static validation key RCEExploited in the wild

In one case, we could see that this variant was deployed following exploitation of the CVE-2020-0688 vulnerability on the network of a government entity. This vulnerability, which was publicly reported in February 2020, allows an authenticated user to run commands as SYSTEM on a Microsoft Exchange server. | Avira blogged about HoneyMyte PlugX variants... PlugX has been used by multiple APT groups over the past decade...

via securelistsecurelist.com
CVE-2024-24919Arbitrary File Read in Check Point Security GatewaysExploited in the wild

The campaign, discovered by Orange Cyberdefense and later analyzed by Fortinet, typically began with the exploitation of CVE-2024-24919, a critical vulnerability in Check Point VPN appliances.

via splunk researchresearch.splunk.com
CVE-2014-3393Authentication Bypass in Cisco ASA Clientless SSL VPN Portal Customization FrameworkExploited in the wild

It appears to have started with CVE-2014-3393, a vulnerability in the Cisco Clientless SSL VPN portal... A vulnerability in the Clientless SSL VPN portal customization framework could allow an unauthenticated, remote attacker to modify the content of the Clientless SSL VPN portal... An exploit could allow the attacker to bypass Clientless SSL VPN authentication and modify the portal content.

via volexity blogvolexity.com
CVE-2023-21716Microsoft Word RTF Heap Corruption Remote Code Execution

Associated Analytic Story AgentTesla CVE-2023-21716 Word RTF Heap Corruption Compromised Windows Host FIN7 PlugX Warzone RAT

via splunk researchresearch.splunk.com
CVE-2021-40444Microsoft MSHTML Remote Code Execution VulnerabilityExploited in the wild

Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”

via cyfirma newscyfirma.com
CVE-2021-1675PrintNightmare / Windows Print Spooler RCE in CVE-2021-1675 contextExploited in the wild

Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”

via cyfirma newscyfirma.com
CVE-2017-0199Microsoft Office/WordPad Remote Code Execution VulnerabilityExploited in the wild

"Mustang Panda has exploited CVE-2017-0199 in Microsoft Word to execute code."

via mitre attack websiteattack.mitre.org
THREAT ACTORS

Groups observed using it

14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Mustang Panda

A well-known Chinese state-sponsored threat group called Mustang Panda has been caught running a sophisticated cyberattack campaign using its signature remote access tool, PlugX.

via cyber security newscybersecuritynews.com
Earth Krahang

Using our telemetry data, we found that the threat actor also dropped PlugX and ShadowPad samples in victim environments.

via trend micro researchtrendmicro.com
Threat Group-3390

Inside: captive-portal Wi-Fi Pineapples that bypass MFA, PlugX side-loading through legitimate apps, and the USB worm that jumps air-gapped military networks.

via securitysenses blogsecuritysenses.com
APT41

This group is also linked to the use of PlugX/Fast/Korplug/ and Winnti/Pasteboy and Shadowpad malware, with the Korplug and Winnti being prominent malware families since 2012.

via fortinet threat signalfortiguard.fortinet.com
Axiom

The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.

via polyswarmblog.polyswarm.io
PKPLUG

The name comes from the tactic of delivering PlugX malware inside ZIP archive files as part of a DLL side-loading package.

via palo alto networks unit 42 blogunit42.paloaltonetworks.com
Space Pirates

Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.

via ptsecurityptsecurity.com
UNC3569

UNC3569 uses this malware payload installer tool to deploy the SOGU backdoor, demonstrating a willingness to leverage external resources to enhance its operational capabilities.

via virusbulletinvirusbulletin.com
TA428

These revolved around a few known toolsets commonly associated with Chinese threat actors, notably the PlugX malware... PlugX is a well-known Chinese trojan used by a whole host of threat actors.

via web archiveweb.archive.org
menuPass

In addition to the continued use of SOGU, the current wave of intrusions has involved new tools we believe are unique to APT10.

via web archiveweb.archive.org
TA459

In 2017, Proofpoint issued a report about attacks against targets in Russia and Belarus using ZeroT and PlugX.

via web archiveweb.archive.org
RedCurl

Like other researchers, we thought this might be a PlugX-like campaign, given that the attack chain shares several characteristics with observed PlugX attacks.

via sophos blogsophos.com
Dragon Breath

Like other researchers, we thought this might be a PlugX-like campaign, given that the attack chain shares several characteristics with observed PlugX attacks.

via sophos blogsophos.com
Carderbee

Later that August, Symantec highlighted the activity of a new threat cluster codenamed Carderbee, which was found using a trojanized version of the program to deploy PlugX, a backdoor widely used by Chinese hacking groups like Mustang Panda.

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

34 distinct techniques documented for this family, organized by ATT&CK tactic.

T1588.001MalwareEvidence1

Earth Krahang delivers backdoors to establish access to victim machines. Cobalt Strike and two custom backdoors, RESHELL and XDealer, were employed during the initial stage of attack.

