Malware

PlugX

Also known as: Destroy RAT · Kaba · Korplug · RedDelta · Sogu · TIGERPLUG

RSA describes PlugX as a RAT (Remote Access Trojan) malware family that is around since 2008 and is used as a backdoor to control the victim's machine fully. Once the device is infected, an attacker can remotely execute several kinds of commands on the affected system. Notable features of this malware family are the ability to execute commands on the affected machine to retrieve: machine information capture the screen send keyboard and mouse events keylogging reboot the system manage processes (create, kill and enumerate) manage services (create, start, stop, etc.); and manage Windows registry entries, open a shell, etc. The malware also logs its events in a text log file.

Indicators of Compromise 100

Domain about[.]blsouqs[.]com Domain api2[.]annoyingremote[.]com Domain black-popular[.]com Domain cloudtroe[.]giize[.]com Domain cms[.]balochistanpolice[.]gov[.]pk Domain confbase[.]mdpsupport[.]net Domain ctyuhjerf[.]kozow[.]com Domain decoraat[.]net Domain digital[.]leroymerling[.]com Domain dns[.]multitoconference[.]com Domain dns[.]ssentialserv[.]xyz Domain employers[.]theworkpc[.]com Domain fm01[.]clouddevicemetrics[.]com Domain freeread[.]casacam[.]net Domain gycudore[.]kozow[.]com Domain news[.]dursamjbataar[.]org Domain onedown[.]gesecole[.]net Domain rgnojb[.]casacam[.]net Domain ssl[.]blsouqs[.]com Domain sundanish[.]freeddns[.]org Domain tj[.]tajikistandip[.]com Domain torinarlabs[.]webredirect[.]org Domain tyhbgtyuj[.]gleeze[.]com Domain us[.]lenovoappstore[.]com Domain uyhvfredc[.]accesscam[.]org Domain video[.]dursamjbataar[.]org Domain wedfcvbn[.]gleeze[.]com Domain whatismybestthing[.]com Filename 1.bat Filename 360Safe.exe Filename 7z.exe Filename AVK.exe Filename AVKTray.dat Filename Adobe.exe Filename AnyDesk.exe Filename Avk.dll Filename Invitation_Letter_No.02_2026.csproj Filename Invitation_Letter_No.02_2026.exe Filename OctLurk Command Shell plugin Filename OctLurk File Manager plugin Filename OctLurk Interaction Manager plugin Filename OctLurk backdoor Filename RasTls.dll Filename RecordedTV.exe Filename auto.bat Filename cert.ini Filename cms_plugin.exe Filename ctxmui.dll Filename defender.exe Filename fc.exe Filename in.bat Filename kmsonline.exe Filename libngs.dll Filename loadcert.ini Filename msagent.sys Filename msbasesysdc.dll Filename mscastrac.dll Filename oleasapi.dll Filename pp.txt Filename recordutil.exe Filename synchost.exe Filename time.ini Filename vulkan-1.dll Filename x64.exe MD5 082d49ef9f14e6811d68c7e0e82e5069 MD5 1415a78b75de7db4ba3d1e61d7db4501 MD5 18dc8bff47cc282508354771d0c8cf8c MD5 2a571f6cee42a17d873f4c942649813f MD5 2d7c8780e97409770a9d4f31c66c9d63 MD5 32a5985543433a4f60da2fafd873b927 MD5 37dc84e4bcad92fa28f1e7778d088283 MD5 3c9a1ba8e0c7475706adc6376e9d7b7c MD5 45cf5916fab4272a1313c26e67aa9220 MD5 4e6d5c4770d5a822d7fcce6a74f7ad73 MD5 5e26df131ff0a679a0a2699b723b46e3 MD5 6ecf84fb18f6747ed08d7598364d853a MD5 7c2f64461bb519c6cbf1fc687675514c MD5 8269d6ba1b6842f9152c90cf7add9b93 MD5 9460e150e1981d5c165043520c5c12fe MD5 9717f005c5fb98e08d2ad983d88f94ee MD5 9a1dd1d96481d61934dcc2d568971d06 MD5 a0cc7accc79abb0287aaba825d0351f0 MD5 a4d550a3ba0cd073fe3839b99d98a7a8 MD5 a56cce62930a6bee80d679b4c495a340 MD5 b874123a80fc4f40e06872b9cb54ebc6 MD5 cf903e4a1629aa0582fd0363b5786676 MD5 ef59aad625eebda8650aec5820d6ce69 MD5 f4578e869a735cfad691f927bae3e638 MD5 f518d8e5fe70d9090f6280c68a95998f SHA-1 9460e150e1981d5c165043520c5c12fe SHA-1 eb79558b037669792652a816e2c669de SHA-1 f518d8e5fe70d9090f6280c68a95998f SHA-256 29cd44aa2a51a200d82cca578d97dc13241bc906ea6a33b132c6ca567dc8f3ad SHA-256 46314092c8d00ab93cbbdc824b9fc39dec9303169163b9625bae3b1717d70ebc SHA-256 5f9af68db10b029453264cfc9b8eee4265549a2855bb79668ccfc571fb11f5fc SHA-256 6df8649bf4e233ee86a896ee8e5a3b3179c168ef927ac9283b945186f8629ee7 SHA-256 7ed0cd4115f3ff35c38d36cc50c6a13eba2d845554439a36108789cd1e05b176 SHA-256 8421e7995778faf1f2a902fb2c51d85ae39481f443b7b3186068d5c33c472d99 SHA-256 d293ded5a63679b81556d2c622c78be6253f500b6751d4eeb271e6500a23b21e SHA-256 de8ddc2451fb1305d76ab20661725d11c77625aeeaa1447faf3fbf56706c87f1

