LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0013: PlugX

PlugX is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.[1][2][3][4]

EnterpriseS0013MalwareObject v3.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

PlugX matters because ATT&CK describes it as a Windows remote access tool with modular plugins and many historical relationships to campaigns and threat groups. For leaders, the key decision is not whether the name alone is detected, but whether the organization can prove visibility into the Windows behaviors ATT&CK links to it: discovery, registry querying, masqueraded services or tasks, and obfuscated or encoded files.

Executive priority

Treat PlugX as a resilience and readiness test for Windows endpoint monitoring, incident response triage, and threat-intelligence validation. Its many ATT&CK relationships mean a PlugX finding should trigger careful scoping and evidence preservation, but not automatic attribution. Executives should ask whether SOC and IR teams can quickly answer: which hosts executed suspicious binaries, what users and network settings were enumerated, whether registry and service/task changes occurred, and whether obfuscation limited inspection or control effectiveness.

Technical view

ATT&CK does not provide an official detection section for PlugX, so defenders should validate coverage against the linked techniques rather than rely on a malware name. Focus on Windows telemetry for Query Registry, System Owner/User Discovery, masqueraded tasks or services, and suspicious discovery of network configuration. Because PlugX is associated with obfuscation, binary padding, dynamic API resolution, and encrypted or encoded files, detection engineering should combine behavioral endpoint signals with file inspection limits and tuning for suspicious service/task naming rather than hash-only matching.

Likely telemetry

  • Windows endpoint process creation and command-line activity
  • Registry query events and registry access telemetry
  • Windows service and scheduled task creation, modification, names, and descriptions
  • File creation, modification, size anomalies, encoded/encrypted content indicators, and malware-analysis metadata
  • Endpoint detection telemetry for dynamic API resolution or suspicious runtime behavior where available

Detection direction

  • Validate detections for the ATT&CK-linked behaviors: registry queries, user discovery, network configuration discovery, masqueraded services/tasks, and obfuscated or encoded files.
  • Avoid relying only on hashes or static signatures because the linked obfuscation techniques include binary padding, encrypted/encoded files, and dynamic API resolution.
  • Tune service and task detections for names or descriptions that imitate legitimate administration artifacts, while accounting for legitimate IT automation to reduce false positives.
  • Correlate endpoint discovery behavior with file-obfuscation indicators and unusual persistence-like service/task changes before escalating to malware-family-level conclusions.
  • Use relationship context for threat-intelligence enrichment, but do not infer a specific group from PlugX alone because ATT&CK lists multiple groups and a campaign using it.

Mitigation priorities

  • Prioritize complete Windows endpoint logging for process, registry, file, service, scheduled task, user, and network-configuration activity.
  • Harden monitoring and approval workflows for new or modified services and scheduled tasks, especially where names resemble legitimate system or administrative components.
  • Ensure malware analysis and file-control processes account for large, padded, encrypted, or encoded binaries that may evade hash-only or size-limited inspection.
  • Prepare IR playbooks to scope suspected RAT activity by host, user, persistence mechanism, discovery activity, and outbound network evidence.
  • Use ATT&CK relationships to inform threat hunting and intelligence requirements, while keeping attribution decisions evidence-based.
Additional notes and limits

ATT&CK identifies PlugX as malware S0013, a Windows RAT with modular plugins used by multiple threat groups. The supplied relationships link PlugX to numerous groups and to RedDelta Modified PlugX Infection Chain Operations, whose description includes phishing delivery leading to PlugX loading. Technique relationships supplied for this object emphasize discovery and stealth behaviors.

The official ATT&CK object provides no detection text, no explicit tactics for the malware object, and only Windows as the malware platform. This take therefore focuses on supplied technique relationships and relationship context. Local telemetry, sample analysis, and incident evidence are required before concluding exposure, detection coverage, impact, or attribution.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

PlugX

PlugX is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

49 rows
DomainIDNameRelationship / procedure
EnterpriseT1622Debugger Evasion

PlugX has made calls to Windows API `CheckRemoteDebuggerPresent` and exits if it detects a debugger.[6]

EnterpriseT1112Modify Registry

PlugX has a module to create, delete, or modify Registry keys.[7][8][9]

EnterpriseT1083File and Directory Discovery

PlugX has a module to enumerate drives and find files recursively.[7][10][8][11] PlugX has also checked the path from which it is running for specific parameters prior to execution. [7][9][6]

