LOLBin (‘certutil’) was used to deploy a PlugX backdoor allowing in-memory execution to evade detection.
PlugX
PlugX, also known as KorPlug and Sogu, is a Windows remote-access trojan and backdoor associated with multiple China-linked espionage operations, notably activity attributed to Mustang Panda.
Profile source: Mallory opens in a new tabPlugX
Family profile
PlugX, also known as KorPlug and Sogu, is a Windows remote-access trojan and backdoor associated with multiple China-linked espionage operations, notably activity attributed to Mustang Panda. It provides remote command-and-control functionality and uses command-dispatching logic to support operator tasking. Observed variants and deployments use API hashing to obscure Windows API resolution, in-memory execution, and DLL sideloading to hinder static analysis and evade endpoint defenses. PlugX has appeared in intrusions targeting government, telecommunications, postal, media, and other strategically relevant organizations. U.S. authorities conducted a 2025 operation that removed PlugX from thousands of U.S. systems compromised in Mustang Panda activity.
Capabilities
- Defense Evasion
- Dll Sideloading
- Post Exploitation
Reported operators
Threat actors
50 named in public reporting« 2025 : Suppression du malware PlugX de plus de 4 000 ordinateurs américains infectés par Mustang Panda »
In addition to using PlugX and Poison Ivy (PIVY), both known to be used by the group...
Additionally, the actors have now added the popular PlugX backdoor to their toolkit.
Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. PlugX has the ability to use DLL search order hijacking for installation on targeted systems.
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. PlugX has the ability to use DLL search order hijacking for installation on targeted systems.
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
RAT used for targeted attacks – Also known as Korplug/Gulpix/Sogu/Thoper/Destory RAT – Acknowledged in earlier 2012
Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17
UAC-0084 aka TA416 (PlugX)
The PlugX malware stood out to us as this variant infects any attached removable USB media devices such as floppy, thumb or flash drives and any additional systems the USB is later plugged into.
It makes use of Motnug and ChaCha20-based loaders, the CROSSWALK and SideWalk backdoors, along with Korplug (aka PlugX) and Cobalt Strike.
The attacks employed PlugX malware, a Remote Access Trojan (RAT) widely used in targeted attacks.
The PlugX malware stood out to us as this variant infects any attached removable USB media devices such as floppy, thumb or flash drives and any additional systems the USB is later plugged into.
PlugX ◆First seen: 2008 ◆A modular malware with multiple capabilities ◆Used by several Chinese APT groups ◆TeleBoyi, APT41, Mustang Panda, APT27, menuPass, and more
This blog covers a PlugX variant that we have named Talisman... The shellcode is used to decrypt the PlugX malware which then serves as a backdoor with plug-in capabilities.
Attackers leveraged a vulnerability in this program to attach a malicious file to an email, which infected the user with the PlugX malware.
Korplug (aka PlugX) • DLL side loading • Abuse F-Secure’s qrtfix.exe • Encrypted payload on disk
APT27 ... Examples of associated tools: ... PlugX RAT ... ; GALLIUM ... Examples of associated tools: PlugX ... ; Mustang Panda ... Examples of associated tools: Cobalt Strike, PlugX...
In many cases we have seen that these systems also were targeted previously with PlugX and other malware.
ASEC (AhnLab Security Emergency response Center) has recently discovered the installation of the PlugX malware through the Chinese remote control programs Sunlogin and Awesun’s remote code execution vulnerability.
PlugX is a malware family existing since at least 2008, used in multiple targeted attacks usually by Chinese threat actors... It is believed that Shadowpad is the successor of PlugX.
TinyX. A version of PlugX sans the plug-in functionality that allows it to adopt new capabilities. TinyX is bundled separately in spear-phishing emails.
PlugX (aka Korplug , Sogu ) Modular RAT widely used by China-nexus clusters; supports command execution, screen capture, keylogging, file operations, and process/service management.
The initial and primary backdoor the threat actor used in this attack was the PlugX backdoor. PlugX is a well-known remote access tool (RAT) with modular plugins and customizable settings that has been popular for over a decade, primarily among Chinese-speaking threat groups.
Using our telemetry data, we found that the threat actor also dropped PlugX and ShadowPad samples in victim environments.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
Злоумышленники также используют и хорошо известное ВПО: PlugX, ShadowPad, Poison Ivy, модифицированный вариант PcShare и публичный шелл ReVBShell.
UNC3569 uses this malware payload installer tool to deploy the SOGU backdoor, demonstrating a willingness to leverage external resources to enhance its operational capabilities.
