KEYPLUG is a modular backdoor written in C++ and active since at least 2021. It has Windows and Linux variants and is closely associated with China-linked espionage activity, especially APT41 and related clusters including STORM-0866/Red Dev 40. The malware has also been assessed as likely shared across multiple suspected China-based intrusion sets, reflecting broader tooling overlap in that ecosystem.
KEYPLUG supports flexible command-and-control communications across multiple protocols, including HTTP, TCP, KCP over UDP, and TLS-encrypted WebSockets. Operators have also used Cloudflare CDN-associated infrastructure to proxy or redirect its command-and-control traffic, and the Windows variant has retrieved command-and-control addresses from encoded data embedded in posts on tech community forums, functioning as dead drop resolvers. Reported behavior also includes obtaining the current tick count from infected systems.
Operational reporting places KEYPLUG in intrusions against government entities, including U.S. government targets, and in campaigns focused on telecommunications providers and government organizations in the Middle East and South Asia. It has also been linked to activity targeting a major Japanese enterprise in operations involving exploitation of Fortinet devices, staging infrastructure, reconnaissance tooling, and webshell deployment. In victim environments, KEYPLUG has been observed coexisting with other espionage implants, underscoring its role as a maintained post-compromise access platform.
The malware is regarded as a staple backdoor in long-term espionage operations because of its modular design, multi-protocol networking, and adaptable infrastructure tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
APT41’s infrastructure was briefly exposed, and scripts, encrypted web shells, and reconnaissance tools that exploit the vulnerability of Fortinet devices were discovered. Malware and Tools: KeyPlug backdoor, 1.py, ws_test.py, bx.php, fscan. | APT41’s infrastructure was briefly exposed, and scripts, encrypted web shells, and reconnaissance tools that exploit the vulnerability of Fortinet devices were discovered. ... CVE-2024-23108: Fortinet vulnerability ... Attempted to gain initial access by exploiting the vulnerability of Fortinet firewall and VPN devices ... Executed CLI commands through an unauthorized WebSocket endpoint.
APT41’s infrastructure was briefly exposed, and scripts, encrypted web shells, and reconnaissance tools that exploit the vulnerability of Fortinet devices were discovered. Malware and Tools: KeyPlug backdoor, 1.py, ws_test.py, bx.php, fscan. | APT41’s infrastructure was briefly exposed, and scripts, encrypted web shells, and reconnaissance tools that exploit the vulnerability of Fortinet devices were discovered. ... CVE-2024-23109: Fortinet vulnerability ... Attempted to gain initial access by exploiting the vulnerability of Fortinet firewall and VPN devices ... Executed CLI commands through an unauthorized WebSocket endpoint.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The modular backdoor KEYPLUG is a staple in STORM-0866/Red Dev 40’s arsenal. Mandiant first reported on KEYPLUG as part of intrusions into U.S. government entities by the Chinese APT group APT41.
The fake FBI domain is one of the group’s favourites... five of which are observed to be used as the C2 server for malware such as KEYPLUG, SOGU, Cobalt Strike BEACON, GRAYRABBIT and Gh0st.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
At the heart of this new Winnti backdoor is a focused cloud credential harvesting engine that systematically walks through each major provider’s metadata and credential storage mechanisms. On AWS, the implant queries the instance metadata endpoint at 169.254.169.254 to extract IAM role credentials, while also reading the standard ~/.aws/credentials file if it exists. On GCP, it requests service account tokens from the metadata server and checks for application default credentials, and on Azure it pulls managed identity tokens from the IMDS endpoint and scans ~/.azure profiles. For Alibaba Cloud, the malware targets ECS metadata to obtain RAM role credentials and inspects the local Alibaba CLI configuration files.
Both backdoors first gather and exfiltrate system and user information in designated functions, with overlaps in gathered information (for example, MAC address, OS version, IP address, computer name, and username).
Both backdoors first gather and exfiltrate system and user information in designated functions, with overlaps in gathered information (for example, MAC address, OS version, IP address, computer name, and username).
Multiple malware and threat groups are described as collecting/deriving local system time, date, timestamp, tick count, or time zone (e.g., "used time /t and net time \ip/hostname for system time discovery"; "collects the timestamp from the victim’s machine"; "can collect the time zone information from the system").
The malware uses KCP protocol for backdoor communication... This backdoor has 20 commands and connects with C2 servers via KCP over UDP.
both implementing support for the HTTP, TCP, WebSocket, and QUIC protocols for C2 communication | The combination of QUIC and WebSocket is a relatively rare backdoor feature and its implementation in both LuaDream and KEYPLUG may be the result of a shared functional requirement by the backdoors’ operators.
PwC tracks STORM-0866/Red Dev 40 as a distinct cluster from the other threat groups using the KEYPLUG malware based on their frequent use of Cloud-based reverse proxy infrastructure, likely as an operational security measure to avoid exposing the true hosting locations. We observed this in the context of Sandman as well, noting a shift from using a directly exposed C2 server IP address (C2 domain: ssl.explorecell[.]com ) to address of a reverse proxy infrastructure (C2 domain: mode.encagil[.]com ).
"APT41 used a tool called CLASSFON to covertly proxy network communications." / "BADCALL functions as a proxy server between the victim and C2 server." / "Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic..."
"APT41 used the Cloudflare CDN to proxy C2 traffic." / "Earth Lusca adopted Cloudflare as a proxy for compromised servers." / "KEYPLUG has used Cloudflare CDN associated infrastructure to redirect C2 communications..." / "Gamaredon Group has used the Cloudflare Tunnel client to proxy C2 traffic."
LuaDream and KEYPLUG then instantiate threads designated for sending and receiving C2 data, establish connection to the C2 server, and continue to process backdoor commands and manage plugins. Plugin management includes loading and unloading plugins.
Examples include: "COATHANGER uses an HTTP GET request to initialize a follow-on TLS tunnel for command and control" and "Drovorub can use the WebSocket protocol and has initiated communication with C2 servers with an HTTP Upgrade request."
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
KeyPlug is a backdoor used by threat actors for persistent access and command and control. It has been observed in campaigns leveraging Fortinet exploits and webshells for initial access and staging.
KeyPlug is a backdoor used by APT41 for persistent access, command execution, and data exfiltration, often deployed after exploiting network device vulnerabilities such as those in Fortinet products.
A malware family/backdoor linked to APT41/RedGolf operations; the exposed infrastructure appeared to be used for staging and managing exploitation tooling and post-access activity.
Malware family referenced in connection with operational infrastructure that also hosted Fortinet exploit scripts and a PHP webshell for decrypted payload execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.