EnterpriseT1614System Location Discovery

PlugX has obtained the location of the victim device by leveraging `GetSystemDefaultLCID`.[7]

EnterpriseT1036.004Masquerade Task or ServiceSub-technique

In one instance, menuPass added PlugX as a service with a display name of "Corel Writing Tools Utility."[12]

EnterpriseT1091Replication Through Removable Media

PlugX has copied itself to infected removable drives for propagation to other victim devices.[9]

EnterpriseT1480.002Mutual ExclusionSub-technique

PlugX has leveraged a mutex in its infection process.[7][6]

EnterpriseT1016System Network Configuration Discovery

PlugX has captured victim IP address details of the targeted machine.[7][9]

EnterpriseT1564.001Hidden Files and DirectoriesSub-technique

PlugX can modify the characteristics of folders to hide them from the compromised user.[11] PlugX has also modified file attributes to hidden and system.[7][6]

EnterpriseT1095Non-Application Layer Protocol

PlugX can be configured to use raw TCP or UDP for command and control.[7][4]

EnterpriseT1204.002Malicious FileSub-technique

PlugX has leveraged an initial executable disguised as a legitimate document to trick the target into opening it.[10][16]

EnterpriseT1680Local Storage Discovery

PlugX has collected a list of all mapped drives on the infected host.[7]

EnterpriseT1056.001KeyloggingSub-technique

PlugX has a module for capturing keystrokes per process including window titles.[8]

EnterpriseT1102.001Dead Drop ResolverSub-technique

PlugX uses Pastebin to store C2 addresses.[17]

EnterpriseT1124System Time Discovery

PlugX has identified system time through its GetSystemInfo command.[7]

EnterpriseT1620Reflective Code Loading

PlugX has loaded its payload into memory.[7][16][23][24][6]

EnterpriseT1057Process Discovery

PlugX has a module to list the processes running on a machine.[8]

EnterpriseT1012Query Registry

PlugX can enumerate and query for information contained within the Windows Registry.[7][8][1]

EnterpriseT1574.001DLLSub-technique

PlugX has the ability to use DLL search order hijacking for installation on targeted systems.[11][24] PlugX has also used DLL side-loading to evade anti-virus.[2][4][26][27][17][21][22] PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file.[7][10][16][24][6]

EnterpriseT1070.009Clear PersistenceSub-technique

PlugX has deleted registry keys that store data and maintained persistence.[7]

EnterpriseT1135Network Share Discovery

PlugX has a module to enumerate network shares.[7][8]

EnterpriseT1127.001MSBuildSub-technique

A version of PlugX loads as shellcode within a .NET Framework project using msbuild.exe, presumably to bypass application control techniques.[17]

EnterpriseT1071.001Web ProtocolsSub-technique

PlugX can be configured to use HTTP for command and control.[7][4][16][11] PlugX has also used HTTPS for C2.[23]

EnterpriseT1543.003Windows ServiceSub-technique

PlugX can be added as a service to establish persistence. PlugX also has a module to change service configurations as well as start, control, and delete services.[8][1][27][12][35]

EnterpriseT1059.003Windows Command ShellSub-technique

PlugX allows actors to spawn a reverse shell on a victim.[7][8][4][16][23][24]

EnterpriseT1105Ingress Tool Transfer

PlugX has a module to download and execute files on the compromised machine.[8][9][23][11]

EnterpriseT1686Disable or Modify System Firewall

PlugX has modified local firewall rules on victim machines to enable a random, high-number listening port for subsequent access and C2 activity.[5]

EnterpriseT1082System Information Discovery

PlugX has collected system information including OS version, processor information, RAM size, location, host name, IP, and screen size of the infected host.[7]

EnterpriseT1074.001Local Data StagingSub-technique

PlugX has collected and staged the victim’s computer files for exfiltration.[9]

EnterpriseT1497.001System ChecksSub-technique

PlugX checks if VMware tools is running in the background by searching for any process named "vmtoolsd".[36]

EnterpriseT1049System Network Connections Discovery

PlugX has a module for enumerating TCP and UDP network connections and associated processes using the netstat command.[8]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

PlugX has been disguised as legitimate Adobe and PotPlayer files.[11] PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs.[7][16][24][6]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

PlugX adds Run key entries in the Registry to establish persistence.[7][8][9][16][27][6][1] PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`.[7]

EnterpriseT1027.001Binary PaddingSub-technique

PlugX has utilized junk code and opaque predicates in payloads to hinder analysis.[7]

EnterpriseT1071.004DNSSub-technique

PlugX can be configured to use DNS for command and control.[4]

EnterpriseT1070.004File DeletionSub-technique

PlugX has the remove itself and other artifacts.[7][9]

EnterpriseT1113Screen Capture

PlugX allows the operator to capture screenshots.[8]

EnterpriseT1053.005Scheduled TaskSub-technique

PlugX has created a scheduled task to execute additional malicious software, as well as maintain persistence.[7]

EnterpriseT1573.001Symmetric CryptographySub-technique

PlugX can use RC4 encryption in C2 communications.[7][11]

EnterpriseT1571Non-Standard Port

PlugX has used random, high-number, non-standard ports to listen for subsequent actions and C2 activities.[5]

EnterpriseT1027.007Dynamic API ResolutionSub-technique

PlugX has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API.[7]

EnterpriseT1140Deobfuscate/Decode Files or Information

PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer.[8][21][11] PlugX has also decrypted its payloads in memory.[7][10][16][6]

EnterpriseT1564.003Hidden WindowSub-technique

PlugX has the ability to execute a command on a hidden desktop.[7]

EnterpriseT1120Peripheral Device Discovery

PlugX can identify removable media attached to compromised hosts.[9]

EnterpriseT1041Exfiltration Over C2 Channel

PlugX has exfiltrated stolen data and files to its C2 server.[9][24]

EnterpriseT1106Native API

PlugX can use the Windows API functions `GetProcAddress`, `LoadLibrary`, and `CreateProcess` to execute another process.[7][11][1]

EnterpriseT1027Obfuscated Files or Information

PlugX can use API hashing and modify the names of strings to evade detection.[21][11]

EnterpriseT1033System Owner/User Discovery

PlugX has the ability to gather the username from the victim’s machine.[7]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

PlugX has leveraged XOR encryption with the key of 123456789.[7]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G1047: Velvet Ant

Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.[1][2]

GroupEnterprise

G1034: Daggerfly

Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa. Daggerfly is associated with exclusive use of MgBot malware and is noted for several potential supply chain infection campaigns.[1][2][3][4]

GroupEnterprise

G0096: APT41

APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries.[1] Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.[2][3]

GroupEnterprise

G0022: APT3

APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security.[1][2] This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap.[1][3] As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.[4]

GroupEnterprise

G0126: Higaisa

Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.[1][2][3]

GroupEnterprise

G0027: Threat Group-3390

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.[1] The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.[2][3][4]

GroupEnterprise

G1021: Cinnamon Tempest

Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.[1][2][3][4]

GroupEnterprise

G0093: GALLIUM

GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers.[1] Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.[1][2][3]

GroupEnterprise

G0001: Axiom

Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008. Some reporting suggests a degree of overlap between Axiom and Winnti Group but the two groups appear to be distinct based on differences in reporting on TTPs and targeting.[1][2][3]

GroupEnterprise

G0045: menuPass

menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company.[1][2]

menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.[3][4][5][6][7][1][2]

GroupEnterprise

G0062: TA459

TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others. [1]

GroupEnterprise

G1014: LuminousMoth

LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted high-profile organizations, including government entities, in Myanmar, the Philippines, Thailand, and other parts of Southeast Asia. Some security researchers have concluded there is a connection between LuminousMoth and Mustang Panda based on similar targeting and TTPs, as well as network infrastructure overlaps.[1][2]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.3
Created
Modified
Raw hash
f9df34816b05c89f...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.13.3Current bundlef9df34816b05…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Lastline PlugX Analysis

    Vasilenko, R. (2013, December 17). An Analysis of PlugX Malware. Retrieved November 24, 2015.

    Open source URL
  2. [2]
    FireEye Clandestine Fox Part 2

    Scott, M.. (2014, June 10). Clandestine Fox, Part Deux. Retrieved January 14, 2016.

    Open source URL
  3. [3]
    New DragonOK

    Miller-Osborn, J., Grunzweig, J.. (2015, April). Unit 42 Identifies New DragonOK Backdoor Malware Deployed Against Japanese Targets. Retrieved November 4, 2015.

  4. [4]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  5. [5]
    Sygnia VelvetAnt 2024A

    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

    Open source URL
  6. [6]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  7. [7]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  8. [8]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  9. [9]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  10. [10]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  11. [11]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  12. [12]
    FireEye APT10 April 2017

    FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.

    Open source URL
  13. [13]
    Symantec Daggerfly 2023

    Threat Hunter Team. (2023, April 20). Daggerfly: APT Actor Targets Telecoms Company in Africa. Retrieved July 25, 2024.

    Open source URL
  14. [14]
    apt41_mandiant

    Mandiant. (n.d.). APT41, A DUAL ESPIONAGE AND CYBER CRIME OPERATION. Retrieved June 11, 2024.

    Open source URL
  15. [15]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  16. [16]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  17. [17]
    Palo Alto PlugX June 2017

    Lancaster, T. and Idrizovic, E.. (2017, June 27). Paranoid PlugX. Retrieved July 13, 2017.

    Open source URL
  18. [18]
    Malwarebytes Higaisa 2020

    Malwarebytes Threat Intelligence Team. (2020, June 4). New LNK attack tied to Higaisa APT discovered. Retrieved March 2, 2021.

    Open source URL
  19. [19]
    SecureWorks BRONZE UNION June 2017

    Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017.

    Open source URL
  20. [20]
    Nccgroup Emissary Panda May 2018

    Pantazopoulos, N., Henry T. (2018, May 18). Emissary Panda – A potential new malicious tool. Retrieved June 25, 2018.

    Open source URL
  21. [21]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  22. [22]
    Profero APT27 December 2020

    Global Threat Center, Intelligence Team. (2020, December). APT27 Turns to Ransomware. Retrieved November 12, 2021.

    Open source URL
  23. [23]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  24. [24]
    Sophos PlugX September 2022

    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.

    Open source URL
  25. [25]
    Dell SecureWorks BRONZE STARLIGHT Profile

    SecureWorks. (n.d.). BRONZE STARLIGHT. Retrieved December 6, 2023.

    Open source URL
  26. [26]
    Stewart 2014

    Stewart, A. (2014). DLL SIDE-LOADING: A Thorn in the Side of the Anti-Virus Industry. Retrieved November 12, 2014.

    Open source URL
  27. [27]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  28. [28]
    Cybereason Soft Cell June 2019

    Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019.

    Open source URL
  29. [29]
    Cisco Group 72

    Esler, J., Lee, M., and Williams, C. (2014, October 14). Threat Spotlight: Group 72. Retrieved January 14, 2016.

  30. [30]
    Novetta-Axiom

    Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.

    Open source URL
  31. [31]
    DOJ APT10 Dec 2018

    United States District Court Southern District of New York (USDC SDNY) . (2018, December 17). United States of America v. Zhu Hua and Zhang Shilong. Retrieved April 17, 2019.

    Open source URL
  32. [32]
    Proofpoint TA459 April 2017

    Axel F. (2017, April 27). APT Targets Financial Analysts with CVE-2017-0199. Retrieved February 15, 2018.

    Open source URL
  33. [33]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  34. [34]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  35. [35]
    Proofpoint ZeroT Feb 2017

    Huss, D., et al. (2017, February 2). Oops, they did it again: APT Targets Russia and Belarus with ZeroT and PlugX. Retrieved April 5, 2018.

    Open source URL
  36. [36]
    Unit42 PlugX June 2017

    Lancaster, T., Idrizovic, E. (2017, June 27). Paranoid PlugX. Retrieved April 19, 2019.

    Open source URL
  37. [37]
    Recorded Future RedDelta 2025

    Insikt Group. (2025, January 9). Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain. Retrieved January 14, 2025.

    Open source URL
  38. [38]
    Kaspersky Winnti April 2013

    Kaspersky Lab's Global Research and Analysis Team. (2013, April 11). Winnti. More than just a game. Retrieved February 8, 2017.

    Open source URL
  39. [39]
    Anomali MUSTANG PANDA October 2019

    Anomali Threat Research. (2019, October 7). China-Based APT Mustang Panda Targets Minority Groups, Public and Private Sector Organizations. Retrieved April 12, 2021.

    Open source URL
  40. [40]
    Secureworks BRONZE PRESIDENT December 2019

    Counter Threat Unit Research Team. (2019, December 29). BRONZE PRESIDENT Targets NGOs. Retrieved April 13, 2021.

    Open source URL
  41. [41]
    Avira Mustang Panda January 2020

    Hamzeloofard, S. (2020, January 31). New wave of PlugX targets Hong Kong | Avira Blog. Retrieved April 13, 2021.

    Open source URL
  42. [42]
    Recorded Future REDDELTA July 2020

    Insikt Group. (2020, July 28). CHINESE STATE-SPONSORED GROUP ‘REDDELTA’ TARGETS THE VATICAN AND CATHOLIC ORGANIZATIONS. Retrieved April 13, 2021.

    Open source URL
  43. [43]
    Crowdstrike MUSTANG PANDA June 2018

    Meyers, A. (2018, June 15). Meet CrowdStrike’s Adversary of the Month for June: MUSTANG PANDA. Retrieved April 12, 2021.

    Open source URL
  44. [44]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  45. [45]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  46. [46]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  47. [47]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  48. [48]
    DestroyRAT

    (Citation: CIRCL PlugX March 2013)

  49. [49]
    DestroyRAT

    (Citation: CIRCL PlugX March 2013)

  50. [50]
    DestroyRAT

    (Citation: CIRCL PlugX March 2013)

  51. [51]
    FireEye Clandestine Fox Part 2

    Scott, M.. (2014, June 10). Clandestine Fox, Part Deux. Retrieved January 14, 2016.

    Open source URL
  52. [52]
    FireEye Clandestine Fox Part 2

    Scott, M.. (2014, June 10). Clandestine Fox, Part Deux. Retrieved January 14, 2016.

    Open source URL
  53. [53]
    Kaba

    (Citation: FireEye Clandestine Fox Part 2)

  54. [54]
    Kaba

    (Citation: FireEye Clandestine Fox Part 2)

  55. [55]
    Kaba

    (Citation: FireEye Clandestine Fox Part 2)

  56. [56]
    Korplug

    (Citation: Lastline PlugX Analysis)(Citation: CIRCL PlugX March 2013)

  57. [57]
    Korplug

    (Citation: Lastline PlugX Analysis)(Citation: CIRCL PlugX March 2013)

  58. [58]
    Korplug

    (Citation: Lastline PlugX Analysis)(Citation: CIRCL PlugX March 2013)

  59. [59]
    Lastline PlugX Analysis

    Vasilenko, R. (2013, December 17). An Analysis of PlugX Malware. Retrieved November 24, 2015.

    Open source URL
  60. [60]
    Lastline PlugX Analysis

    Vasilenko, R. (2013, December 17). An Analysis of PlugX Malware. Retrieved November 24, 2015.

    Open source URL
  61. [61]
    New DragonOK

    Miller-Osborn, J., Grunzweig, J.. (2015, April). Unit 42 Identifies New DragonOK Backdoor Malware Deployed Against Japanese Targets. Retrieved November 4, 2015.

  62. [62]
    New DragonOK

    Miller-Osborn, J., Grunzweig, J.. (2015, April). Unit 42 Identifies New DragonOK Backdoor Malware Deployed Against Japanese Targets. Retrieved November 4, 2015.

  63. [63]
    Novetta-Axiom

    Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.

    Open source URL
  64. [64]
    Novetta-Axiom

    Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.

    Open source URL
  65. [65]
    PlugX

    (Citation: Lastline PlugX Analysis) (Citation: FireEye Clandestine Fox Part 2)(Citation: CIRCL PlugX March 2013)

  66. [66]
    PlugX

    (Citation: Lastline PlugX Analysis) (Citation: FireEye Clandestine Fox Part 2)(Citation: CIRCL PlugX March 2013)

  67. [67]
    PlugX

    (Citation: Lastline PlugX Analysis) (Citation: FireEye Clandestine Fox Part 2)(Citation: CIRCL PlugX March 2013)

  68. [68]
    Sogu

    (Citation: Lastline PlugX Analysis)(Citation: FireEye Clandestine Fox Part 2)(Citation: CIRCL PlugX March 2013)

  69. [69]
    Sogu

    (Citation: Lastline PlugX Analysis)(Citation: FireEye Clandestine Fox Part 2)(Citation: CIRCL PlugX March 2013)

  70. [70]
    Sogu

    (Citation: Lastline PlugX Analysis)(Citation: FireEye Clandestine Fox Part 2)(Citation: CIRCL PlugX March 2013)

  71. [71]
    TVT

    (Citation: Novetta-Axiom)

  72. [72]
    TVT

    (Citation: Novetta-Axiom)

  73. [73]
    TVT

    (Citation: Novetta-Axiom)

  74. [74]
    Thoper

    (Citation: Novetta-Axiom)

  75. [75]
    Thoper

    (Citation: Novetta-Axiom)

  76. [76]
    Thoper

    (Citation: Novetta-Axiom)

  77. [77]
    mitre-attackS0013
    Open source URL
  78. [78]
    mitre-attackS0013
    Open source URL
  79. [79]
    mitre-attackS0013
    Open source URL
  80. [80]
    Sygnia VelvetAnt 2024A

    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

    Open source URL
  81. [81]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  82. [82]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  83. [83]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  84. [84]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  85. [85]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  86. [86]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  87. [87]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  88. [88]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  89. [89]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  90. [90]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  91. [91]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  92. [92]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  93. [93]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  94. [94]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  95. [95]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  96. [96]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  97. [97]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  98. [98]
    FireEye APT10 April 2017

    FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.

    Open source URL
  99. [99]
    Symantec Daggerfly 2023

    Threat Hunter Team. (2023, April 20). Daggerfly: APT Actor Targets Telecoms Company in Africa. Retrieved July 25, 2024.

    Open source URL
  100. [100]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  101. [101]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  102. [102]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  103. [103]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  104. [104]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  105. [105]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  106. [106]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  107. [107]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  108. [108]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  109. [109]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  110. [110]
    FireEye APT41 Aug 2019

    Fraser, N., et al. (2019, August 7). Double DragonAPT41, a dual espionage and cyber crime operation APT41. Retrieved September 23, 2019.

    Open source URL
  111. [111]
    apt41_mandiant

    Mandiant. (n.d.). APT41, A DUAL ESPIONAGE AND CYBER CRIME OPERATION. Retrieved June 11, 2024.

    Open source URL
  112. [112]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  113. [113]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  114. [114]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  115. [115]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  116. [116]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  117. [117]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  118. [118]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  119. [119]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  120. [120]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  121. [121]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  122. [122]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  123. [123]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  124. [124]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  125. [125]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  126. [126]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  127. [127]
    FireEye Clandestine Fox Part 2

    Scott, M.. (2014, June 10). Clandestine Fox, Part Deux. Retrieved January 14, 2016.

    Open source URL
  128. [128]
    FireEye Clandestine Fox Part 2

    Scott, M.. (2014, June 10). Clandestine Fox, Part Deux. Retrieved January 14, 2016.

    Open source URL
  129. [129]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  130. [130]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  131. [131]
    Palo Alto PlugX June 2017

    Lancaster, T. and Idrizovic, E.. (2017, June 27). Paranoid PlugX. Retrieved July 13, 2017.

    Open source URL
  132. [132]
    Malwarebytes Higaisa 2020

    Malwarebytes Threat Intelligence Team. (2020, June 4). New LNK attack tied to Higaisa APT discovered. Retrieved March 2, 2021.

    Open source URL
  133. [133]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  134. [134]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  135. [135]
    Nccgroup Emissary Panda May 2018

    Pantazopoulos, N., Henry T. (2018, May 18). Emissary Panda – A potential new malicious tool. Retrieved June 25, 2018.

    Open source URL
  136. [136]
    Profero APT27 December 2020

    Global Threat Center, Intelligence Team. (2020, December). APT27 Turns to Ransomware. Retrieved November 12, 2021.

    Open source URL
  137. [137]
    SecureWorks BRONZE UNION June 2017

    Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017.

    Open source URL
  138. [138]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  139. [139]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  140. [140]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  141. [141]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  142. [142]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  143. [143]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  144. [144]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  145. [145]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  146. [146]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  147. [147]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  148. [148]
    Sophos PlugX September 2022

    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.

    Open source URL
  149. [149]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  150. [150]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  151. [151]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  152. [152]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  153. [153]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  154. [154]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  155. [155]
    Lastline PlugX Analysis

    Vasilenko, R. (2013, December 17). An Analysis of PlugX Malware. Retrieved November 24, 2015.

    Open source URL
  156. [156]
    Lastline PlugX Analysis

    Vasilenko, R. (2013, December 17). An Analysis of PlugX Malware. Retrieved November 24, 2015.

    Open source URL
  157. [157]
    Dell SecureWorks BRONZE STARLIGHT Profile

    SecureWorks. (n.d.). BRONZE STARLIGHT. Retrieved December 6, 2023.

    Open source URL
  158. [158]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  159. [159]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  160. [160]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  161. [161]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  162. [162]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  163. [163]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  164. [164]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  165. [165]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  166. [166]
    FireEye Clandestine Fox Part 2

    Scott, M.. (2014, June 10). Clandestine Fox, Part Deux. Retrieved January 14, 2016.

    Open source URL
  167. [167]
    FireEye Clandestine Fox Part 2

    Scott, M.. (2014, June 10). Clandestine Fox, Part Deux. Retrieved January 14, 2016.

    Open source URL
  168. [168]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  169. [169]
    Palo Alto PlugX June 2017

    Lancaster, T. and Idrizovic, E.. (2017, June 27). Paranoid PlugX. Retrieved July 13, 2017.

    Open source URL
  170. [170]
    Palo Alto PlugX June 2017

    Lancaster, T. and Idrizovic, E.. (2017, June 27). Paranoid PlugX. Retrieved July 13, 2017.

    Open source URL
  171. [171]
    Profero APT27 December 2020

    Global Threat Center, Intelligence Team. (2020, December). APT27 Turns to Ransomware. Retrieved November 12, 2021.

    Open source URL
  172. [172]
    Profero APT27 December 2020

    Global Threat Center, Intelligence Team. (2020, December). APT27 Turns to Ransomware. Retrieved November 12, 2021.

    Open source URL
  173. [173]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  174. [174]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  175. [175]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  176. [176]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  177. [177]
    Sophos PlugX September 2022

    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.

    Open source URL
  178. [178]
    Sophos PlugX September 2022

    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.

    Open source URL
  179. [179]
    Stewart 2014

    Stewart, A. (2014). DLL SIDE-LOADING: A Thorn in the Side of the Anti-Virus Industry. Retrieved November 12, 2014.

    Open source URL
  180. [180]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  181. [181]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  182. [182]
    Cybereason Soft Cell June 2019

    Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019.

    Open source URL
  183. [183]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  184. [184]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  185. [185]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  186. [186]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  187. [187]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  188. [188]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  189. [189]
    Cisco Group 72

    Esler, J., Lee, M., and Williams, C. (2014, October 14). Threat Spotlight: Group 72. Retrieved January 14, 2016.

  190. [190]
    Novetta-Axiom

    Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.

    Open source URL
  191. [191]
    Novetta-Axiom

    Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.

    Open source URL
  192. [192]
    Palo Alto PlugX June 2017

    Lancaster, T. and Idrizovic, E.. (2017, June 27). Paranoid PlugX. Retrieved July 13, 2017.

    Open source URL
  193. [193]
    Palo Alto PlugX June 2017

    Lancaster, T. and Idrizovic, E.. (2017, June 27). Paranoid PlugX. Retrieved July 13, 2017.

    Open source URL
  194. [194]
    DOJ APT10 Dec 2018

    United States District Court Southern District of New York (USDC SDNY) . (2018, December 17). United States of America v. Zhu Hua and Zhang Shilong. Retrieved April 17, 2019.

    Open source URL
  195. [195]
    FireEye APT10 April 2017

    FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.

    Open source URL
  196. [196]
    FireEye APT10 April 2017

    FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.

    Open source URL
  197. [197]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  198. [198]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  199. [199]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  200. [200]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  201. [201]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  202. [202]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  203. [203]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  204. [204]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  205. [205]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  206. [206]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  207. [207]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  208. [208]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  209. [209]
    Proofpoint TA459 April 2017

    Axel F. (2017, April 27). APT Targets Financial Analysts with CVE-2017-0199. Retrieved February 15, 2018.

    Open source URL
  210. [210]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  211. [211]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  212. [212]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  213. [213]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  214. [214]
    FireEye APT10 April 2017

    FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.

    Open source URL
  215. [215]
    FireEye APT10 April 2017

    FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.

    Open source URL
  216. [216]
    Lastline PlugX Analysis

    Vasilenko, R. (2013, December 17). An Analysis of PlugX Malware. Retrieved November 24, 2015.

    Open source URL
  217. [217]
    Lastline PlugX Analysis

    Vasilenko, R. (2013, December 17). An Analysis of PlugX Malware. Retrieved November 24, 2015.

    Open source URL
  218. [218]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  219. [219]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  220. [220]
    Proofpoint ZeroT Feb 2017

    Huss, D., et al. (2017, February 2). Oops, they did it again: APT Targets Russia and Belarus with ZeroT and PlugX. Retrieved April 5, 2018.

    Open source URL
  221. [221]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  222. [222]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  223. [223]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  224. [224]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  225. [225]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  226. [226]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  227. [227]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  228. [228]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  229. [229]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  230. [230]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  231. [231]
    Sophos PlugX September 2022

    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.

    Open source URL
  232. [232]
    Sophos PlugX September 2022

    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.

    Open source URL
  233. [233]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  234. [234]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  235. [235]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  236. [236]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  237. [237]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  238. [238]
    Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

    Open source URL
  239. [239]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  240. [240]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  241. [241]
    Sygnia VelvetAnt 2024A

    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

    Open source URL
  242. [242]
    Sygnia VelvetAnt 2024A

    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

    Open source URL
  243. [243]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  244. [244]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  245. [245]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  246. [246]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  247. [247]
    Unit42 PlugX June 2017

    Lancaster, T., Idrizovic, E. (2017, June 27). Paranoid PlugX. Retrieved April 19, 2019.

    Open source URL
  248. [248]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  249. [249]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  250. [250]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  251. [251]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  252. [252]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  253. [253]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  254. [254]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  255. [255]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  256. [256]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  257. [257]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  258. [258]
    Sophos PlugX September 2022

    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.

    Open source URL
  259. [259]
    Sophos PlugX September 2022

    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.

    Open source URL
  260. [260]
    Recorded Future RedDelta 2025

    Insikt Group. (2025, January 9). Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain. Retrieved January 14, 2025.

    Open source URL
  261. [261]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  262. [262]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  263. [263]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  264. [264]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  265. [265]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  266. [266]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  267. [267]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  268. [268]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  269. [269]
    Lastline PlugX Analysis

    Vasilenko, R. (2013, December 17). An Analysis of PlugX Malware. Retrieved November 24, 2015.

    Open source URL
  270. [270]
    Lastline PlugX Analysis

    Vasilenko, R. (2013, December 17). An Analysis of PlugX Malware. Retrieved November 24, 2015.

    Open source URL
  271. [271]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  272. [272]
    PWC Cloud Hopper Technical Annex April 2017

    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

    Open source URL
  273. [273]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  274. [274]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  275. [275]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  276. [276]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  277. [277]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  278. [278]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  279. [279]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  280. [280]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  281. [281]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  282. [282]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  283. [283]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  284. [284]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  285. [285]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  286. [286]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  287. [287]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  288. [288]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  289. [289]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  290. [290]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  291. [291]
    Sygnia VelvetAnt 2024A

    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

    Open source URL
  292. [292]
    Sygnia VelvetAnt 2024A

    Sygnia Team. (2024, June 3). China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence. Retrieved March 14, 2025.

    Open source URL
  293. [293]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  294. [294]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  295. [295]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  296. [296]
    CIRCL PlugX March 2013

    Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

  297. [297]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  298. [298]
    Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

    Open source URL
  299. [299]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  300. [300]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  301. [301]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  302. [302]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  303. [303]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  304. [304]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  305. [305]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  306. [306]
    Sophos Mustang Panda PLUGX

    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.

    Open source URL
  307. [307]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  308. [308]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  309. [309]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  310. [310]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  311. [311]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  312. [312]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  313. [313]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  314. [314]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  315. [315]
    Sophos PlugX September 2022

    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.

    Open source URL
  316. [316]
    Sophos PlugX September 2022

    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.

    Open source URL
  317. [317]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  318. [318]
    Lastline PlugX Analysis

    Vasilenko, R. (2013, December 17). An Analysis of PlugX Malware. Retrieved November 24, 2015.

    Open source URL
  319. [319]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  320. [320]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  321. [321]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  322. [322]
    New DragonOK

    Miller-Osborn, J., Grunzweig, J.. (2015, April). Unit 42 Identifies New DragonOK Backdoor Malware Deployed Against Japanese Targets. Retrieved November 4, 2015.

  323. [323]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  324. [324]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  325. [325]
    EclecticIQ Mustang Panda PlugX

    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.

    Open source URL
  326. [326]
    Eset PlugX Korplug Mustang Panda March 2022

    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

    Open source URL
  327. [327]
    Proofpoint TA416 Europe March 2022

    Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.

    Open source URL
  328. [328]
    Sophos PlugX September 2022

    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.