PlugX, also known as Korplug and SOGU, is a long-running Windows remote access trojan and backdoor family closely associated with Chinese espionage activity and frequently linked to clusters such as Mustang Panda and other China-nexus operators. It has been used for years across government, diplomatic, defense, law-enforcement, and regional geopolitical targeting, including campaigns against European government entities and Pakistani law-enforcement organizations.
PlugX is commonly delivered through DLL sideloading chains that abuse legitimate signed executables to load a malicious DLL, which then decrypts and executes the final implant or shellcode in memory. Observed delivery themes include spearphishing lures, fake software or browser updates, and archive-based social engineering. Recent campaigns have used multi-stage loaders, CHM and LNK orchestration, MSI payloads, and signed binaries from security or printer software to sideload PlugX components.
The malware is modular and supports a broad post-compromise feature set. Documented capabilities include remote command execution, file management and transfer, plugin loading, keylogging, screenshot capture, process and service control, registry enumeration and modification, network share browsing, port forwarding, remote shell access, and system reconnaissance. Variants also query and modify the Windows Registry for configuration, persistence, and host information. Some analyzed samples support multiple command-and-control transports, including HTTP or HTTPS, raw TCP, UDP, and DNS tunneling, and use layered obfuscation, encrypted configuration storage, API hashing, manual PE mapping, and polymorphic or shellcode-based loaders to hinder detection and analysis.
PlugX remains one of the most recognizable malware families in the Chinese intrusion ecosystem and is often treated as a shared backdoor platform across multiple China-aligned threat clusters rather than a tool exclusive to a single actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In May 2024, CVE-2024-24919, an information disclosure vulnerability in Check Point Quantum Security Gateways was exploited in the wild and tied to NailaoLocker ransomware (distributed via ShadowPad and PlugX backdoors, as documented by Orange Cyberdefense CERT).
attackers opportunistically used spear-phishing emails with a Microsoft Word attachment exploiting the recently patched CVE-2017-0199 to deploy the ZeroT Trojan... In this campaign, attackers used a Microsoft Word document called 0721.doc, which exploits CVE-2017-0199. This vulnerability was disclosed and patched days prior to this attack.
In previous campaigns, the group used spear-phishing emails with Microsoft Word document attachments utilizing CVE-2012-0158... Attackers also continued to send spear-phishing emails with Microsoft Word attachments utilizing CVE-2012-0158 to exploit the client.
At the end of the infection chain, hackers deployed a version of PlugX malware onto victim machines. PlugX is a remote access Trojan that's been a staple of Chinese nation-state hacking since 2008. | Microsoft has been aware of the flaw, tracked as CVE-2025-9491, at least since September 2024, when the Zero Day Initiative identified it as ZDI-25-148 and ZDI-CAN-25373 and notified Redmond. The vulnerability exists in how Windows processes .lnk files, which are desktop icons acting as a shortcut to another file or application.
"...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks." | Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 ... Security firm Volexity spotted hackers targeting Exchange servers on Jan. 3, when it saw CVE-2021-26855 being exploited.
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks."
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks."
"...Winnti, aka Barium and APT41... The group used the PlugX RAT and ShadowPad malware in its attacks." | Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
“PlugX often used by Chinese threat actors… PlugX is a variant of the BackDoor.PlugX.38…”
In one case, we could see that this variant was deployed following exploitation of the CVE-2020-0688 vulnerability on the network of a government entity. This vulnerability, which was publicly reported in February 2020, allows an authenticated user to run commands as SYSTEM on a Microsoft Exchange server. | Avira blogged about HoneyMyte PlugX variants... PlugX has been used by multiple APT groups over the past decade...
It appears to have started with CVE-2014-3393, a vulnerability in the Cisco Clientless SSL VPN portal... A vulnerability in the Clientless SSL VPN portal customization framework could allow an unauthenticated, remote attacker to modify the content of the Clientless SSL VPN portal... An exploit could allow the attacker to bypass Clientless SSL VPN authentication and modify the portal content.
