PlugX, also known as Korplug and SOGU, is a long-running Windows remote access trojan and backdoor family closely associated with Chinese espionage activity and frequently observed in campaigns attributed to groups such as Mustang Panda and in broader China-nexus intrusion clusters. It has been used for cyberespionage against government, law enforcement, defense, diplomatic, research, and other strategic targets across Asia and Europe, and has also appeared in activity linked to the wider APT10 ecosystem.
PlugX is typically deployed through multi-stage infection chains that rely on social engineering and loader components rather than direct execution of the final implant. Observed delivery patterns include spearphishing lures, fake software or browser update themes, malicious shortcut-based execution chains, and DLL sideloading using legitimate signed executables. Recent campaigns have used layered loaders, shellcode stages, and encrypted payload containers to unpack and manually map the final PlugX implant in memory, complicating static detection and forensic recovery.
The malware provides full remote access and post-compromise control. Documented capabilities include remote shell execution, file management, process control, service control, screenshot capture, keylogging, registry enumeration and modification, system and network information gathering, network share browsing, port forwarding, ODBC query support, and plugin-based extensibility. PlugX variants commonly support multiple command-and-control transports, including HTTP or HTTPS and raw TCP, with some variants also supporting UDP and DNS-based tunneling. Configuration data and traffic are often protected with layered encoding or encryption such as XOR and RC4.
PlugX is notable for its modularity and the breadth of its operational use across Chinese intrusion sets. It has repeatedly appeared alongside other China-linked tooling such as ShadowPad and Cobalt Strike in espionage operations. In one reported victim set involving Pakistani law enforcement organizations, PlugX activity was assessed as part of a China-nexus cluster targeting systems containing biometric, criminal, personnel, and citizen complaint data. Across campaigns, its tradecraft emphasizes stealthy execution, persistence, and durable remote administration in support of long-term intelligence collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In May 2024, CVE-2024-24919, an information disclosure vulnerability in Check Point Quantum Security Gateways was exploited in the wild and tied to NailaoLocker ransomware (distributed via ShadowPad and PlugX backdoors, as documented by Orange Cyberdefense CERT).
attackers opportunistically used spear-phishing emails with a Microsoft Word attachment exploiting the recently patched CVE-2017-0199 to deploy the ZeroT Trojan... In this campaign, attackers used a Microsoft Word document called 0721.doc, which exploits CVE-2017-0199. This vulnerability was disclosed and patched days prior to this attack.
In previous campaigns, the group used spear-phishing emails with Microsoft Word document attachments utilizing CVE-2012-0158... Attackers also continued to send spear-phishing emails with Microsoft Word attachments utilizing CVE-2012-0158 to exploit the client.
At the end of the infection chain, hackers deployed a version of PlugX malware onto victim machines. PlugX is a remote access Trojan that's been a staple of Chinese nation-state hacking since 2008. | Microsoft has been aware of the flaw, tracked as CVE-2025-9491, at least since September 2024, when the Zero Day Initiative identified it as ZDI-25-148 and ZDI-CAN-25373 and notified Redmond. The vulnerability exists in how Windows processes .lnk files, which are desktop icons acting as a shortcut to another file or application.
"...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks." | Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 ... Security firm Volexity spotted hackers targeting Exchange servers on Jan. 3, when it saw CVE-2021-26855 being exploited.
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks."
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks."
"...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks." | Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
“PlugX often used by Chinese threat actors… PlugX is a variant of the BackDoor.PlugX.38…”
In one case, we could see that this variant was deployed following exploitation of the CVE-2020-0688 vulnerability on the network of a government entity. This vulnerability, which was publicly reported in February 2020, allows an authenticated user to run commands as SYSTEM on a Microsoft Exchange server. | Avira blogged about HoneyMyte PlugX variants... PlugX has been used by multiple APT groups over the past decade...
It appears to have started with CVE-2014-3393, a vulnerability in the Cisco Clientless SSL VPN portal... A vulnerability in the Clientless SSL VPN portal customization framework could allow an unauthenticated, remote attacker to modify the content of the Clientless SSL VPN portal... An exploit could allow the attacker to bypass Clientless SSL VPN authentication and modify the portal content.
