Netskope Threat Labs

PlugX

ATP Sandbox Adv. HeuristicsAVNetskope IPS

PlugX is a remote access trojan widely used by Chinese state sponsored groups for espionage against governments, dissidents, and industries across Asia and beyond. It gives operators full remote control, including command execution, file theft, and device monitoring, and its USB propagation variants spread automatically through removable drives. Intrusions typically begin with spear phishing and DLL side loading, and the family's modular design and long maintenance history have kept it central to regional espionage for over a decade.

First seen
March 2022
Last seen
October 2026
KorplugPlugxThoper

49 techniques across 9 tactics.

TA0002 Execution

TA0003 Persistence

  • T1543Create or Modify System Process
  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1012Query Registry
  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1049System Network Connections Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1120Peripheral Device Discovery
  • T1124System Time Discovery
  • T1135Network Share Discovery
  • T1614System Location Discovery
  • T1680Local Storage Discovery

TA0008 Lateral Movement

  • T1091Replication Through Removable Media

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0112 Defense Impairment

  • T1112Modify Registry
  • T1686Disable or Modify System Firewall
Alert Name
Binary.Backdoor.Korplug
Binary.Backdoor.Plugx
ByteCode-MSIL.Backdoor.Korplug
ByteCode-MSIL.Backdoor.Plugx
ByteCode-MSIL.Trojan.Plugx
Gen:Variant.Korplug.25
Gen:Variant.Korplug.30
Gen:Variant.Korplug.8
Gen:Variant.PlugX.1
Script-JS.Backdoor.Plugx