Last seven days
- First activity
- Aug 19, 2026
- Last activity
- Aug 19, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
PlugX is a long-running Windows remote access trojan widely associated with Chinese espionage activity and frequently used in targeted intrusions against government, diplomatic, academic, and private-sector organizations across Asia and beyond.
Profile source: Mallory opens in a new tabPlugX
PlugX is a long-running Windows remote access trojan widely associated with Chinese espionage activity and frequently used in targeted intrusions against government, diplomatic, academic, and private-sector organizations across Asia and beyond. It is also known by aliases including Korplug, Sogu, Thoper, and Destory RAT. PlugX has been active since at least the late 2000s and has evolved through multiple variants with differing loaders, configuration formats, encryption schemes, and anti-analysis features. ShadowPad has been described as an evolution of PlugX, and both malware families are broadly used by Chinese threat clusters.
PlugX is a modular post-compromise implant and backdoor that provides operators with persistent remote control over infected Windows systems. Documented capabilities include process enumeration, system reconnaissance, command execution, screenshot capture, keylogging, registry modification, and execution of additional processes, including on hidden desktops. Some variants support remote shell functionality, port scanning, SQL command execution, and process injection into legitimate Windows processes. PlugX commonly uses encrypted and compressed payloads and configuration data, and some variants decrypt and decompress components in memory before injecting them into other processes.
A hallmark of PlugX tradecraft is abuse of DLL side-loading or DLL load-order hijacking through legitimate signed executables to evade detection and blend malicious execution with trusted software. It has also been observed establishing persistence through Windows Registry Run key entries. Technical analyses have identified multiple major PlugX types and extensive variation in configuration structures, protocols, and obfuscation methods, reflecting sustained development over many years.
PlugX has appeared in numerous espionage campaigns and has been linked to or used by multiple China-aligned threat actors, including Mustang Panda and menuPass, among others. In some modern intrusion chains, PlugX serves as an initial post-compromise implant used to deploy secondary backdoors such as CoolClient. Its longevity, modularity, and adaptability have made it one of the most recognizable and enduring espionage RAT families in the China-nexus ecosystem.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
По данным специалистов, в новых атаках HoneyMyte сначала устанавливала на машины жертв PlugX, а уже через него разворачивала CoolClient.
In addition to using PlugX and Poison Ivy (PIVY), both known to be used by the group...
Additionally, the actors have now added the popular PlugX backdoor to their toolkit.
Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. PlugX has the ability to use DLL search order hijacking for installation on targeted systems.
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. PlugX has the ability to use DLL search order hijacking for installation on targeted systems.
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17
UAC-0084 aka TA416 (PlugX)
The PlugX malware stood out to us as this variant infects any attached removable USB media devices such as floppy, thumb or flash drives and any additional systems the USB is later plugged into.
It makes use of Motnug and ChaCha20-based loaders, the CROSSWALK and SideWalk backdoors, along with Korplug (aka PlugX) and Cobalt Strike.
The attacks employed PlugX malware, a Remote Access Trojan (RAT) widely used in targeted attacks.
The PlugX malware stood out to us as this variant infects any attached removable USB media devices such as floppy, thumb or flash drives and any additional systems the USB is later plugged into.
PlugX ◆First seen: 2008 ◆A modular malware with multiple capabilities ◆Used by several Chinese APT groups ◆TeleBoyi, APT41, Mustang Panda, APT27, menuPass, and more
This blog covers a PlugX variant that we have named Talisman... The shellcode is used to decrypt the PlugX malware which then serves as a backdoor with plug-in capabilities.
The discovery of two malware families – HenBox for Android and, recently, Farseer for Windows – with significant, mostly infrastructure-based overlaps with previously seen malware, such as 9002, PlugX, Poison Ivy and FHAPPI...
Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
Korplug (aka PlugX) • DLL side loading • Abuse F-Secure’s qrtfix.exe • Encrypted payload on disk
APT27 ... Examples of associated tools: ... PlugX RAT ... ; GALLIUM ... Examples of associated tools: PlugX ... ; Mustang Panda ... Examples of associated tools: Cobalt Strike, PlugX...
In many cases we have seen that these systems also were targeted previously with PlugX and other malware.
ASEC (AhnLab Security Emergency response Center) has recently discovered the installation of the PlugX malware through the Chinese remote control programs Sunlogin and Awesun’s remote code execution vulnerability.
PlugX is a malware family existing since at least 2008, used in multiple targeted attacks usually by Chinese threat actors... It is believed that Shadowpad is the successor of PlugX.
TinyX. A version of PlugX sans the plug-in functionality that allows it to adopt new capabilities. TinyX is bundled separately in spear-phishing emails.
PlugX (aka Korplug , Sogu ) Modular RAT widely used by China-nexus clusters; supports command execution, screen capture, keylogging, file operations, and process/service management.
The initial and primary backdoor the threat actor used in this attack was the PlugX backdoor. PlugX is a well-known remote access tool (RAT) with modular plugins and customizable settings that has been popular for over a decade, primarily among Chinese-speaking threat groups.
Using our telemetry data, we found that the threat actor also dropped PlugX and ShadowPad samples in victim environments.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.
UNC3569 uses this malware payload installer tool to deploy the SOGU backdoor, demonstrating a willingness to leverage external resources to enhance its operational capabilities.
These revolved around a few known toolsets commonly associated with Chinese threat actors, notably the PlugX malware... PlugX is a well-known Chinese trojan used by a whole host of threat actors.
Like other researchers, we thought this might be a PlugX-like campaign, given that the attack chain shares several characteristics with observed PlugX attacks.
