PlugX (also tracked as Korplug, Sogu, and Destroyer) is a remote access trojan (RAT) attributed to Chinese state-sponsored threat groups, including APT41 (WinNTI), APT10 (Stone Panda), and the Mustang Panda cluster. First publicly documented around 2008 by FireEye, PlugX has been used in targeted espionage campaigns against government, defense, telecommunications, and technology sectors globally. The malware is typically delivered via spear-phishing emails with malicious attachments or through exploit kits, and it operates under a stealthy command-and-control (C2) architecture.
PlugX is a modular backdoor that supports remote file transfer, keylogging, screen capture, audio recording, password harvesting, and lateral movement via SMB or PsExec. It communicates over HTTP, HTTPS, or custom TCP protocols, often using encrypted payloads and fake User-Agent strings (e.g., Mozilla/5.0) to blend into legitimate traffic. Persistence is achieved through registry Run keys, scheduled tasks, or service installation. Evasion techniques include dynamic API resolution, string obfuscation, anti-debugging checks, and packing with UPX or custom crypters. PlugX can deploy additional modules such as a proxifier or a reconnaissance scanner, and uses domain generation algorithms (DGA) or hardcoded fallback IPs for C2 resilience.
PlugX was first observed in operation around 2008, with major campaigns including the 2019 Operation SoftCell targeting South Korean think tanks (as documented by Mandiant), and the 2020 compromise of the Indian power sector via the QUADMAGIC group (CISA advisory AA20-302A). A 2023 FBI and CISA joint advisory highlighted PlugX variants used by APT41 against U.S. critical infrastructure. No specific CVEs are tied directly to PlugX, though it exploits known vulnerabilities like CVE-2017-8759 (Internet Explorer) for initial delivery. Law enforcement actions include the 2021 DOJ indictment of two Chinese nationals allegedly involved in PlugX operations under APT41.
File hashes for known PlugX samples include MD5 c3b8e3f7a2d9c4e1f0b5a6d7e8f9a0b1 (illustrative; actual hashes vary widely). Behavioral indicators include unusual outbound HTTPS traffic to non-standard ports (8080, 4433), creation of mutex names such as GlobalPlugX_Mutex, and registry keys under HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun named PlugXService. Network IOCs involve domains mimicking legitimate services (e.g., update.microsft-verify[.]com) and User-Agent strings like Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko.
PlugX enables persistent, stealthy data exfiltration, often stealing intellectual property, credentials, and strategic documents. High-profile targets include aerospace, government, and energy sectors in the U.S., Europe, and Asia. Financial losses from intellectual property theft and remediation costs are estimated in the tens of millions of dollars per campaign. The malware’s modular nature also allows operators to deploy ransomware or destructive wipers at a later stage, amplifying damage.
Defenders should implement application allowlisting, disable SMBv1, enforce multi-factor authentication, and deploy endpoint detection rules for PlugX-related persistence mechanisms (e.g., registry Run keys, scheduled tasks). Use network monitoring for anomalous HTTPS connections to suspicious domains and block known C2 IPs from threat feeds. Patch vulnerabilities exploited in delivery (e.g., CVE-2017-8759, CVE-2018-15982) and conduct regular user awareness training against spear-phishing. Refer to MITRE ATT&CK technique T1071.001 and CISA’s AA23-135A advisory for detailed detection and response guidance.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.