PyPlunderPlug is a Python-based espionage malware component used by the threat actor TAG-110, also tracked as UAC-0063, in campaigns targeting government entities, diplomatic missions, and other high-value organizations in Central Asia and Europe. It has been associated with broader intelligence-gathering operations aligned with Russian strategic interests, although a definitive link to APT28 has not been established by all researchers.
PyPlunderPlug is designed to collect files from removable media. It searches attached removable drives for documents and other user data of interest, including document, image, archive, text, and temporary file types, then stages copies locally for later theft. It also maintains a local record of previously collected files to avoid redundant copying. Available reporting indicates that PyPlunderPlug does not implement its own command-and-control or direct exfiltration channel; instead, stolen data is likely removed through companion malware in the same intrusion set, particularly DownEx or CHERRYSPY/DownExPyer.
PyPlunderPlug has been observed as part of multi-stage intrusion chains involving malicious Microsoft Office documents and other TAG-110 tooling, including HATVIBE and LOGPIE. Within these operations, it functions as a specialized removable-media collection module supporting espionage objectives such as document theft and intelligence collection from compromised systems, especially where data may be transferred via USB devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
An USB data exfiltrator we named PyPlunderPlug was discovered on a victim's system.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware strain associated with UAC-0063/TAG-110 and used in attacks targeting Ukrainian state bodies.
A malware family used as a downstream payload in TAG-110's phishing-based espionage operations.
Custom malware family used by TAG-110 in espionage operations.
A Python script that monitors removable drives, recursively collects files with selected document/archive/image extensions, stages them locally, and avoids recopied duplicates using a local tracking database. It lacks its own exfiltration mechanism and likely relies on other implants for onward theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.