Associated Analytic Story AgentTesla CVE-2023-21716 Word RTF Heap Corruption Compromised Windows Host FIN7 PlugX Warzone RAT
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
26 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A similar G DATA binary has been used recently by Chinese APT to load PlugX malware... Proofpoint published recently on a new PlugX variant with multiple DLLs sideloaded by signed binaries.
Malware families and tools associated with APT10 include SOGU, HAYMAKER, SNUGRIDE, BUGJUICE, QUASARRAT, RedLeaves, PlugX, UPPERCUT/ANEL, ChChes, and, in newer related reporting, LODEINFO, NOOPDOOR, and NOOPLDR.
The initial and primary backdoor the threat actor used in this attack was the PlugX backdoor. PlugX is a well-known remote access tool (RAT) with modular plugins and customizable settings that has been popular for over a decade, primarily among Chinese-speaking threat groups.
The stage 2 payload was PlugX that beaconed to C&C servers www[.]icefirebest[.]com and www[.]icekkk[.]net.
Moshen Dragon deployed five different malware triads in an attempt to use DLL search order hijacking to sideload ShadowPad and PlugX variants.
Using our telemetry data, we found that the threat actor also dropped PlugX and ShadowPad samples in victim environments.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
According to the researchers, a China-linked operator planted malware disguised as a portal update — an executable that displayed a fake “update complete” message while infecting the visitor's device.
Backdoors shared among Chinese groups, including PlugX and ShadowPad, anchored the China-nexus assessments
Target chain : rundll32.exe -> shell32.dll,ShellExec_RunDLL -> conhost --headless -> cmd /c curl ...
The loader and payload directly use many Native/Windows APIs such as NtCreateFile, NtQueryInformationFile, NtReadFile, NtProtectVirtualMemory, VirtualAlloc, CreateThread, WriteProcessMemory, WinHttpOpen, and WinHttpConnect.
Upon clicking the link, the target is presented with a fake Cloudflare turnstile-style page
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
reads Shelter.ex , decrypts it using SystemFunction033 with the key 20260301@@@ , then transfers execution into the newly decrypted region
Numerous malware families and threat groups are described as achieving persistence by adding values under Run/RunOnce/Policies\Explorer\Run Registry keys or by placing shortcuts/files in the Windows Startup folder.
It doesn't rely on any packer or fancy encryption; it just inserts junk characters, fake whitespace, and misplaced quotes to break simple pattern matching.
Avk.dll resolves APIs using DJB2 hash; cJvsVIDinbGD resolves them using ROL19 hash; the worker thread decodes API names and resolves them at runtime.
The researchers also found malicious files disguised as software updates planted directly on Balochistan Police’s public Complaint Management System.
The malware installs itself into %PUBLIC%\GData and uses the folder name GData and Run key G Data to match the legitimate publisher/brand of Avk.exe.
reads Shelter.ex , decrypts it using SystemFunction033 with the key 20260301@@@ , then transfers execution into the newly decrypted region
The malware decodes multiple layers at runtime: decoding the string \AVKTray.dat, XOR-decoding the payload, RC4-decoding the config, and XOR-decoding each config field and C2 entry.
launch ShellFolder.exe as a signed cover for the sideloading step.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The command surface includes process-related capability; additionally, the side-effect taskkill iediagcmd.exe shows that the payload handles processes by name.
register_system_control_dispatcher System info, memory, locale
Its analysis of command-and-control netflow data revealed four tooling clusters converging on this victim class: PlugX, ShadowPad, Cobalt Strike, and Remcos.
The controller loop uses WinHTTP to connect to fruitbrat[.]com:443, builds an HTTP GET request, uses an Edge/Chrome-like User-Agent, and sends Cookie q63S=<encoded context> for beaconing.
733 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced for comparison with similar Chinese APT DLL sideloading tradecraft; not the primary malware analyzed in this report.
Referenced only in related content/background, not as part of the analyzed sample.
A backdoor associated in the content with suspected China-nexus cyberespionage activity targeting Pakistani law enforcement.
Referenced in external links only; not part of the main malware discussed in this article.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.