DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwarePlugX | PlugX has captured victim IP address details of the targeted machine. |
| T1041 Exfiltration Over C2 Channel |
MalwarePlugX | PlugX has exfiltrated stolen data and files to its C2 server. |
| T1070.004 File Deletion |
MalwarePlugX | PlugX has the remove itself and other artifacts. |
| T1074.001 Local Data Staging |
MalwarePlugX | PlugX has collected and staged the victim’s computer files for exfiltration. |
| T1083 File and Directory Discovery |
MalwarePlugX | PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution. |
| T1091 Replication Through Removable Media |
MalwarePlugX | PlugX has copied itself to infected removable drives for propagation to other victim devices. |
| T1105 Ingress Tool Transfer |
MalwarePlugX | PlugX has a module to download and execute files on the compromised machine. |
| T1112 Modify Registry |
MalwarePlugX | PlugX has a module to create, delete, or modify Registry keys. |
| T1120 Peripheral Device Discovery |
MalwarePlugX | PlugX can identify removable media attached to compromised hosts. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePlugX | PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.