PlugX, also known as KorPlug and Sogu, is a Windows remote-access trojan widely associated with Chinese cyberespionage activity. It provides an operator-controlled backdoor with command dispatching and command-and-control functionality, and its implementations use API-resolution obfuscation to hinder static analysis. PlugX has been used by groups including Mustang Panda (HoneyMyte), including as an initial foothold from which additional implants such as CoolClient were deployed. U.S. authorities removed PlugX surveillance malware from thousands of U.S. systems infected in Mustang Panda activity during 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
The Microsoft Word document attachments observed in this campaign utilized CVE-2012-0158 to exploit the client and implant the PlugX RAT. | The attacks employed PlugX malware, a Remote Access Trojan (RAT) widely used in targeted attacks.
It is assumed that the initial infection occurred due to an exploit of a vulnerability in MS Exchange: CVE-2021-26855 — Exploit Public-Facing Application T1190.
The Sanshiro series contains a vulnerability that allows arbitrary code execution (CVE-2014-0810), which was leveraged as a zero-day exploit by APT actors against Japanese government agencies. | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
The attacks observed in September 2013 leveraged another zero-day vulnerability in Internet Explorer (CVE-2013-3918). In these cases, the PlugX malware, a plug-in-based bot known as McRAT and a tunnelling tool, Htran, were later found in the victim’s environment. | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
They used various exploits such as Adobe Flash (CVE-2011-2462), Microsoft Office Word (CVE-2012-0158) and Ichitaro (CVE-2013-5990). | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
They used various exploits such as Adobe Flash (CVE-2011-2462), Microsoft Office Word (CVE-2012-0158) and Ichitaro (CVE-2013-5990). In the case of Ichitaro, the actor leveraged the vulnerability as a zero-day exploit. | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
CVE-2014-7247 was exploited as a zero-day vulnerability. The attack was carried out through targeted emails which were distributed to government agencies and enterprises in Japan. | Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
Exploit public facing app: LookingFrog and JollyFrog CVE-2019-0604 ProxyLogon (March 2021) ProxyShell (August 2021)
On March 19, 2021, attackers were observed exploiting an Exchange Server via a chain of zero-days (CVE-2021-26855 and CVE-2021-27065), known as ProxyLogon, originating from IP 101.36.120[.]227. | Unit 42 researchers identified a PlugX variant delivered as a post-exploitation remote access tool (RAT) to one of the compromised servers. The variant observed by Unit 42 is unique in that it contains a change to its core source code: the replacement of its trademark word “PLUG” to “THOR.”
As per my analysis, this variant of Poison Ivy eventually launches the MS17-010 (Eternal Blue) attack against the machines located inside the victim’s LAN... Based on our analysis, this new Poison Ivy variant takes advantage of the EternalBlue exploit to spread.
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
Post-exploitation included credential dumping (Mimikatz) and privilege escalation using CVE-2017-0213... overall attribution remains unresolved (APT27 vs. Winnti remains plausible).
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
Associated Analytic Story Spearphishing Attachments ... CVE-2023-36884 Office and Windows HTML RCE Vulnerability ... PlugX ... NjRAT
In May 2024, CVE-2024-24919, an information disclosure vulnerability in Check Point Quantum Security Gateways was exploited in the wild and tied to NailaoLocker ransomware (distributed via ShadowPad and PlugX backdoors, as documented by Orange Cyberdefense CERT).
attackers opportunistically used spear-phishing emails with a Microsoft Word attachment exploiting the recently patched CVE-2017-0199 to deploy the ZeroT Trojan... In this campaign, attackers used a Microsoft Word document called 0721.doc, which exploits CVE-2017-0199. This vulnerability was disclosed and patched days prior to this attack.
At the end of the infection chain, hackers deployed a version of PlugX malware onto victim machines. PlugX is a remote access Trojan that's been a staple of Chinese nation-state hacking since 2008. | Microsoft has been aware of the flaw, tracked as CVE-2025-9491, at least since September 2024, when the Zero Day Initiative identified it as ZDI-25-148 and ZDI-CAN-25373 and notified Redmond. The vulnerability exists in how Windows processes .lnk files, which are desktop icons acting as a shortcut to another file or application.
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks."
