Skip to content

PlugX

PlugX is a long-running Windows remote access trojan widely associated with Chinese espionage activity and frequently used in targeted intrusions against government, diplomatic, academic, and private-sector organizations across Asia and beyond.

Profile source: Mallory opens in a new tab

PlugX

Family profile

PlugX is a long-running Windows remote access trojan widely associated with Chinese espionage activity and frequently used in targeted intrusions against government, diplomatic, academic, and private-sector organizations across Asia and beyond. It is also known by aliases including Korplug, Sogu, Thoper, and Destory RAT. PlugX has been active since at least the late 2000s and has evolved through multiple variants with differing loaders, configuration formats, encryption schemes, and anti-analysis features. ShadowPad has been described as an evolution of PlugX, and both malware families are broadly used by Chinese threat clusters.

PlugX is a modular post-compromise implant and backdoor that provides operators with persistent remote control over infected Windows systems. Documented capabilities include process enumeration, system reconnaissance, command execution, screenshot capture, keylogging, registry modification, and execution of additional processes, including on hidden desktops. Some variants support remote shell functionality, port scanning, SQL command execution, and process injection into legitimate Windows processes. PlugX commonly uses encrypted and compressed payloads and configuration data, and some variants decrypt and decompress components in memory before injecting them into other processes.

A hallmark of PlugX tradecraft is abuse of DLL side-loading or DLL load-order hijacking through legitimate signed executables to evade detection and blend malicious execution with trusted software. It has also been observed establishing persistence through Windows Registry Run key entries. Technical analyses have identified multiple major PlugX types and extensive variation in configuration structures, protocols, and obfuscation methods, reflecting sustained development over many years.

PlugX has appeared in numerous espionage campaigns and has been linked to or used by multiple China-aligned threat actors, including Mustang Panda and menuPass, among others. In some modern intrusion chains, PlugX serves as an initial post-compromise implant used to deploy secondary backdoors such as CoolClient. Its longevity, modularity, and adaptability have made it one of the most recognizable and enduring espionage RAT families in the China-nexus ecosystem.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 19, 2026
Last activity
Aug 19, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • JP1

Leading providers

  • xTom Japan Corporation1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

50 named in public reporting
Mustang Panda

По данным специалистов, в новых атаках HoneyMyte сначала устанавливала на машины жертв PlugX, а уже через него разворачивала CoolClient.

menuPass

In addition to using PlugX and Poison Ivy (PIVY), both known to be used by the group...

DragonOK

Additionally, the actors have now added the popular PlugX backdoor to their toolkit.

Velvet Ant

Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. PlugX has the ability to use DLL search order hijacking for installation on targeted systems.

APT41

RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012

APT1

RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012

Ke3chang

RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012

Daggerfly

Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. PlugX has the ability to use DLL search order hijacking for installation on targeted systems.

Hangover

RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012

Icefog

RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012

APT17

Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17

PKPLUG Group

The PlugX malware stood out to us as this variant infects any attached removable USB media devices such as floppy, thumb or flash drives and any additional systems the USB is later plugged into.

SparklingGoblin

It makes use of Motnug and ChaCha20-based loaders, the CROSSWALK and SideWalk backdoors, along with Korplug (aka PlugX) and Cobalt Strike.

TA459

The attacks employed PlugX malware, a Remote Access Trojan (RAT) widely used in targeted attacks.

Black Basta

The PlugX malware stood out to us as this variant infects any attached removable USB media devices such as floppy, thumb or flash drives and any additional systems the USB is later plugged into.

Threat Group-3390

PlugX ◆First seen: 2008 ◆A modular malware with multiple capabilities ◆Used by several Chinese APT groups ◆TeleBoyi, APT41, Mustang Panda, APT27, menuPass, and more

RedFoxtrot

This blog covers a PlugX variant that we have named Talisman... The shellcode is used to decrypt the PlugX malware which then serves as a backdoor with plug-in capabilities.

PKPLUG

The discovery of two malware families – HenBox for Android and, recently, Farseer for Windows – with significant, mostly infrastructure-based overlaps with previously seen malware, such as 9002, PlugX, Poison Ivy and FHAPPI...

Blue Termite

Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.

TA410

Korplug (aka PlugX) • DLL side loading • Abuse F-Secure’s qrtfix.exe • Encrypted payload on disk

GALLIUM

APT27 ... Examples of associated tools: ... PlugX RAT ... ; GALLIUM ... Examples of associated tools: PlugX ... ; Mustang Panda ... Examples of associated tools: Cobalt Strike, PlugX...

Naikon

In many cases we have seen that these systems also were targeted previously with PlugX and other malware.

APT3

ASEC (AhnLab Security Emergency response Center) has recently discovered the installation of the PlugX malware through the Chinese remote control programs Sunlogin and Awesun’s remote code execution vulnerability.

