PlugX

S0013

Malware.View on attack.mitre.org

About this malware

PlugX is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.

Techniques used49

Procedure examples49

TechniqueProcedure example
T1012
Query Registry

PlugX can enumerate and query for information contained within the Windows Registry.

T1016
System Network Configuration Discovery

PlugX has captured victim IP address details of the targeted machine.

T1027
Obfuscated Files or Information

PlugX can use API hashing and modify the names of strings to evade detection.

T1027.001
Binary Padding

PlugX has utilized junk code and opaque predicates in payloads to hinder analysis.

T1027.007
Dynamic API Resolution

PlugX has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API.

T1027.013
Encrypted/Encoded File

PlugX has leveraged XOR encryption with the key of 123456789.

T1033
System Owner/User Discovery

PlugX has the ability to gather the username from the victim’s machine.

T1036.004
Masquerade Task or Service

In one instance, menuPass added PlugX as a service with a display name of "Corel Writing Tools Utility."

T1036.005
Match Legitimate Resource Name or Location

PlugX has been disguised as legitimate Adobe and PotPlayer files. PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs.

T1041
Exfiltration Over C2 Channel

PlugX has exfiltrated stolen data and files to its C2 server.

T1049
System Network Connections Discovery

PlugX has a module for enumerating TCP and UDP network connections and associated processes using the netstat command.

T1053.005
Scheduled Task

PlugX has created a scheduled task to execute additional malicious software, as well as maintain persistence.

T1056.001
Keylogging

PlugX has a module for capturing keystrokes per process including window titles.

T1057
Process Discovery

PlugX has a module to list the processes running on a machine.

T1059.003
Windows Command Shell

PlugX allows actors to spawn a reverse shell on a victim.

View all 49 procedure examples

Groups that use it15

Campaigns1

References4

  1. Dell TG-3390 Open source
    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.
  2. FireEye Clandestine Fox Part 2 Open source
    Scott, M.. (2014, June 10). Clandestine Fox, Part Deux. Retrieved January 14, 2016.
  3. Lastline PlugX Analysis Open source
    Vasilenko, R. (2013, December 17). An Analysis of PlugX Malware. Retrieved November 24, 2015.
  4. New DragonOK Open source
    Miller-Osborn, J., Grunzweig, J.. (2015, April). Unit 42 Identifies New DragonOK Backdoor Malware Deployed Against Japanese Targets. Retrieved November 4, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.