IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AIFlash Threat Intel Brief

SOGU Remote Access Malware

PlugX-Family Tradecraft, DLL Side-Loading, Persistent Access, and Espionage Risk

Windows backdoorDLL side-loadingSource-bound attribution
Published
Aug 6, 2026
Brief Version
v1.7
Updated
Aug 6, 2026
AI Monitor
CARDS malware and actor review queue
Brief ID
PANDA-FTIB-SOGU-2026-001
Template
Flash Threat Brief v2.0
  • The strongest SOGU-specific access evidence is credential and trust abuse: In CISA's observed campaign, stolen local and domain administrator credentials, certificates, user impersonation, and access through IT service providers were the primary mechanisms. The implant was used to maintain persistence and additional access on relay and staging systems.1
  • Other delivery paths are real but sample-specific: Primary vendor cases document malicious Office documents exploiting CVE-2012-0158, spear-phishing documents, post-compromise component download, and removable-media LNK execution. Use them as scoped hunt hypotheses, not as one universal SOGU entry chain.9, 10, 11
  • Preserve evidence before isolation or cleanup: Collect memory, processes, loaded modules, handles, sockets, services, scheduled tasks, autoruns, registry hives, the three-component loader set, DNS/proxy/firewall data, authentication logs, and EDR history. Some observed implants existed only in memory and evaded then-current antivirus signatures.1, 2
  • Prove execution—not just file presence: A suspicious executable, DLL, or payload is a lead. Stronger proof includes the legitimate process loading the DLL, the DLL reading or decoding the payload, executable memory or injected code, implant configuration or modules in memory, persistence creation, or characteristic command traffic.1, 2, 9, 10
  • Treat confirmed execution as an enterprise-trust incident: The implant can provide remote shell, discovery, keylogging, screenshots, registry and service control, file operations, database access, plugin updates, and file transfer. Scope credentials, administrative paths, domain controllers, file servers, MSP infrastructure, and connected clients.1, 2, 4
  • Contain in sequence: Preserve volatile evidence first when operationally safe; then isolate the host, block confirmed command paths, revoke exposed identities, hunt related hosts, remove persistence, rebuild from trusted media where integrity is uncertain, and monitor for re-entry.1, 2
  • The 2024-2025 U.S. disruption was remote remediation of a separate USB-propagating PlugX variant: After Sekoia.io sinkholed the variant's hard-coded command server, the FBI used nine rolling warrants beginning in August 2024 to send PlugX's native self-delete command to reachable U.S. systems. DOJ reported approximately 4,258 removals when the U.S. operation ended January 3, 2025. The command stopped PlugX and removed its files, persistence registry keys, malware directory, and temporary cleanup script; the FBI said it collected no victim content and did not affect legitimate files or functions.6, 12, 13
  • Removal did not equal complete eradication: The host-only command could not clean infected USB devices, dormant media, air-gapped systems, or hosts that never contacted the sinkhole. The 4,258 figure is the DOJ-reported remediation count—not the total U.S. infection population—and reinfection remained possible. FBI/DOJ notices were routed through victims' internet service providers.6, 12, 13
  • Recent-law-enforcement boundary: A review of public FBI/DOJ records found no additional operation in the last three years that explicitly named SOGU. A separate March 2025 DOJ/FBI action alleged APT27-linked actors installed PlugX for persistence, but it did not identify that malware as SOGU and must not be merged with either the historical APT10 PLUGX/SOGU record or the Mustang Panda removal operation.1, 6, 14
  • Keep four conclusions separate: Artifact presence, execution, malware-family identification, and actor attribution are different proof levels. A PlugX-family finding does not by itself prove APT10, a government sponsor, a particular CVE, a named victim, or data exfiltration.1, 2, 3, 4, 6

Research and scoping note

The response priority is evidence preservation plus identity and trust recovery—not a filename block. If the suspected system administered other systems or customer environments, assume the scoping boundary extends to every reachable trust path until authentication, network, and endpoint evidence narrows it.1, 4

SOGU appears in CISA reporting as part of the combined PLUGX/SOGU label. For incident response, it should be treated as source-specific PlugX-related nomenclature unless sample analysis establishes a narrower family distinction. MITRE maintains PlugX as a modular Windows backdoor used by multiple groups, which makes the name useful for capability and detection context but insufficient for actor attribution.1, 2

Initial access is not one fixed malware feature. In CISA's multi-victim campaign, the primary mechanisms were stolen local and domain administrator credentials, stolen certificates, user impersonation, and access through compromised IT service providers. The implant was then left on critical relay and staging systems to preserve or expand access. Other primary cases show malicious Office documents and exploits, spear-phishing documents, post-compromise downloads, and removable-media execution; each belongs to its specific sample or campaign until local evidence connects it.1, 9, 10, 11

The most reliable technical model is the three-component loader: a legitimate executable, a malicious DLL named or placed so the executable loads it, and an encoded or encrypted payload. The DLL reads, decodes, decrypts, or decompresses the payload and runs the implant in memory. Trusted signatures on the executable do not make the directory or loaded DLL trustworthy, and the decoded implant may never be written to disk.1, 2, 7, 9, 10

Responders should use a graduated proof standard. Artifact presence means the components exist. Execution is supported when telemetry shows the legitimate process loading the malicious DLL, the DLL reading the payload, decoded executable memory, injection, persistence creation, or command traffic. Family identification requires compatible code, configuration, modules, memory structures, protocol behavior, or authoritative sample analysis. Actor attribution requires additional infrastructure, victimology, delivery, timing, companion tooling, and intelligence evidence.1, 2, 3, 6, 9, 10