Associated Analytic Story AgentTesla CVE-2023-21716 Word RTF Heap Corruption Compromised Windows Host FIN7 PlugX Warzone RAT
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
26 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A core infosec truth, often overlooked, is that only CN threat actors leverage the sogu/plugx/korplug toolset for live intrusions... At this point we see the below decoy content, and see a standard SOGU connection to naturadeco.net
Malware families and tools associated with APT10 include SOGU, HAYMAKER, SNUGRIDE, BUGJUICE, QUASARRAT, RedLeaves, PlugX, UPPERCUT/ANEL, ChChes, and, in newer related reporting, LODEINFO, NOOPDOOR, and NOOPLDR.
The initial and primary backdoor the threat actor used in this attack was the PlugX backdoor. PlugX is a well-known remote access tool (RAT) with modular plugins and customizable settings that has been popular for over a decade, primarily among Chinese-speaking threat groups.
The stage 2 payload was PlugX that beaconed to C&C servers www[.]icefirebest[.]com and www[.]icekkk[.]net.
Moshen Dragon deployed five different malware triads in an attempt to use DLL search order hijacking to sideload ShadowPad and PlugX variants.
Using our telemetry data, we found that the threat actor also dropped PlugX and ShadowPad samples in victim environments.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
According to the researchers, a China-linked operator planted malware disguised as a portal update — an executable that displayed a fake “update complete” message while infecting the visitor's device.
Backdoors shared among Chinese groups, including PlugX and ShadowPad, anchored the China-nexus assessments
Target chain : rundll32.exe -> shell32.dll,ShellExec_RunDLL -> conhost --headless -> cmd /c curl ...
The loader and payload directly use many Native/Windows APIs such as NtCreateFile, NtQueryInformationFile, NtReadFile, NtProtectVirtualMemory, VirtualAlloc, CreateThread, WriteProcessMemory, WinHttpOpen, and WinHttpConnect.
Upon clicking the link, the target is presented with a fake Cloudflare turnstile-style page
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
reads Shelter.ex , decrypts it using SystemFunction033 with the key 20260301@@@ , then transfers execution into the newly decrypted region
Numerous malware families and threat groups are described as achieving persistence by adding values under Run/RunOnce/Policies\Explorer\Run Registry keys or by placing shortcuts/files in the Windows Startup folder.
It doesn't rely on any packer or fancy encryption; it just inserts junk characters, fake whitespace, and misplaced quotes to break simple pattern matching.
Avk.dll resolves APIs using DJB2 hash; cJvsVIDinbGD resolves them using ROL19 hash; the worker thread decodes API names and resolves them at runtime.
The researchers also found malicious files disguised as software updates planted directly on Balochistan Police’s public Complaint Management System.
The malware installs itself into %PUBLIC%\GData and uses the folder name GData and Run key G Data to match the legitimate publisher/brand of Avk.exe.
reads Shelter.ex , decrypts it using SystemFunction033 with the key 20260301@@@ , then transfers execution into the newly decrypted region
The malware decodes multiple layers at runtime: decoding the string \AVKTray.dat, XOR-decoding the payload, RC4-decoding the config, and XOR-decoding each config field and C2 entry.
launch ShellFolder.exe as a signed cover for the sideloading step.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The command surface includes process-related capability; additionally, the side-effect taskkill iediagcmd.exe shows that the payload handles processes by name.
register_system_control_dispatcher System info, memory, locale
Its analysis of command-and-control netflow data revealed four tooling clusters converging on this victim class: PlugX, ShadowPad, Cobalt Strike, and Remcos.
The controller loop uses WinHTTP to connect to fruitbrat[.]com:443, builds an HTTP GET request, uses an Edge/Chrome-like User-Agent, and sends Cookie q63S=<encoded context> for beaconing.
730 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor associated in the content with suspected China-nexus cyberespionage activity targeting Pakistani law enforcement.
Referenced in external links only; not part of the main malware discussed in this article.
PlugX6
A malware family used in the observed espionage activity; the content notes PlugX is traditionally linked to Chinese state-sponsored groups.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.