Teleboyi

PlugX is a malware family existing since at least 2008, used in multiple targeted attacks usually by Chinese threat actors... It is believed that Shadowpad is the successor of PlugX.

APT 10

TinyX. A version of PlugX sans the plug-in functionality that allows it to adopt new capabilities. TinyX is bundled separately in spear-phishing emails.

Budworm

PlugX (aka Korplug , Sogu ) Modular RAT widely used by China-nexus clusters; supports command execution, screen capture, keylogging, file operations, and process/service management.

DragonRank

The initial and primary backdoor the threat actor used in this attack was the PlugX backdoor. PlugX is a well-known remote access tool (RAT) with modular plugins and customizable settings that has been popular for over a decade, primarily among Chinese-speaking threat groups.

Earth Krahang

Using our telemetry data, we found that the threat actor also dropped PlugX and ShadowPad samples in victim environments.

Axiom

The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.

Space Pirates

Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.

UNC3569

UNC3569 uses this malware payload installer tool to deploy the SOGU backdoor, demonstrating a willingness to leverage external resources to enhance its operational capabilities.

TA428

These revolved around a few known toolsets commonly associated with Chinese threat actors, notably the PlugX malware... PlugX is a well-known Chinese trojan used by a whole host of threat actors.

RedCurl

Like other researchers, we thought this might be a PlugX-like campaign, given that the attack chain shares several characteristics with observed PlugX attacks.

DragonBreath

Like other researchers, we thought this might be a PlugX-like campaign, given that the attack chain shares several characteristics with observed PlugX attacks.

Carderbee

Later that August, Symantec highlighted the activity of a new threat cluster codenamed Carderbee, which was found using a trojanized version of the program to deploy PlugX, a backdoor widely used by Chinese hacking groups like Mustang Panda.

Earth Lusca

“Malware such as PlugX and ShadowPad... became central to campaigns attributed to APT3, APT41, GALLIUM, and Winnti.” | In 2008, a new remote access Trojan named PlugX… was detected in the wild for the first time. PlugX is to this day widely used by Chinese threat actors for data theft and remote control. | PlugX was developed in 2008... According to MITRE ATT&CK, PlugX has been used by more than ten China-linked APT groups, including APT3, APT31, GALLIUM, the Winnti Group, as well as Zhou Shuai’s APT27. PlugX’s ongoing relevance was highlighted in January 2025, when the FBI removed PlugX from over 4,000 U.S. systems.

HAFNIUM

"...a DLL (CANONSTAGER), and the SOGU.SEC backdoor in RC-4 encrypted form. CANONSTAGER decrypts and loads the final payload... SOGU.SEC, which Google says is a variant of the PlugX malware..." | "SOGU.SEC, which Google says is a variant of the PlugX malware, used extensively by multiple Chinese threat groups..."

ZIRCONIUM

In 2008, a new remote access Trojan named PlugX… was detected in the wild for the first time. PlugX is to this day widely used by Chinese threat actors for data theft and remote control. | PlugX was developed in 2008... According to MITRE ATT&CK, PlugX has been used by more than ten China-linked APT groups, including APT3, APT31, GALLIUM, the Winnti Group, as well as Zhou Shuai’s APT27. PlugX’s ongoing relevance was highlighted in January 2025, when the FBI removed PlugX from over 4,000 U.S. systems.

Lotus Blossom

Telecommunications and manufacturing sectors in Central and South Asian countries have emerged as the target of an ongoing campaign distributing a new variant of a known malware called PlugX (aka Korplug or SOGU).

LuoYu

They said LuoYu have newly used the following malware since JSAC2021: Malware: XDealer, ShadowPad, PlugX

Cycldek

Telecommunications and manufacturing sectors in Central and South Asian countries have emerged as the target of an ongoing campaign distributing a new variant of a known malware called PlugX (aka Korplug or SOGU).

CTG-5938

Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike

APT6

"Usually, the delivered payload is either the well-known ‘PlugX’ or ‘HttpBrowser’ RAT"

CloudComputating

Avira blogged about HoneyMyte PlugX variants... PlugX has been used by multiple APT groups over the past decade...

Salt Typhoon

“this intrusion set also utilizes commonly used remote control tools like Cobalt Strike, PlugX, or Meterpreter stagers interchangeably in various attack stages.”

Flax Typhoon

"...uses well-crafted phishing to deliver PlugX payloads." / "...side-loaded DLL acted as a PlugX loader, which then brought in multiple plugins..."

Agrius

“PlugX Diplomacy: A Mustang Panda Campaign”

APT19

"PlugX is a long-running Remote Access Trojan (RAT)..." ... "Avk.dll – identified by VirusTotal as Korplug (a PlugX variant)."

