Skip to content

PlugX

PlugX, also known as KorPlug and Sogu, is a Windows remote-access trojan and backdoor associated with multiple China-linked espionage operations, notably activity attributed to Mustang Panda.

Profile source: Mallory opens in a new tab

PlugX

Family profile

PlugX, also known as KorPlug and Sogu, is a Windows remote-access trojan and backdoor associated with multiple China-linked espionage operations, notably activity attributed to Mustang Panda. It provides remote command-and-control functionality and uses command-dispatching logic to support operator tasking. Observed variants and deployments use API hashing to obscure Windows API resolution, in-memory execution, and DLL sideloading to hinder static analysis and evade endpoint defenses. PlugX has appeared in intrusions targeting government, telecommunications, postal, media, and other strategically relevant organizations. U.S. authorities conducted a 2025 operation that removed PlugX from thousands of U.S. systems compromised in Mustang Panda activity.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Post Exploitation

Reported operators

Threat actors

50 named in public reporting
CL-STA-0048

LOLBin (‘certutil’) was used to deploy a PlugX backdoor allowing in-memory execution to evade detection.

Mustang Panda

« 2025 : Suppression du malware PlugX de plus de 4 000 ordinateurs américains infectés par Mustang Panda »

menuPass

In addition to using PlugX and Poison Ivy (PIVY), both known to be used by the group...

DragonOK

Additionally, the actors have now added the popular PlugX backdoor to their toolkit.

Velvet Ant

Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. PlugX has the ability to use DLL search order hijacking for installation on targeted systems.

APT41

RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012

APT1

RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012

Ke3chang

RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012

Daggerfly

Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. PlugX has the ability to use DLL search order hijacking for installation on targeted systems.

Hangover

RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012

Icefog

RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012

APT17

Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17

PKPLUG

The PlugX malware stood out to us as this variant infects any attached removable USB media devices such as floppy, thumb or flash drives and any additional systems the USB is later plugged into.

SparklingGoblin

It makes use of Motnug and ChaCha20-based loaders, the CROSSWALK and SideWalk backdoors, along with Korplug (aka PlugX) and Cobalt Strike.

TA459

The attacks employed PlugX malware, a Remote Access Trojan (RAT) widely used in targeted attacks.

Black Basta

The PlugX malware stood out to us as this variant infects any attached removable USB media devices such as floppy, thumb or flash drives and any additional systems the USB is later plugged into.

Threat Group-3390

PlugX ◆First seen: 2008 ◆A modular malware with multiple capabilities ◆Used by several Chinese APT groups ◆TeleBoyi, APT41, Mustang Panda, APT27, menuPass, and more

RedFoxtrot

This blog covers a PlugX variant that we have named Talisman... The shellcode is used to decrypt the PlugX malware which then serves as a backdoor with plug-in capabilities.

Blue Termite

Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.

TA410

Korplug (aka PlugX) • DLL side loading • Abuse F-Secure’s qrtfix.exe • Encrypted payload on disk

GALLIUM

APT27 ... Examples of associated tools: ... PlugX RAT ... ; GALLIUM ... Examples of associated tools: PlugX ... ; Mustang Panda ... Examples of associated tools: Cobalt Strike, PlugX...

Naikon

In many cases we have seen that these systems also were targeted previously with PlugX and other malware.

APT3

ASEC (AhnLab Security Emergency response Center) has recently discovered the installation of the PlugX malware through the Chinese remote control programs Sunlogin and Awesun’s remote code execution vulnerability.

Teleboyi

PlugX is a malware family existing since at least 2008, used in multiple targeted attacks usually by Chinese threat actors... It is believed that Shadowpad is the successor of PlugX.

APT 10

TinyX. A version of PlugX sans the plug-in functionality that allows it to adopt new capabilities. TinyX is bundled separately in spear-phishing emails.

Budworm

PlugX (aka Korplug , Sogu ) Modular RAT widely used by China-nexus clusters; supports command execution, screen capture, keylogging, file operations, and process/service management.

