PlugX

MITRE ATT&CK: S0013 View on attack.mitre.org

Aliases: Thoper, TVT, DestroyRAT, Sogu, Kaba, Korplug, Destroy RAT, RedDelta, TIGERPLUG, PlugX, SOGU, Scontroller

First seen
2008-06-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
636 (325 malicious)
Last IoC activity
2026-09-02 03:54:35
Profile updated
2026-07-07 15:46:30

Targeted industries: government-and-public-sector defense-and-aerospace healthcare-and-pharmaceutical technology-and-telecommunications

Targeted regions: country_code:cn country_code:us country_code:hk country_code:tw

Context

PlugX is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.

Recent IoC activity

325 malicious indicators in Maltiverse are attributed to PlugX (S0013). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname quickoffice360.com 2026-09-03 1
hostname update-trellix.com 2026-09-03 1
hostname gw95.nanosystems.it 2026-09-03 1
hostname getfiledown.com 2026-09-03 1
hostname gw668.nanosystems.it 2026-09-03 1
hostname gw344.nanosystems.it 2026-09-03 1
hostname electrictulsa.com 2026-09-03 1
hostname armzrace.com 2026-09-03 1
hostname gw563.nanosystems.it 2026-09-03 1
hostname update.googlewired.com 2026-09-03 1
hostname gw90.nanosystems.it 2026-09-03 1
hostname gw728.nanosystems.it 2026-09-03 1
hostname truckingaccidentattorneyblog.com 2026-09-03 1
hostname gw671.nanosystems.it 2026-09-03 1
hostname gw669.nanosystems.it 2026-09-03 1
hostname gw572.nanosystems.it 2026-09-03 1
hostname createcopilot.com 2026-09-03 1
hostname gw786.nanosystems.it 2026-09-03 1
hostname gw574.nanosystems.it 2026-09-03 1
hostname gw545.nanosystems.it 2026-09-03 1

Detection coverage

  • 10 YARA rules
  • 749 Sigma rules

Malware & tools used

  • Debugger Evasion (attack-pattern)
  • Modify Registry (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • System Location Discovery (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • Mutual Exclusion (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Malicious File (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Dead Drop Resolver (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Reflective Code Loading (attack-pattern)
  • Process Discovery (attack-pattern)
  • Query Registry (attack-pattern)
  • DLL (attack-pattern)
  • Clear Persistence (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • MSBuild (attack-pattern)
  • Web Protocols (attack-pattern)
  • Windows Service (attack-pattern)
  • Windows Command Shell (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Plugx_Auto (yara-rule)
  • ARKBIRD_SOLG_Mal_Plugx_Thor_July_2021_1 (yara-rule)
  • SECUINFRA_MALWARE_Plugx_USB_Delivery_LNK_Jun23 (yara-rule)
  • SECUINFRA_MALWARE_Plugx_USB_Delivery_Ini_Icon_Jun23 (yara-rule)
  • SECUINFRA_MALWARE_Plugx_USB_Delivery_Ini_Recbin_Jun23 (yara-rule)
  • SEKOIA_Plugx_Final_Payload (yara-rule)
  • SEKOIA_Apt_Mustangpanda_Maliciousdll_Loading_Plugx_Strings (yara-rule)
  • SIGNATURE_BASE_APT_CN_MAL_Reddelta_Shellcode_Loader_Oct20_1 (yara-rule)
  • SIGNATURE_BASE_APT_CN_MAL_Reddelta_Shellcode_Loader_Oct20_2 (yara-rule)
  • SIGNATURE_BASE_APT_CN_MAL_Reddelta_Shellcode_Loader_Oct20_3 (yara-rule)

Reports & references

  • secureworks.com — Bronze Keystone (report)
  • MITRE ATT&CK — G0001 (report)
  • secureworks.com — Bronze Firestone (report)
  • web.archive.org — Bkdr Rarstone New Rat To Watch Out For (report)
  • secureworks.com — Threat Group 3390 Targets Organizations For Cyberespionage (report)
  • secureworks.com — Bronze Union (report)
  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • ESET — Exchange Servers Under Siege 10 Apt Groups (report)
  • secureworks.com — Bronze Riverside (report)
  • go.recordedfuture.com — Cta 2021 0616 (report)
  • secureworks.com — Bronze Woodland (report)
  • threatconnect.com — Research Roundup Activity On Previously Identified Apt33 Domains (report)
  • secureworks.com — Bronze Overbrook (report)
  • Palo Alto Unit 42 — Shallowtaurus (report)
  • secureworks.com — Bronze Olive (report)
  • secureworks.com — Bronze Express (report)
  • uscc.gov — Adam Kozy Testimony (report)
  • pwc.com — Yir Cyber Threats Annex Download (report)
  • secureworks.com — Bronze President (report)
  • darkreading.com — Chinese Apt Bronze President Spy Campaign Russian Military (report)
  • proofpoint.com — Ta416 Goes Ground And Returns Golang Plugx Malware Loader (report)
  • proofpoint.com — Good Bad And Web Bug Ta416 Increases Operational Tempo Against European (report)
  • jsac.jpcert.or.jp — Jsac2023 2 Lt4 (report)
  • recordedfuture.com — China Linked Ta428 Threat Group (report)
  • decoded.avast.io — Apt Group Targeting Governmental Agencies In East Asia (report)

External references