Malware.View on attack.mitre.org
PlugX is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
PlugX can enumerate and query for information contained within the Windows Registry. |
| T1016 System Network Configuration Discovery |
PlugX has captured victim IP address details of the targeted machine. |
| T1027 Obfuscated Files or Information |
PlugX can use API hashing and modify the names of strings to evade detection. |
| T1027.001 Binary Padding |
PlugX has utilized junk code and opaque predicates in payloads to hinder analysis. |
| T1027.007 Dynamic API Resolution |
PlugX has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API. |
| T1027.013 Encrypted/Encoded File |
PlugX has leveraged XOR encryption with the key of 123456789. |
| T1033 System Owner/User Discovery |
PlugX has the ability to gather the username from the victim’s machine. |
| T1036.004 Masquerade Task or Service |
In one instance, menuPass added PlugX as a service with a display name of "Corel Writing Tools Utility." |
| T1036.005 Match Legitimate Resource Name or Location |
PlugX has been disguised as legitimate Adobe and PotPlayer files. PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs. |
| T1041 Exfiltration Over C2 Channel |
PlugX has exfiltrated stolen data and files to its C2 server. |
| T1049 System Network Connections Discovery |
PlugX has a module for enumerating TCP and UDP network connections and associated processes using the |
| T1053.005 Scheduled Task |
PlugX has created a scheduled task to execute additional malicious software, as well as maintain persistence. |
| T1056.001 Keylogging |
PlugX has a module for capturing keystrokes per process including window titles. |
| T1057 Process Discovery |
PlugX has a module to list the processes running on a machine. |
| T1059.003 Windows Command Shell |
PlugX allows actors to spawn a reverse shell on a victim. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.