DragonRank

The initial and primary backdoor the threat actor used in this attack was the PlugX backdoor. PlugX is a well-known remote access tool (RAT) with modular plugins and customizable settings that has been popular for over a decade, primarily among Chinese-speaking threat groups.

Earth Krahang

Using our telemetry data, we found that the threat actor also dropped PlugX and ShadowPad samples in victim environments.

Axiom

The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.

Space Pirates

Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.

UNC3569

UNC3569 uses this malware payload installer tool to deploy the SOGU backdoor, demonstrating a willingness to leverage external resources to enhance its operational capabilities.

TA428

These revolved around a few known toolsets commonly associated with Chinese threat actors, notably the PlugX malware... PlugX is a well-known Chinese trojan used by a whole host of threat actors.

RedCurl

Like other researchers, we thought this might be a PlugX-like campaign, given that the attack chain shares several characteristics with observed PlugX attacks.

Dragon Breath

Like other researchers, we thought this might be a PlugX-like campaign, given that the attack chain shares several characteristics with observed PlugX attacks.

Carderbee

Later that August, Symantec highlighted the activity of a new threat cluster codenamed Carderbee, which was found using a trojanized version of the program to deploy PlugX, a backdoor widely used by Chinese hacking groups like Mustang Panda.

Earth Lusca

“Malware such as PlugX and ShadowPad... became central to campaigns attributed to APT3, APT41, GALLIUM, and Winnti.” | In 2008, a new remote access Trojan named PlugX… was detected in the wild for the first time. PlugX is to this day widely used by Chinese threat actors for data theft and remote control. | PlugX was developed in 2008... According to MITRE ATT&CK, PlugX has been used by more than ten China-linked APT groups, including APT3, APT31, GALLIUM, the Winnti Group, as well as Zhou Shuai’s APT27. PlugX’s ongoing relevance was highlighted in January 2025, when the FBI removed PlugX from over 4,000 U.S. systems.

HAFNIUM

"...a DLL (CANONSTAGER), and the SOGU.SEC backdoor in RC-4 encrypted form. CANONSTAGER decrypts and loads the final payload... SOGU.SEC, which Google says is a variant of the PlugX malware..." | "SOGU.SEC, which Google says is a variant of the PlugX malware, used extensively by multiple Chinese threat groups..."

ZIRCONIUM

In 2008, a new remote access Trojan named PlugX… was detected in the wild for the first time. PlugX is to this day widely used by Chinese threat actors for data theft and remote control. | PlugX was developed in 2008... According to MITRE ATT&CK, PlugX has been used by more than ten China-linked APT groups, including APT3, APT31, GALLIUM, the Winnti Group, as well as Zhou Shuai’s APT27. PlugX’s ongoing relevance was highlighted in January 2025, when the FBI removed PlugX from over 4,000 U.S. systems.

Lotus Blossom

Telecommunications and manufacturing sectors in Central and South Asian countries have emerged as the target of an ongoing campaign distributing a new variant of a known malware called PlugX (aka Korplug or SOGU).

LuoYu

They said LuoYu have newly used the following malware since JSAC2021: Malware: XDealer, ShadowPad, PlugX

Cycldek

Telecommunications and manufacturing sectors in Central and South Asian countries have emerged as the target of an ongoing campaign distributing a new variant of a known malware called PlugX (aka Korplug or SOGU).

CTG-5938

Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike

APT6

"Usually, the delivered payload is either the well-known ‘PlugX’ or ‘HttpBrowser’ RAT"

CloudComputating

Avira blogged about HoneyMyte PlugX variants... PlugX has been used by multiple APT groups over the past decade...

Salt Typhoon

“this intrusion set also utilizes commonly used remote control tools like Cobalt Strike, PlugX, or Meterpreter stagers interchangeably in various attack stages.”

Flax Typhoon

"...uses well-crafted phishing to deliver PlugX payloads." / "...side-loaded DLL acted as a PlugX loader, which then brought in multiple plugins..."

Agrius

“PlugX Diplomacy: A Mustang Panda Campaign”

APT19

"PlugX is a long-running Remote Access Trojan (RAT)..." ... "Avk.dll – identified by VirusTotal as Korplug (a PlugX variant)."