MITRE ATT&CK TTPs 53

T1001
Data Obfuscation
Command And Control
T1001.002
Steganography
Command And Control
T1001.003
Protocol or Service Impersonation
Command And Control
T1003
OS Credential Dumping
Credential Access
T1012
Query Registry
Discovery
T1018
Remote System Discovery
Discovery
T1021
Remote Services
Lateral Movement
T1021.001
Remote Desktop Protocol
Lateral Movement
T1021.002
SMB/Windows Admin Shares
Lateral Movement
T1027
Obfuscated Files or Information
Defense Evasion
T1027.002
Software Packing
Defense Evasion
T1036
Masquerading
Defense Evasion
T1036.001
Invalid Code Signature
Defense Evasion
T1036.005
Match Legitimate Name or Location
Defense Evasion
T1041
Exfiltration Over C2 Channel
Exfiltration
T1048
Exfiltration Over Alternative Protocol
Exfiltration
T1053
Scheduled Task/Job
Execution
T1055
Process Injection
Defense Evasion
T1055.001
Dynamic-link Library Injection
Defense Evasion
T1056.001
Keylogging
Collection
T1059
Command and Scripting Interpreter
Execution
T1059.001
PowerShell
Execution
T1059.003
Windows Command Shell
Execution
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1070.001
Clear Windows Event Logs
Defense Evasion
T1070.002
Clear Linux or Mac System Logs
Defense Evasion
T1070.003
Clear Command History
Defense Evasion
T1070.004
File Deletion
Defense Evasion
T1070.005
Network Share Connection Removal
Defense Evasion
T1070.006
Timestomp
Defense Evasion
T1071
Application Layer Protocol
Command And Control
T1071.001
Web Protocols
Command And Control
T1075
T1075
T1078
Valid Accounts
Defense Evasion
T1078.003
Local Accounts
Defense Evasion
T1081
T1081
T1082
System Information Discovery
Discovery
T1083
File and Directory Discovery
Discovery
T1090
Proxy
Command And Control
T1090.001
Internal Proxy
Command And Control
T1110
Brute Force
Credential Access
T1114
Email Collection
Collection
T1120
Peripheral Device Discovery
Discovery
T1133
External Remote Services
Persistence
T1134
Access Token Manipulation
Defense Evasion
T1134.001
Token Impersonation/Theft
Defense Evasion
T1204.002
Malicious File
Execution
T1210
Exploitation of Remote Services
Lateral Movement
T1548
Abuse Elevation Control Mechanism
Privilege Escalation
T1548.002
Bypass User Account Control
Privilege Escalation
T1555
Credentials from Password Stores
Credential Access
T1566
Phishing
Initial Access
T1566.001
Spearphishing Attachment
Initial Access