Exploited software

Vulnerabilities linked to PlugX

28 CVEs
CVE-2013-3906 Remote Code Execution in Microsoft GDI+ TIFF Parsing CVE-2012-0158 MSCOMCTL.OCX ActiveX Controls Remote Code Execution CVE-2021-26855 ProxyLogon pre-auth SSRF in Microsoft Exchange Server CVE-2014-0810 Remote Code Execution in JustSystems Sanshiro (Multiple Versions) CVE-2013-3918 InformationCardSigninHelper ActiveX Out-of-Bounds Write RCE CVE-2011-2462 Adobe Reader and Acrobat U3D Memory Corruption RCE CVE-2013-5990 Remote Code Execution in JustSystems Ichitaro via Crafted Document CVE-2014-7247 Arbitrary Code Execution in JustSystems Ichitaro (CVE-2014-7247) CVE-2019-0604 Microsoft SharePoint Remote Code Execution Vulnerability CVE-2021-34473 ProxyShell pre-auth path confusion in Microsoft Exchange Server CVE-2021-27065 ProxyLogon post-auth arbitrary file write in Microsoft Exchange Server CVE-2017-0144 EternalBlue SMBv1 Remote Code Execution CVE-2021-45105 Apache Log4j2 uncontrolled recursion denial of service CVE-2017-0213 Windows COM Aggregate Marshaler Elevation of Privilege CVE-2021-44228 Log4Shell CVE-2023-36884 Windows HTML and Office Remote Code Execution Vulnerability CVE-2024-24919 Arbitrary File Read in Check Point Quantum Security Gateways CVE-2017-0199 Microsoft Office and WordPad Remote Code Execution Vulnerability CVE-2025-9491 Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability CVE-2021-26857 Microsoft Exchange Server Insecure Deserialization RCE CVE-2021-26858 Microsoft Exchange Server Post-Authentication Arbitrary File Write CVE-2025-55182 React2Shell CVE-2024-23692 Unauthenticated RCE in Rejetto HTTP File Server via Template Injection CVE-2020-0688 Microsoft Exchange ECP ViewState Deserialization RCE CVE-2014-3393 Authentication Bypass in Cisco ASA Clientless SSL VPN Portal Customization Framework CVE-2023-21716 Microsoft Word RTF Heap Corruption Remote Code Execution CVE-2021-40444 MSHTML Remote Code Execution in Microsoft Windows CVE-2021-1675 Windows Print Spooler Remote Code Execution Vulnerability

MITRE ATT&CK

PlugX in ATT&CK

121 distinct techniques

Techniques

121 techniques
T1090.003 Multi-hop Proxy T1053.005 Scheduled Task T1036 Masquerading T1071 Application Layer Protocol T1106 Native API T1059.003 Windows Command Shell T1027 Obfuscated Files or Information T1204.002 Malicious File T1566 Phishing T1566.003 Spearphishing via Service T1112 Modify Registry T1113 Screen Capture T1057 Process Discovery T1105 Ingress Tool Transfer T1083 File and Directory Discovery T1564.001 Hidden Files and Directories T1135 Network Share Discovery T1055 Process Injection T1219 Remote Access Tools T1543.003 Windows Service T1574.001 DLL T1046 Network Service Discovery T1547.001 Registry Run Keys / Startup Folder T1056.001 Keylogging T1059 Command and Scripting Interpreter T1140 Deobfuscate/Decode Files or Information T1564.003 Hidden Window T1040 Network Sniffing T1071.001 Web Protocols T1560 Archive Collected Data T1548.002 Bypass User Account Control T1587.001 Malware T1573 Encrypted Channel T1566.002 Spearphishing Link T1588.002 Tool T1560.001 Archive via Utility T1005 Data from Local System T1566.001 Spearphishing Attachment T1036.005 Match Legitimate Resource Name or Location T1029 Scheduled Transfer T1078 Valid Accounts T1567.002 Exfiltration to Cloud Storage T1012 Query Registry T1480.001 Environmental Keying T1091 Replication Through Removable Media T1041 Exfiltration Over C2 Channel T1074 Data Staged T1095 Non-Application Layer Protocol T1222 File and Directory Permissions Modification T1218 System Binary Proxy Execution T1547.009 Shortcut Modification T1620 Reflective Code Loading T1082 System Information Discovery T1056 Input Capture T1497 Virtualization/Sandbox Evasion T1204 User Execution T1070.004 File Deletion T1190 Exploit Public-Facing Application T1197 BITS Jobs T1218.011 Rundll32 T1059.005 Visual Basic T1543 Create or Modify System Process T1049 System Network Connections Discovery T1203 Exploitation for Client Execution T1189 Drive-by Compromise T1071.004 DNS T1195 Supply Chain Compromise T1027.007 Dynamic API Resolution T1548 Abuse Elevation Control Mechanism T1102 Web Service T1486 Data Encrypted for Impact T1001.002 Steganography T1574 Hijack Execution Flow T1129 Shared Modules T1568 Dynamic Resolution T1614 System Location Discovery T1505.003 Web Shell T1090 Proxy T1021.001 Remote Desktop Protocol T1033 System Owner/User Discovery T1016 System Network Configuration Discovery T1021.002 SMB/Windows Admin Shares T1583.001 Domains T1007 System Service Discovery T1583.004 Server T1569 System Services T1039 Data from Network Shared Drive T1571 Non-Standard Port T1059.001 PowerShell T1027.005 Indicator Removal from Tools T1134 Access Token Manipulation T1055.001 Dynamic-link Library Injection T1036.004 Masquerade Task or Service T1070.006 Timestomp T1570 Lateral Tool Transfer T1070 Indicator Removal T1025 Data from Removable Media T1132.001 Standard Encoding T1573.001 Symmetric Cryptography T1087 Account Discovery T1588.001 Malware T1608.001 Upload Malware T1052 Exfiltration Over Physical Medium T1115 Clipboard Data T1016.001 Internet Connection Discovery T1583.003 Virtual Private Server T1562.004 Disable or Modify System Firewall T1124 System Time Discovery T1480.002 Mutual Exclusion T1588.006 Vulnerabilities T1008 Fallback Channels T1053 Scheduled Task/Job T1074.001 Local Data Staging T1649 Steal or Forge Authentication Certificates T1210 Exploitation of Remote Services T1489 Service Stop T1090.001 Internal Proxy T1622 Debugger Evasion T1021 Remote Services T1204.001 Malicious Link T1562.001 Disable or Modify Tools

