Skip to content

Malware

POISONPLUG

aka Barlaiy

According to FireEye, POISONPLUG is a highly obfuscated modular backdoor with plug-in capabilities.

POISONPLUG, also known as Barlaiy, is a Windows malware family operated by APT41.

Background

FireEye characterizes POISONPLUG as a heavily obfuscated, modular backdoor that supports plug-ins. It can persist via the registry or as a service, remove itself, run plug-ins, and forward network connections. Analysts have also seen POISONPLUG abuse social platforms to host encoded C&C commands.


Source: Malpedia (Fraunhofer FKIE).