Source Articles

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
The threat actor Mustang Panda, also known as HoneyMyte, has updated its CoolClient backdoor with a signed Windows kernel-mode rootkit to enhance stealth. The rootkit, deployed as msagent.sys, is digitally signed with a certificate from Nanjing Ranyi Technology Co., Ltd. and enables hiding of malicious processes, files, registry entries, and C2 network activity. The malware is typically deployed after initial compromise via PlugX and uses DLL sideloading through a legitimate Sangfor executable to execute malicious components and establish persistence.
hacker-news ·2w ago
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
The HoneyMyte APT group, also known as Mustang Panda, has upgraded its CoolClient backdoor with a kernel-mode Windows rootkit to enhance stealth and persistence. The new variant uses a signed kernel driver, msagent.sys, deployed as a Windows service to hide malicious processes, files, registry keys, and network connections. The malware chain begins with DLL sideloading via a renamed Sangfor executable (defender.exe), establishes persistence through scheduled tasks and registry entries, performs UAC bypass using RPC techniques, and injects into synchost.exe before deploying the driver. The driver communicates with user-mode components via IOCTLs and employs minifilter and registry callbacks to protect its artifacts.
securelist ·2w ago
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
A Chinese-speaking threat actor has been targeting government and public sector organizations in Central Asia since January 2025 using two custom backdoors, OctLurk and SilkLurk, along with a proxy tool called LurkProxy. The malware operates primarily in memory, using obfuscated loaders and victim-specific encoding to evade detection. Post-compromise activities include credential dumping, data exfiltration, remote access via Pandora RC, and lateral movement using tools like Impacket and Fscan.
hacker-news ·4w ago
PlugX Meeting Invitation via MSBuild and GDATA
A recent PlugX RAT campaign leverages a spear-phishing email with the subject 'Meeting Invitation' to deliver malicious payloads via DLL side-loading. The infection chain uses a legitimate G DATA antivirus executable (Avk.exe) to load a malicious DLL (Avk.dll), which decrypts and executes the payload from AVKTray.dat. The malware establishes persistence through a registry Run key and communicates with the C2 server at decoorat[.]net over HTTPS on port 443. The campaign demonstrates continued use of trusted binaries, XOR-based obfuscation, and API hashing techniques consistent with China-aligned threat actors.
lab52 ·6mo ago
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Kaspersky researchers identified a cyber-espionage campaign targeting government and public sector organizations in Central Asia since January 2025, using two custom backdoors: OctLurk and SilkLurk. Both backdoors are heavily obfuscated, deployed via customized loaders that use victim-specific data for decryption, and support plugin-based post-compromise activities including credential theft, keylogging, remote access, and data exfiltration. The same threat actor, assessed as Chinese-speaking, operates both backdoors and has deployed secondary payloads such as PlugX and Impacket's secretsdump. Infrastructure overlap with the TrustFall (MystRodX/SilentRaid) campaign suggests coordinated multi-platform operations.
securelist ·4w ago
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Cyber espionage campaigns targeting Pakistani law enforcement agencies, including the Balochistan Police, have been conducted by suspected China- and India-aligned threat actors between February 2024 and April 2026. The attackers exploited web applications such as the Complaint Management System to deploy custom malware, including PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. These operations targeted sensitive data including biometric records, criminal files, and personnel information, with infrastructure overlaps linking some activity to known threat groups like Mysterious Elephant. The compromise of public-facing portals extended the attack surface to both law enforcement and citizens.
hacker-news ·1mo ago