CARDS
CARDS
CISA documented multi-victim intrusions in which stolen local and domain administrator credentials, certificates, impersonation, and trusted IT-service-provider relationships were primary access mechanisms. PLUGX/SOGU was used as a secondary remote-access implant on relay and staging systems through a legitimate executable, malicious DLL, and encoded payload that decoded in memory.
Last updated Aug 06, 2026, 12:00 PM EDT
Evidence Boundary
Bottom Line Up Front
CISA documented multi-victim intrusions in which stolen local and domain administrator credentials, certificates, impersonation, and trusted IT-service-provider relationships were primary access mechanisms. PLUGX/SOGU was used as a secondary remote-access implant on relay and staging systems through a legitimate executable, malicious DLL, and encoded payload that decoded in memory.[1][2][3][4][5][6][7]
Compromise of privileged identities or provider trust can extend access from one organization into downstream client environments. The implant supports remote command execution, discovery, credential access, file operations, and data staging; those capabilities are not proof they were all used in a specific incident.[1][2][3][4][5][6][7]
1. Preserve identity, VPN, remote-access, certificate, endpoint, DNS, proxy, firewall, and service-provider logs. 2. Identify the first anomalous privileged sign-in and every system or client tenant it reached. 3. Hunt for the three-file side-loading triad: legitimate executable, unexpected adjacent DLL, and encoded payload. 4. Capture memory before rebuilding suspected hosts because the decoded implant may be memory-resident. 5. Prove compromise by correlating unauthorized authentication or provider access with loader execution, memory or network evidence, or implant persistence. 6. Isolate confirmed systems, revoke sessions and certificates, rotate credentials, remove persistence, rebuild from trusted media, and validate downstream tenants separately.[1][2][3][4][5][6][7]
Decision Summary
CISA documented multi-victim intrusions in which stolen local and domain administrator credentials, certificates, impersonation, and trusted IT-service-provider relationships were primary access mechanisms. PLUGX/SOGU was used as a secondary remote-access implant on relay and staging systems through a legitimate executable, malicious DLL, and encoded payload that decoded in memory.
The retained record scopes this as credential- and trusted-relationship-led espionage / windows remote access activity during May 2016 to April 2017. Compromise of privileged identities or provider trust can extend access from one organization into downstream client environments. The implant supports remote command execution, discovery, credential access, file operations, and data staging; those capabilities are not proof they were all used in a specific incident.[1][2][3][4][5][6][7]
1. Preserve identity, VPN, remote-access, certificate, endpoint, DNS, proxy, firewall, and service-provider logs. 2. Identify the first anomalous privileged sign-in and every system or client tenant it reached. 3. Hunt for the three-file side-loading triad: legitimate executable, unexpected adjacent DLL, and encoded payload. 4. Capture memory before rebuilding suspected hosts because the decoded implant may be memory-resident. 5. Prove compromise by correlating unauthorized authentication or provider access with loader execution, memory or network evidence, or implant persistence. 6. Isolate confirmed systems, revoke sessions and certificates, rotate credentials, remove persistence, rebuild from trusted media, and validate downstream tenants separately.[1][2][3][4][5][6][7]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for the CISA-observed access and implant mechanics. APT10 association is historical context and is not exclusive attribution for every PlugX/SOGU intrusion..[1][2][3][4][5][6][7]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Campaign Chronology
2014–2015
Malicious Office documents exploiting CVE-2012-0158 delivered a Samsung-based three-file PlugX loader chain.
May 2016–April 2017
CISA observed credential, certificate, impersonation, and provider-trust access with PLUGX/SOGU on relay and staging systems.
December 2018
DOJ charged two alleged APT10 members and described MSP and technology-theft campaigns; allegations are historical attribution context.
2019–2020
Symantec documented Japan-linked activity and a tool capable of exploiting CVE-2020-1472; this is not proof of SOGU delivery.
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
PlugX is used by multiple operators. CVE-2012-0158 is tied to specific Unit 42 delivery samples; CVE-2013-3906 is historical shared-infrastructure context only; CVE-2020-1472 appeared in a separate APT10/Cicada campaign and is not an inherent SOGU vulnerability.
Evidence Controls
IntelliOS
Citations