PlugX is a modular Windows remote access trojan and backdoor that has been used for many years in targeted cyber-espionage operations, especially by multiple China-nexus threat actors. It is widely associated with long-running espionage activity against government, diplomatic, military, law-enforcement, research, telecommunications, and other strategic organizations across Asia, the Middle East, Europe, and elsewhere. PlugX has also appeared as a secondary payload in broader intrusion chains alongside other malware and post-compromise tooling.
PlugX is typically deployed after initial compromise and provides persistent remote control of infected systems. Reported capabilities include command execution, file operations, plugin-based expansion, credential theft, keylogging, reconnaissance, and broader post-exploitation support. In observed campaigns it has been installed as a second-stage payload after operators gained access through other malware, and it has been used to extend access during espionage operations involving document collection and staging.
A common operational pattern is delivery through DLL sideloading using legitimate signed executables, a technique repeatedly seen in China-linked intrusion sets. PlugX has also been delivered through spearphishing campaigns, including archive-based lures that ultimately execute sideloaded malicious components. Its long operational history, modular design, and repeated reuse across distinct clusters have made it one of the most recognizable malware families in the Chinese espionage ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In May 2024, CVE-2024-24919, an information disclosure vulnerability in Check Point Quantum Security Gateways was exploited in the wild and tied to NailaoLocker ransomware (distributed via ShadowPad and PlugX backdoors, as documented by Orange Cyberdefense CERT).
attackers opportunistically used spear-phishing emails with a Microsoft Word attachment exploiting the recently patched CVE-2017-0199 to deploy the ZeroT Trojan... In this campaign, attackers used a Microsoft Word document called 0721.doc, which exploits CVE-2017-0199. This vulnerability was disclosed and patched days prior to this attack.
In previous campaigns, the group used spear-phishing emails with Microsoft Word document attachments utilizing CVE-2012-0158... Attackers also continued to send spear-phishing emails with Microsoft Word attachments utilizing CVE-2012-0158 to exploit the client.
At the end of the infection chain, hackers deployed a version of PlugX malware onto victim machines. PlugX is a remote access Trojan that's been a staple of Chinese nation-state hacking since 2008. | Microsoft has been aware of the flaw, tracked as CVE-2025-9491, at least since September 2024, when the Zero Day Initiative identified it as ZDI-25-148 and ZDI-CAN-25373 and notified Redmond. The vulnerability exists in how Windows processes .lnk files, which are desktop icons acting as a shortcut to another file or application.
"...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks." | Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 ... Security firm Volexity spotted hackers targeting Exchange servers on Jan. 3, when it saw CVE-2021-26855 being exploited.
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks."
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks."
"...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks." | Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
“PlugX often used by Chinese threat actors… PlugX is a variant of the BackDoor.PlugX.38…”
In one case, we could see that this variant was deployed following exploitation of the CVE-2020-0688 vulnerability on the network of a government entity. This vulnerability, which was publicly reported in February 2020, allows an authenticated user to run commands as SYSTEM on a Microsoft Exchange server. | Avira blogged about HoneyMyte PlugX variants... PlugX has been used by multiple APT groups over the past decade...
It appears to have started with CVE-2014-3393, a vulnerability in the Cisco Clientless SSL VPN portal... A vulnerability in the Clientless SSL VPN portal customization framework could allow an unauthenticated, remote attacker to modify the content of the Clientless SSL VPN portal... An exploit could allow the attacker to bypass Clientless SSL VPN authentication and modify the portal content.
Associated Analytic Story AgentTesla CVE-2023-21716 Word RTF Heap Corruption Compromised Windows Host FIN7 PlugX Warzone RAT
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
28 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It is best known for its long-running use of PlugX, a modular remote access trojan (RAT)
Malware families and tools associated with APT10 include SOGU, HAYMAKER, SNUGRIDE, BUGJUICE, QUASARRAT, RedLeaves, PlugX, UPPERCUT/ANEL, ChChes, and, in newer related reporting, LODEINFO, NOOPDOOR, and NOOPLDR.
The initial and primary backdoor the threat actor used in this attack was the PlugX backdoor. PlugX is a well-known remote access tool (RAT) with modular plugins and customizable settings that has been popular for over a decade, primarily among Chinese-speaking threat groups.
The stage 2 payload was PlugX that beaconed to C&C servers www[.]icefirebest[.]com and www[.]icekkk[.]net.
Moshen Dragon deployed five different malware triads in an attempt to use DLL search order hijacking to sideload ShadowPad and PlugX variants.
Using our telemetry data, we found that the threat actor also dropped PlugX and ShadowPad samples in victim environments.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
According to the researchers, a China-linked operator planted malware disguised as a portal update — an executable that displayed a fake “update complete” message while infecting the visitor's device.
Une fois déployé, PlugX permet l’exécution à distance de commandes...
The loader and payload directly use many Native/Windows APIs such as NtCreateFile, NtQueryInformationFile, NtReadFile, NtProtectVirtualMemory, VirtualAlloc, CreateThread, WriteProcessMemory, WinHttpOpen, and WinHttpConnect.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The 1.bat script creates a service named NgcCIntSvc, which loads the loader DLL named oleasapi.dll.
The 1.bat script creates a service named NgcCIntSvc, which loads the loader DLL named oleasapi.dll.
Numerous malware families and threat groups are described as achieving persistence by adding values under Run/RunOnce/Policies\Explorer\Run Registry keys or by placing shortcuts/files in the Windows Startup folder.
It doesn't rely on any packer or fancy encryption; it just inserts junk characters, fake whitespace, and misplaced quotes to break simple pattern matching.
The researchers also found malicious files disguised as software updates planted directly on Balochistan Police’s public Complaint Management System.
The malware decodes multiple layers at runtime: decoding the string \AVKTray.dat, XOR-decoding the payload, RC4-decoding the config, and XOR-decoding each config field and C2 entry.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
Its analysis of command-and-control netflow data revealed four tooling clusters converging on this victim class: PlugX, ShadowPad, Cobalt Strike, and Remcos.
MINIRECON ... upgrades C2 to a WebSocket connection over HTTPS using the native WinHTTP API
814 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A secondary payload deployed during the intrusions to provide additional persistent access as part of the broader espionage activity.
Mentioned as another malware family sharing overlapping code-signing certificate signers with GoldenEyeDog-linked malware; not described as used by GoldenEyeDog in this reference.
A remote-access malware family deployed as a second-stage payload during the campaign. Its presence is cited as supporting Kaspersky's assessment of a Chinese-speaking actor.
China-nexus Threat Actor Targets Arabian Gulf Region With PlugX
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.