Exploited software

Vulnerabilities linked to PlugX

28 CVEs
CVE-2013-3906 Remote Code Execution in Microsoft GDI+ TIFF Parsing CVE-2012-0158 Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability CVE-2021-26855 ProxyLogon SSRF in Microsoft Exchange Server CVE-2014-0810 Remote Code Execution in JustSystems Sanshiro (Multiple Versions) CVE-2013-3918 InformationCardSigninHelper ActiveX Out-of-Bounds Write RCE CVE-2011-2462 Adobe Reader and Acrobat U3D Memory Corruption RCE CVE-2013-5990 Remote Code Execution in JustSystems Ichitaro via Crafted Document CVE-2014-7247 Arbitrary Code Execution in JustSystems Ichitaro (CVE-2014-7247) CVE-2019-0604 Microsoft SharePoint Application Package Remote Code Execution CVE-2021-34473 ProxyShell Pre-authentication ACL Bypass in Microsoft Exchange Server CVE-2021-27065 Microsoft Exchange Server ECP Arbitrary File Write CVE-2017-0144 EternalBlue Windows SMBv1 Remote Code Execution CVE-2021-45105 Apache Log4j2 Uncontrolled Recursion Denial of Service CVE-2017-0213 Windows COM Aggregate Marshaler Elevation of Privilege CVE-2021-44228 Log4Shell: Remote Code Execution in Apache Log4j2 CVE-2023-36884 Office and Windows HTML Remote Code Execution Vulnerability CVE-2024-24919 Arbitrary File Read in Check Point Security Gateways CVE-2017-0199 Microsoft Office and WordPad Remote Code Execution Vulnerability CVE-2025-9491 Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability CVE-2021-26857 Microsoft Exchange Unified Messaging Insecure Deserialization RCE CVE-2021-26858 Post-authentication Arbitrary File Write in Microsoft Exchange Server CVE-2025-55182 React2Shell: Pre-authentication RCE in React Server Components CVE-2024-23692 Rejetto HTTP File Server Template Injection RCE CVE-2020-0688 Microsoft Exchange Server ECP ViewState Deserialization RCE CVE-2014-3393 Authentication Bypass in Cisco ASA Clientless SSL VPN Portal Customization Framework CVE-2023-21716 Microsoft Word RTF Heap Corruption Remote Code Execution CVE-2021-40444 MSHTML Remote Code Execution Vulnerability CVE-2021-1675 Windows Print Spooler Remote Code Execution Vulnerability

