Malware
POISONPLUG
aka Barlaiy
According to FireEye, POISONPLUG is a highly obfuscated modular backdoor with plug-in capabilities.
POISONPLUG, also known as Barlaiy, is a Windows malware family operated by APT41.
Background
FireEye characterizes POISONPLUG as a heavily obfuscated, modular backdoor that supports plug-ins. It can persist via the registry or as a service, remove itself, run plug-ins, and forward network connections. Analysts have also seen POISONPLUG abuse social platforms to host encoded C&C commands.
Source: Malpedia (Fraunhofer FKIE).