Like other researchers, we thought this might be a PlugX-like campaign, given that the attack chain shares several characteristics with observed PlugX attacks.
Later that August, Symantec highlighted the activity of a new threat cluster codenamed Carderbee, which was found using a trojanized version of the program to deploy PlugX, a backdoor widely used by Chinese hacking groups like Mustang Panda.
“Malware such as PlugX and ShadowPad... became central to campaigns attributed to APT3, APT41, GALLIUM, and Winnti.” | In 2008, a new remote access Trojan named PlugX… was detected in the wild for the first time. PlugX is to this day widely used by Chinese threat actors for data theft and remote control. | PlugX was developed in 2008... According to MITRE ATT&CK, PlugX has been used by more than ten China-linked APT groups, including APT3, APT31, GALLIUM, the Winnti Group, as well as Zhou Shuai’s APT27. PlugX’s ongoing relevance was highlighted in January 2025, when the FBI removed PlugX from over 4,000 U.S. systems.
"...a DLL (CANONSTAGER), and the SOGU.SEC backdoor in RC-4 encrypted form. CANONSTAGER decrypts and loads the final payload... SOGU.SEC, which Google says is a variant of the PlugX malware..." | "SOGU.SEC, which Google says is a variant of the PlugX malware, used extensively by multiple Chinese threat groups..."
In 2008, a new remote access Trojan named PlugX… was detected in the wild for the first time. PlugX is to this day widely used by Chinese threat actors for data theft and remote control. | PlugX was developed in 2008... According to MITRE ATT&CK, PlugX has been used by more than ten China-linked APT groups, including APT3, APT31, GALLIUM, the Winnti Group, as well as Zhou Shuai’s APT27. PlugX’s ongoing relevance was highlighted in January 2025, when the FBI removed PlugX from over 4,000 U.S. systems.
Telecommunications and manufacturing sectors in Central and South Asian countries have emerged as the target of an ongoing campaign distributing a new variant of a known malware called PlugX (aka Korplug or SOGU).
They said LuoYu have newly used the following malware since JSAC2021: Malware: XDealer, ShadowPad, PlugX
Telecommunications and manufacturing sectors in Central and South Asian countries have emerged as the target of an ongoing campaign distributing a new variant of a known malware called PlugX (aka Korplug or SOGU).
Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike
Appendix A lists "PlugX" under Malware.
"Usually, the delivered payload is either the well-known ‘PlugX’ or ‘HttpBrowser’ RAT"
Avira blogged about HoneyMyte PlugX variants... PlugX has been used by multiple APT groups over the past decade...
“this intrusion set also utilizes commonly used remote control tools like Cobalt Strike, PlugX, or Meterpreter stagers interchangeably in various attack stages.”
"...uses well-crafted phishing to deliver PlugX payloads." / "...side-loaded DLL acted as a PlugX loader, which then brought in multiple plugins..."
“PlugX Diplomacy: A Mustang Panda Campaign”
"PlugX is a long-running Remote Access Trojan (RAT)..." ... "Avk.dll – identified by VirusTotal as Korplug (a PlugX variant)."
Exploited software
MITRE ATT&CK
Reporting
A previously unreported cyberespionage campaign dubbed SilkParasite has targeted government bodies across Central Asia, with researchers assessing the activity with medium confidence as having a China nexus. The operation, first identified in late 2025, used spear-phishing emails carrying password-protected RAR archives and malicious Microsoft Office documents that triggered DLL sideloading to deploy malware. Lures were tailored to government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and one Georgian government organization. Bitdefender linked the campaign to a small, modular, professionally engineered toolset spanning .NET, C++, Go, and JavaScript, including seven remote access trojan families and five newly documented strains: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Attribution was further supported by the use of BLOODALCHEMY and an updated SpiceRAT variant associated with Chinese-speaking threat activity. Researchers said the malware ecosystem showed signs of AI-assisted development, including phishing content and coding artifacts, while one implant used Google Drive for command-and-control; the most consistent detection opportunity was DLL sideloading by legitimately signed applications launched from unusual locations.
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
HoneyMyte, also tracked as Mustang Panda, has deployed a new 2025–2026 variant of its CoolClient backdoor that adds a signed Windows kernel-mode driver, msagent.sys, to deepen stealth and persistence during espionage intrusions. Researchers said the malware retains its multi-stage DLL sideloading design but now uses rootkit functions to hide and protect malicious processes, files, and registry objects, while also filtering network information linked to command-and-control infrastructure through an Nsiproxy hook. In one intrusion targeting Myanmar, the group reportedly used PlugX as an initial implant before installing CoolClient from a fake Windows Defender directory via a renamed legitimate Sangfor executable. The malware persists through AutoRun entries, scheduled tasks, and Windows services, injects into synchost.exe, and can relaunch itself with elevated privileges using an RPC-based UAC bypass with PPID spoofing. Victims were identified in Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities, indicating HoneyMyte is expanding kernel-level defense evasion in post-compromise operations.
Armored Likho, also tracked as Eagle Werewolf, launched a cyber-espionage campaign against private users and organizations in Russia, including targets in government, corporate, IT, and education sectors. The operation used fake charity-assistance applications built as Rust/Tauri droppers to install a new modular espionage framework called Still Toolkit. Its Still Sync component steals Telegram Desktop session data, authenticates to victims’ Telegram accounts, and exfiltrates chats, media, and account details through the Telegram API, while Still Audio covertly activates microphone surveillance by detecting speech and uploading recordings to command-and-control servers.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.