MITRE ATT&CK

PlugX in ATT&CK

121 distinct techniques

Techniques

121 techniques
T1588.001 Malware T1140 Deobfuscate/Decode Files or Information T1027 Obfuscated Files or Information T1027.007 Dynamic API Resolution T1574.001 DLL T1090.003 Multi-hop Proxy T1053.005 Scheduled Task T1036 Masquerading T1071 Application Layer Protocol T1106 Native API T1059.003 Windows Command Shell T1204.002 Malicious File T1566 Phishing T1566.003 Spearphishing via Service T1112 Modify Registry T1113 Screen Capture T1057 Process Discovery T1105 Ingress Tool Transfer T1083 File and Directory Discovery T1564.001 Hidden Files and Directories T1135 Network Share Discovery T1055 Process Injection T1219 Remote Access Tools T1543.003 Windows Service T1046 Network Service Discovery T1547.001 Registry Run Keys / Startup Folder T1056.001 Keylogging T1059 Command and Scripting Interpreter T1564.003 Hidden Window T1040 Network Sniffing T1071.001 Web Protocols T1560 Archive Collected Data T1548.002 Bypass User Account Control T1587.001 Malware T1573 Encrypted Channel T1566.002 Spearphishing Link T1588.002 Tool T1560.001 Archive via Utility T1005 Data from Local System T1566.001 Spearphishing Attachment T1036.005 Match Legitimate Resource Name or Location T1029 Scheduled Transfer T1078 Valid Accounts T1567.002 Exfiltration to Cloud Storage T1012 Query Registry T1480.001 Environmental Keying T1091 Replication Through Removable Media T1041 Exfiltration Over C2 Channel T1074 Data Staged T1095 Non-Application Layer Protocol T1222 File and Directory Permissions Modification T1218 System Binary Proxy Execution T1547.009 Shortcut Modification T1620 Reflective Code Loading T1082 System Information Discovery T1056 Input Capture T1497 Virtualization/Sandbox Evasion T1204 User Execution T1070.004 File Deletion T1190 Exploit Public-Facing Application T1197 BITS Jobs T1218.011 Rundll32 T1059.005 Visual Basic T1543 Create or Modify System Process T1049 System Network Connections Discovery T1203 Exploitation for Client Execution T1189 Drive-by Compromise T1071.004 DNS T1195 Supply Chain Compromise T1548 Abuse Elevation Control Mechanism T1102 Web Service T1486 Data Encrypted for Impact T1001.002 Steganography T1574 Hijack Execution Flow T1129 Shared Modules T1568 Dynamic Resolution T1614 System Location Discovery T1505.003 Web Shell T1090 Proxy T1021.001 Remote Desktop Protocol T1033 System Owner/User Discovery T1016 System Network Configuration Discovery T1021.002 SMB/Windows Admin Shares T1583.001 Domains T1007 System Service Discovery T1583.004 Server T1569 System Services T1039 Data from Network Shared Drive T1571 Non-Standard Port T1059.001 PowerShell T1027.005 Indicator Removal from Tools T1134 Access Token Manipulation T1055.001 Dynamic-link Library Injection T1036.004 Masquerade Task or Service T1070.006 Timestomp T1570 Lateral Tool Transfer T1070 Indicator Removal T1025 Data from Removable Media T1132.001 Standard Encoding T1573.001 Symmetric Cryptography T1087 Account Discovery T1608.001 Upload Malware T1052 Exfiltration Over Physical Medium T1115 Clipboard Data T1016.001 Internet Connection Discovery T1583.003 Virtual Private Server T1562.004 Disable or Modify System Firewall T1124 System Time Discovery T1480.002 Mutual Exclusion T1588.006 Vulnerabilities T1008 Fallback Channels T1053 Scheduled Task/Job T1074.001 Local Data Staging T1649 Steal or Forge Authentication Certificates T1210 Exploitation of Remote Services T1489 Service Stop T1090.001 Internal Proxy T1622 Debugger Evasion T1021 Remote Services T1204.001 Malicious Link T1562.001 Disable or Modify Tools

Reporting

Research mentioning PlugX

Aug 26
Cyberscoop

Officials disrupt Chinese espionage operation that hit multiple federal agencies | CyberScoop

The FBI and Department of Justice seized domains supporting the China-linked QTFY espionage group's QScan and QTRouter platforms after the infrastructure was linked to intrusions at NASA, the Federal Reserve, the Departments of Justice and Energy, and the U.S. Senate. Officials said the platforms supported follow-on attacks against sensitive networks and U.S. critical infrastructure, though they did not disclose the extent of access or data compromise at each victim. QTFY's technical infrastructure included the QScan reconnaissance and IoT-compromise tool, QTRouter hardware, QTProxy route management, and the Fast Labyrinth encrypted relay network. The operators combined compromised IoT devices, leased VPS systems, and premium nodes from the Chinese commercial proxy service fastlink.ws to rotate malicious traffic through consumer-proxy infrastructure and conceal its origin. Defenders should prioritize edge-device hardening and apply CISA and NCSC guidance on China-linked threats, as static IP or domain blocking alone is unlikely to stop the dynamically changing relay network.

Aug 26
Wired Com Security

FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure | WIRED

Aug 26
Malware News

US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate - Malware News - Malware Analysis, News and Indicators

Aug 26
Security Affairs

FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure

Aug 26
Data Breaches

US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate - DataBreaches.Net

Aug 26
Techcrunch Com Security

US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate | TechCrunch

Aug 26
Malware News

FBI disables China-linked hacking tools used against US agencies - Malware News - Malware Analysis, News and Indicators

Aug 26
The Hacker News

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.