These revolved around a few known toolsets commonly associated with Chinese threat actors, notably the PlugX malware... PlugX is a well-known Chinese trojan used by a whole host of threat actors.
Like other researchers, we thought this might be a PlugX-like campaign, given that the attack chain shares several characteristics with observed PlugX attacks.
Like other researchers, we thought this might be a PlugX-like campaign, given that the attack chain shares several characteristics with observed PlugX attacks.
Later that August, Symantec highlighted the activity of a new threat cluster codenamed Carderbee, which was found using a trojanized version of the program to deploy PlugX, a backdoor widely used by Chinese hacking groups like Mustang Panda.
“Malware such as PlugX and ShadowPad... became central to campaigns attributed to APT3, APT41, GALLIUM, and Winnti.” | In 2008, a new remote access Trojan named PlugX… was detected in the wild for the first time. PlugX is to this day widely used by Chinese threat actors for data theft and remote control. | PlugX was developed in 2008... According to MITRE ATT&CK, PlugX has been used by more than ten China-linked APT groups, including APT3, APT31, GALLIUM, the Winnti Group, as well as Zhou Shuai’s APT27. PlugX’s ongoing relevance was highlighted in January 2025, when the FBI removed PlugX from over 4,000 U.S. systems.
"...a DLL (CANONSTAGER), and the SOGU.SEC backdoor in RC-4 encrypted form. CANONSTAGER decrypts and loads the final payload... SOGU.SEC, which Google says is a variant of the PlugX malware..." | "SOGU.SEC, which Google says is a variant of the PlugX malware, used extensively by multiple Chinese threat groups..."
In 2008, a new remote access Trojan named PlugX… was detected in the wild for the first time. PlugX is to this day widely used by Chinese threat actors for data theft and remote control. | PlugX was developed in 2008... According to MITRE ATT&CK, PlugX has been used by more than ten China-linked APT groups, including APT3, APT31, GALLIUM, the Winnti Group, as well as Zhou Shuai’s APT27. PlugX’s ongoing relevance was highlighted in January 2025, when the FBI removed PlugX from over 4,000 U.S. systems.
Telecommunications and manufacturing sectors in Central and South Asian countries have emerged as the target of an ongoing campaign distributing a new variant of a known malware called PlugX (aka Korplug or SOGU).
They said LuoYu have newly used the following malware since JSAC2021: Malware: XDealer, ShadowPad, PlugX
Telecommunications and manufacturing sectors in Central and South Asian countries have emerged as the target of an ongoing campaign distributing a new variant of a known malware called PlugX (aka Korplug or SOGU).
Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike
Appendix A lists "PlugX" under Malware.
"Usually, the delivered payload is either the well-known ‘PlugX’ or ‘HttpBrowser’ RAT"
Avira blogged about HoneyMyte PlugX variants... PlugX has been used by multiple APT groups over the past decade...
“this intrusion set also utilizes commonly used remote control tools like Cobalt Strike, PlugX, or Meterpreter stagers interchangeably in various attack stages.”
"...uses well-crafted phishing to deliver PlugX payloads." / "...side-loaded DLL acted as a PlugX loader, which then brought in multiple plugins..."
“PlugX Diplomacy: A Mustang Panda Campaign”
"PlugX is a long-running Remote Access Trojan (RAT)..." ... "Avk.dll – identified by VirusTotal as Korplug (a PlugX variant)."
Exploited software
Vulnerabilities linked to PlugX
28 CVEsMITRE ATT&CK
PlugX in ATT&CK
121 distinct techniquesTechniques
121 techniquesReporting
Research mentioning PlugX
Officials disrupt Chinese espionage operation that hit multiple federal agencies | CyberScoop
The FBI and Department of Justice seized domains supporting the China-linked QTFY espionage group's QScan and QTRouter platforms after the infrastructure was linked to intrusions at NASA, the Federal Reserve, the Departments of Justice and Energy, and the U.S. Senate. Officials said the platforms supported follow-on attacks against sensitive networks and U.S. critical infrastructure, though they did not disclose the extent of access or data compromise at each victim. QTFY's technical infrastructure included the QScan reconnaissance and IoT-compromise tool, QTRouter hardware, QTProxy route management, and the Fast Labyrinth encrypted relay network. The operators combined compromised IoT devices, leased VPS systems, and premium nodes from the Chinese commercial proxy service fastlink.ws to rotate malicious traffic through consumer-proxy infrastructure and conceal its origin. Defenders should prioritize edge-device hardening and apply CISA and NCSC guidance on China-linked threats, as static IP or domain blocking alone is unlikely to stop the dynamically changing relay network.