"...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks." | Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
“PlugX often used by Chinese threat actors… PlugX is a variant of the BackDoor.PlugX.38…”
In one case, we could see that this variant was deployed following exploitation of the CVE-2020-0688 vulnerability on the network of a government entity. This vulnerability, which was publicly reported in February 2020, allows an authenticated user to run commands as SYSTEM on a Microsoft Exchange server. | Avira blogged about HoneyMyte PlugX variants... PlugX has been used by multiple APT groups over the past decade...
It appears to have started with CVE-2014-3393, a vulnerability in the Cisco Clientless SSL VPN portal... A vulnerability in the Clientless SSL VPN portal customization framework could allow an unauthenticated, remote attacker to modify the content of the Clientless SSL VPN portal... An exploit could allow the attacker to bypass Clientless SSL VPN authentication and modify the portal content.
Associated Analytic Story AgentTesla CVE-2023-21716 Word RTF Heap Corruption Compromised Windows Host FIN7 PlugX Warzone RAT
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
26 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
« 2025 : Suppression du malware PlugX de plus de 4 000 ordinateurs américains infectés par Mustang Panda »
In addition to using PlugX and Poison Ivy (PIVY), both known to be used by the group...
Additionally, the actors have now added the popular PlugX backdoor to their toolkit.
Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. PlugX has the ability to use DLL search order hijacking for installation on targeted systems.
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The actor copied the malware components into the directory, renamed a legitimate Sangfor executable to defender.exe for DLL sideloading, and established persistence through a scheduled task that launched the binary with SYSTEM privileges during system startup.
Functions – File/Registry operations – Keylogging, screenshot, remote shell
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
Windows API functions are called directly | If this is not the case, the auto-run registry key is created instead.
The actor copied the malware components into the directory, renamed a legitimate Sangfor executable to defender.exe for DLL sideloading, and established persistence through a scheduled task that launched the binary with SYSTEM privileges during system startup.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
Upon execution, the malware will install itself as a service with the following parameters: Service Name RasTls... Service Description Symantec 802.1x Supplicant
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The actor copied the malware components into the directory, renamed a legitimate Sangfor executable to defender.exe for DLL sideloading, and established persistence through a scheduled task that launched the binary with SYSTEM privileges during system startup.
create & inject code ... 1st injected process (e.g., svchost.exe) 2nd injected process (msiexec.exe) ... PlugX Payload (only resident in RAM)
Upon execution, the malware will install itself as a service with the following parameters: Service Name RasTls... Service Description Symantec 802.1x Supplicant
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Quarkslab said in a report shared with Cyber Security News (CSN) that rather than untangling flattened code paths and misleading calculations, it copied small routines into Python, executed code under emulation, or searched the workspace for useful clues.
the constant 0xffc97c1f —in combination with the string kernel32 , suggests that this sequence of function calls represents an API hashing routine , a mechanism often utilized by malware to obfuscate API calls from static analysis. | This mechanism works by traversing a series of API function names represented as strings, computing their hash values and subsequently comparing the computed hash values to a pre-computed constant during runtime. If a match is found, the corresponding API function is imported and executed.
The actor copied the malware components into the directory, renamed a legitimate Sangfor executable to defender.exe for DLL sideloading... before injecting into a process named synchost.exe.
create & inject code ... 1st injected process (e.g., svchost.exe) 2nd injected process (msiexec.exe) ... PlugX Payload (only resident in RAM)
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content repeatedly describes malware and threat actors creating hidden folders, adding dot prefixes to filenames, and setting file attributes such as hidden/system to conceal files and directories from users and defenders.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
Functions – File/Registry operations – Keylogging, screenshot, remote shell – portscan, SQL command, etc…
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Supported Protocols – TCP, HTTP, UDP, ICMP (not implemented) ... Type III ... TCP & HTTP supported | Supported Protocols – TCP, HTTP, UDP, ICMP (not implemented) ... Type II ... More protocols • ICMP • DNS [5] (not sure) ... Type III ... TCP & HTTP supported
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
По данным специалистов, в новых атаках HoneyMyte сначала устанавливала на машины жертв PlugX, а уже через него разворачивала CoolClient.
1,388 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access trojan mentioned as part of a separate 2025 U.S. disruption operation involving systems infected by Mustang Panda.
The article cites the FBI disruption of PlugX in 2025 as a prior example of U.S. operations against China-linked malicious activity.
Surveillance malware removed by the FBI from more than 4,000 infected U.S. computers during a separate 2025 operation.
Malware referenced as a prior, separate FBI remediation operation involving Mustang Panda, rather than the subject QTFY operation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.