Reporting

Research mentioning PlugX

Aug 19
Dark Reading

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A previously unreported cyberespionage campaign dubbed SilkParasite has targeted government bodies across Central Asia, with researchers assessing the activity with medium confidence as having a China nexus. The operation, first identified in late 2025, used spear-phishing emails carrying password-protected RAR archives and malicious Microsoft Office documents that triggered DLL sideloading to deploy malware. Lures were tailored to government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and one Georgian government organization. Bitdefender linked the campaign to a small, modular, professionally engineered toolset spanning .NET, C++, Go, and JavaScript, including seven remote access trojan families and five newly documented strains: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. Attribution was further supported by the use of BLOODALCHEMY and an updated SpiceRAT variant associated with Chinese-speaking threat activity. Researchers said the malware ecosystem showed signs of AI-assisted development, including phishing content and coding artifacts, while one implant used Google Drive for command-and-control; the most consistent detection opportunity was DLL sideloading by legitimately signed applications launched from unusual locations.

Aug 19
Malware News

SilkParasite: Tracking a China-Nexus APT Across Central Asia - Malware News - Malware Analysis, News and Indicators

Aug 19
The Hacker News

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 14
Malware News

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit - Malware News - Malware Analysis, News and Indicators

HoneyMyte, also tracked as Mustang Panda, has deployed a new 2025–2026 variant of its CoolClient backdoor that adds a signed Windows kernel-mode driver, msagent.sys, to deepen stealth and persistence during espionage intrusions. Researchers said the malware retains its multi-stage DLL sideloading design but now uses rootkit functions to hide and protect malicious processes, files, and registry objects, while also filtering network information linked to command-and-control infrastructure through an Nsiproxy hook. In one intrusion targeting Myanmar, the group reportedly used PlugX as an initial implant before installing CoolClient from a fake Windows Defender directory via a renamed legitimate Sangfor executable. The malware persists through AutoRun entries, scheduled tasks, and Windows services, injects into synchost.exe, and can relaunch itself with elevated privileges using an RPC-based UAC bypass with PPID spoofing. Victims were identified in Myanmar, Mongolia, Pakistan, and Russia, including confirmed government entities, indicating HoneyMyte is expanding kernel-level defense evasion in post-compromise operations.

Aug 14
Securelist

CoolClient backdoor goes deeper: HoneyMyte adds Windows kernel rootkit | Securelist

Aug 14
Securelist Ru

CoolClient от HoneyMyte внедряется в ядро ​​Windows | Securelist

Aug 13
Malware News

Armored Likho expands its cyber-espionage toolkit - Malware News - Malware Analysis, News and Indicators

Armored Likho, also tracked as Eagle Werewolf, launched a cyber-espionage campaign against private users and organizations in Russia, including targets in government, corporate, IT, and education sectors. The operation used fake charity-assistance applications built as Rust/Tauri droppers to install a new modular espionage framework called Still Toolkit. Its Still Sync component steals Telegram Desktop session data, authenticates to victims’ Telegram accounts, and exfiltrates chats, media, and account details through the Telegram API, while Still Audio covertly activates microphone surveillance by detecting speech and uploading recordings to command-and-control servers.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.