Skip to main content
QUIETLYTIC
Malware

PlugX

Modular remote access tool with plugin architecture, per MITRE ATT&CK, used by multiple China-linked threat groups and the subject of a December 2024 US DOJ court-authorized disruption operation.

Threat Level
HIGH
Family
PlugX
Type
OTHER
Also Known As
Thoper, TVT, DestroyRAT, Sogu, Kaba, Korplug

Overview

PlugX (MITRE ATT&CK ID S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups, per MITRE’s software profile. MITRE’s citations include a December 2024 US Department of Justice affidavit describing a court-authorized law-enforcement operation against PlugX infrastructure — one of the more concrete recent enforcement actions documented in MITRE’s reference data for any malware family in this batch.

Actors documented using this tool (per MITRE ATT&CK relationship data)

Our ingested data links PlugX to 12 distinct MITRE ATT&CK groups, including GALLIUM, APT3, APT41, menuPass, Mustang Panda, Higaisa, Axiom, Winnti Group, and Threat Group-3390 — a heavily China-associated cluster of threat actors, consistent with PlugX’s long-documented status as a favored tool of China-linked espionage groups.

Notable techniques (per MITRE ATT&CK relationship data)

Techniques MITRE links to PlugX in our data include Binary Padding (T1027.001), Clear Persistence (T1070.009), DLL-based execution (T1574.001), DNS-based command-and-control (T1071.004), Dead Drop Resolver (T1102.001), Debugger Evasion (T1622), and Disable or Modify System Firewall (T1686).

What we don’t have

MITRE’s ingested data doesn’t include a structured discovery-date field for software entries. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no data on PlugX’s current operational status following the DOJ’s documented 2024 disruption operation against a portion of its infrastructure.

Frequently Asked Questions

What is PlugX? A modular remote access tool, per MITRE ATT&CK, used by multiple China-linked threat groups — the subject of a December 2024 US DOJ court-authorized infrastructure disruption operation.

Which threat groups use PlugX? Per MITRE ATT&CK’s relationship data, 12 tracked groups, including APT41, Mustang Panda, menuPass, and Winnti Group — predominantly China-associated espionage actors.

Is PlugX still active? MITRE’s static reference data doesn’t include current operational-status telemetry; the 2024 DOJ action targeted specific documented infrastructure, not necessarily the malware family’s continued development or use elsewhere.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), software ID S0013, aggregated September 2, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more malware profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools