Skip to content

Malware

PlugX

aka Destroy RAT · Kaba · Korplug · Sogu · TIGERPLUG · RedDelta

RSA describes PlugX as a RAT (Remote Access Trojan) malware family that is around since 2008 and is used as a backdoor to control the victim's machine fully.

PlugX, also known as Destroy RAT, Kaba, Korplug, Sogu, is a Windows malware family operated by APT 22, APT 26 and others.

Background

Per RSA, PlugX is a RAT (Remote Access Trojan) family that has existed since 2008 and serves as a backdoor granting full control over a victim's machine. After infection, an operator can remotely issue a variety of commands on the compromised system.

Among its key capabilities, PlugX can run commands on the affected machine to: gather machine information capture the screen send keyboard and mouse events perform keylogging reboot the system manage processes (create, kill and enumerate) manage services (create, start, stop, etc.); and manage Windows registry entries, open a shell, etc.

It additionally records its activity in a text log file.


Source: Malpedia (Fraunhofer FKIE).