Initial Access

6 techniques
T1091Replication Through Removable MediaEvidence1

the USB worm that jumps air-gapped military networks

T1195Supply Chain CompromiseEvidence1

It has been linked to supply chain compromises and for hacking into popular software vendors. Well known software titles with significant installation bases were compromised with malware.

T1195.001Compromise Software Dependencies and Development ToolsEvidence1

The modus operandi of this group was to compromise developer workstations that had access to source code repositories and then install backdoors and other malware into legitimate software.

T1566PhishingEvidence1

Considering all the malware related to PKPLUG that Unit 42 has analyzed, the use of such exploits appears to be less common than a spear-phishing technique making use of social engineering to lure victims into running their malware.

T1566.001Spearphishing AttachmentEvidence3

UNC6384 hackers goaded Belgian and Hungarian diplomats into unzipping archived files containing a malicious shortcut file through spear-phishing emails that used themes such as an agenda for a European Commission meeting on free trade in the Western Balkans.

T1566.002Spearphishing LinkEvidence1

Most recently, RedDelta used spearphishing links to prompt a victim to load an HTML file remotely hosted on Microsoft Azure.

Execution

4 techniques
T1059.001PowerShellEvidence1
TacticExecution

After execution, the malicious shortcut file decodes a tar archive file and uses PowerShell to execute it - while also displaying a PDF decoy document.

T1059.003Windows Command ShellEvidence2
TacticExecution

It could... launch processes and capture their output...

T1204.002Malicious FileEvidence2
TacticExecution

In 2024, the group transitioned to using Microsoft Management Console Snap-In Control (MSC) files. | In late 2023, RedDelta evolved the first stage of its infection chain to leverage a Windows Shortcut (LNK) file likely delivered via spearphishing.

T1574.001DLLEvidence2

Hidden folders within the archive contained three files used to complete dynamic-link library (DLL) search order hijacking: a legitimate binary, a malicious DLL loader, and an encrypted PlugX payload that was ultimately loaded into memory.

Persistence

3 techniques
T1112Modify RegistryEvidence2

It also stored a unique client ID in the registry to identify the infected machine to the remote server.

T1547Boot or Logon Autostart ExecutionEvidence1

Examples include 'adds Registry Run keys to establish persistence', 'creates a shortcut in the Startup folder', and 'RunOnce Registry key to run itself on safe mode.'

T1547.001Registry Run Keys / Startup FolderEvidence2

After loading, it installed itself into %PUBLIC%\GData and wrote a persistence entry to the Windows Run registry key, ensuring it restarts every time the user logs in.

T1055.003Thread Execution HijackingEvidence1

It read the encrypted payload inside AVKTray.dat, granted it execute permissions in memory, then triggered execution through a Windows threadpool callback, a method that hides the true origin of execution from security monitoring tools.

T1547Boot or Logon Autostart ExecutionEvidence1

Examples include 'adds Registry Run keys to establish persistence', 'creates a shortcut in the Startup folder', and 'RunOnce Registry key to run itself on safe mode.'

T1547.001Registry Run Keys / Startup FolderEvidence2

After loading, it installed itself into %PUBLIC%\GData and wrote a persistence entry to the Windows Run registry key, ensuring it restarts every time the user logs in.

Stealth

10 techniques
T1027.007Dynamic API ResolutionEvidence1
TacticStealth

Avk.dll served as an intermediate loader, using a runtime hashing technique to resolve Windows APIs without exposing them through static analysis.

T1036MasqueradingEvidence2
TacticStealth

The group used a cleverly disguised fake browser update to trick users into downloading a multi-stage malware loader... The dropper, Browser_Updater.exe, opened a convincing fake update window styled after Adobe Acrobat... and downloaded what looked like a JPEG image but was actually a hidden MSI installer.

T1055.003Thread Execution HijackingEvidence1

It read the encrypted payload inside AVKTray.dat, granted it execute permissions in memory, then triggered execution through a Windows threadpool callback, a method that hides the true origin of execution from security monitoring tools.

T1070.004File DeletionEvidence1
TacticStealth

It could... enumerate and delete files...

T1140Deobfuscate/Decode Files or InformationEvidence1
TacticStealth

The payload inside AVKTray.dat passed through multiple decryption layers, including XOR followed by RC4 decryption using the key VOphJo...

T1218System Binary Proxy ExecutionEvidence2
TacticStealth

The tar archive also contains a legitimate Canon printer assistant utility that hackers hijack to use as a loader to decrypt and execute yet another file containing the PlugX payload. The Canon utility is signed with a legitimate Symantec certificate...

T1497.001System ChecksEvidence1

It could... kill diagnostic tools like iediagcmd.exe to prevent an admin from spotting unusual activity.

T1564.001Hidden Files and DirectoriesEvidence1
TacticStealth

The PlugX variant crates a hidden directory... This version of the Trojan can change the directory name with each new system launch, making the infection harder to detect.

T1574.001DLLEvidence2

Hidden folders within the archive contained three files used to complete dynamic-link library (DLL) search order hijacking: a legitimate binary, a malicious DLL loader, and an encrypted PlugX payload that was ultimately loaded into memory.

T1620Reflective Code LoadingEvidence2
TacticStealth

It read the encrypted payload inside AVKTray.dat, granted it execute permissions in memory... The payload... was manually mapped into memory without touching the disk as a normal executable.

T1112Modify RegistryEvidence2

It also stored a unique client ID in the registry to identify the infected machine to the remote server.

Discovery

2 techniques
T1083File and Directory DiscoveryEvidence1
TacticDiscovery

It could... enumerate and delete files...

T1497.001System ChecksEvidence1

It could... kill diagnostic tools like iediagcmd.exe to prevent an admin from spotting unusual activity.

Lateral Movement

2 techniques
T1091Replication Through Removable MediaEvidence1

the USB worm that jumps air-gapped military networks

T1570Lateral Tool TransferEvidence1

the USB worm that jumps air-gapped military networks

Collection

3 techniques
T1005Data from Local SystemEvidence1

PUBLOAD is equipped with features to conduct reconnaissance of the infected network and harvest files of interest (.doc, .docx, .xls, .xlsx, .pdf, .ppt, and .pptx) ... PlugX then takes care of deploying another bespoke file collector called FILESAC that can collect the victim's files.

T1074Data StagedEvidence1

The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.

T1560Archive Collected DataEvidence2

This activity used an infection chain that began by delivering an archive file (ZIP, RAR, or ISO), which was likely delivered via spearphishing.

T1071Application Layer ProtocolEvidence2

Both UNC6384 and Mustang Panda share operational characteristics including a mutual interest in breaching government agencies, overlapping command-and-control infrastructure utilization of DLL side-loading techniques and PlugX deployment, Arctic Wolf wrote.

T1071.001Web ProtocolsEvidence3

Once installed, the payload connected to its command-and-control server at fruitbrat[.]com over port 443, using HTTPS to blend in with normal web traffic.

T1105Ingress Tool TransferEvidence3

It could download and execute files from the C2... Plugin loader stubs in the code also allowed the attackers to push additional capabilities to infected machines whenever needed.

T1219Remote Access ToolsEvidence1

ShadowPad This backdoor RAT, reported by Kaspersky in 2017... It is considered to be an evolution of PlugX, both of which originated from China and are used by Chinese APTs (APT41 in particular).

T1568.002Domain Generation AlgorithmsEvidence1

Unlike the last cluster however, this variant appears to have been used in an extensive DDNS cluster of infrastructure dating back to at least 2013... that campaign appeared to have slightly different tactics, techniques, and procedures (TTPs), including potentially target-themed domain infrastructure as well as heavily relying on dynamic DNS for C2 domains.

Other

1 technique
T1656ImpersonationEvidence1

It crafted its requests to mimic Microsoft Edge browser activity, making detection at the network level even harder.

INDICATORS OF COMPROMISE

IOCs tracked for this family

520 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
231 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
277 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
12 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
hash.md5●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in app3 days ago
domain●●●●●●●●●●●●View more in app3 days ago
hash.sha256●●●●●●●●●●●●View more in app3 days ago
hash.sha256●●●●●●●●●●●●View more in app3 days ago
hash.sha256●●●●●●●●●●●●View more in app3 days ago
ACTIVITY FEED

Recent activity

200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

cyber security newsNews
Jun 2, 2026
Mustang Panda Deploys PlugX RAT Through Multi-Stage LNK and PowerShell Attack Chain

PlugX is a remote access implant used by Mustang Panda. In this campaign it was delivered through a multi-stage loader chain using DLL sideloading, decrypted from AVKTray.dat, manually mapped into memory, persisted via the Windows Run key, and communicated with a C2 server over HTTPS while mimicking Microsoft Edge traffic. It supports downloading and executing files, launching processes and capturing output, uploading and downloading file chunks, enumerating and deleting files, killing diagnostic tools, and loading additional plugins.

Read more
securitysenses blogNews
May 27, 2026
Ep. 60 - The Puppet Masters: Mustang Panda's Long Con Against ASEAN Diplomats | SecuritySenses

A remote access trojan used via DLL side-loading through legitimate applications to provide covert access on victim systems.

Read more
cysecurity newsNews
May 23, 2026
Fake Claude AI Site Spreads New Beagle Windows Backdoor - Here’s How to Stay Safe - CySecurity News - Latest Information Security and Hacking Incidents

A malware family referenced for technical overlap and possible actor linkage; the content suggests actors associated with PlugX may be experimenting with Beagle.

Read more
polyswarmNews
May 22, 2026
Wicked Panda’s ShadowPad RAT

The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching520

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution14

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities15

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping34

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.