A confirmed implant can provide remote shell access, system, process, file, network, and database discovery; keylogging; screenshots; service and registry control; file transfer; port mapping; and runtime plugin changes. The investigation must determine which modules were present, which operator commands ran, and whether the host reached credentials, domain controllers, file servers, management systems, customer networks, or sensitive data.1, 2

Before destructive containment, collect volatile evidence when operationally safe: physical or logical memory, process and thread state, loaded modules, handles, sockets, injected regions, command lines, active logons, and implant configuration. Also preserve the executable/DLL/payload set, signatures and hashes, full paths and timestamps, services, tasks, autoruns, registry hives, prefetch and execution artifacts, EDR history, DNS, proxy, firewall, NetFlow or packet capture, VPN, identity, SMB, RDP, WMI, and file-access evidence.1, 2, 9, 10

The playbook proceeds in gates: preserve evidence; validate access hypotheses and execution; isolate affected hosts; block confirmed command paths; identify and revoke exposed credentials and certificates; hunt for the loader set, persistence, command traffic, administrative-share use, VPN mismatches, and related tooling; scope lateral movement and data activity; eradicate persistence; rebuild systems whose integrity cannot be proven; then monitor for renewed authentication or beaconing.1, 2, 4

APT10 is relevant historical context: MITRE groups menuPass, APT10, Stone Panda, Cicada, and related names under G0045, and DOJ describes global APT10 campaigns against MSPs, technology companies, and government targets. PlugX is not exclusive to that group. DOJ's 2025 removal operation concerned a Mustang Panda version, demonstrating that family identification cannot settle the operator.2, 3, 4, 6

The Mustang Panda operation began from a private-sector sinkhole, not from a newly disclosed SOGU incident. Sekoia.io acquired the abandoned hard-coded command-server address 45.142.166[.]112 in September 2023 and demonstrated that this USB-propagating variant accepted a native self-delete command. French authorities and Sekoia.io supported the FBI, which obtained nine rolling warrants from August 2024 through January 3, 2025 and remotely sent the command when eligible U.S. systems beaconed. DOJ announced the operation on January 14, 2025 and reported approximately 4,258 U.S. computers and networks remediated.6, 12, 13

The court-authorized command stopped the PlugX process; deleted malware-created files, the persistence registry keys, the malware directory, and its temporary cleanup script; and was tested not to collect content or alter legitimate functions or files. The FBI notified affected owners through their ISPs. This was targeted malware deletion, not a forensic examination of victim content, a declaration that no follow-on malware or stolen credentials remained, or proof that data had or had not been exfiltrated.6, 12

The disruption had material limits. The selected low-impact command removed PlugX from online hosts but did not clean infected USB devices; dormant removable media, air-gapped systems, and unreachable hosts could remain infected and reintroduce the worm. DOJ's 4,258 count is the reported remediation total, while the affidavit separately noted at least 45,000 U.S. IP addresses had contacted the sinkhole since September 2023. IP churn, NAT, VPNs, satellite links, and repeated beacons prevent that larger number from being treated as a device count.6, 12, 13

Public FBI/DOJ research for the last three years identified no second operation that explicitly named SOGU. The closest additional PlugX-related legal action was announced March 5, 2025: DOJ and the FBI unsealed charges and disruption measures involving PRC hacker-for-hire and APT27-linked activity in which defendants allegedly installed malware such as PlugX for persistence. That record is useful evidence of PlugX family reuse, but it is not a SOGU-specific operation and does not connect APT27, APT10, or Mustang Panda activity into one campaign.1, 6, 14

A professional conclusion should state exactly what is proven: suspicious artifact present, loader executed, implant identified, persistence confirmed, command-and-control observed, credentials exposed, lateral movement validated, data staged, or exfiltration confirmed. Do not silently convert one finding into a stronger claim about actor, CVE, victim impact, or data loss.1, 2, 3, 4

Research and scoping note

If the suspected endpoint was an administrator workstation, jump host, relay, staging server, domain controller, file server, or MSP management system, elevate severity and widen collection immediately. These systems can expose credentials and trusted routes that make downstream activity appear legitimate to ordinary monitoring.1, 4

This timeline separates malware-family history, observed campaigns, legal attribution, and later family reuse. Dates do not create automatic continuity between operators.

Date / Period
At least 2008 onward
Source-backed Event
MITRE tracks PlugX as a long-lived modular Windows backdoor used by multiple threat groups.
Why It Matters
Defenders need durable behavior detections and cannot rely on one campaign IOC set.
Boundary
Family history is not continuous actor attribution.2
Date / Period
2014-2015 samples
Source-backed Event
Unit 42 analyzed malicious Office documents that exploited CVE-2012-0158, dropped a signed Samsung executable, malicious DLL, and encrypted configuration/payload, then established service persistence.
Why It Matters
This is a concrete example of exploit-driven delivery and proof-bearing loader telemetry.
Boundary
It describes particular samples, not every SOGU infection.9
Date / Period
May 2016-Apr 2017
Source-backed Event
CISA observed a multi-victim campaign using stolen administrative credentials and certificates, provider trust, PowerShell, malware implants, memory-resident execution, and the three-component PlugX loader model.
Why It Matters
This is the strongest retained SOGU-specific access, execution, detection, and mitigation record.
Boundary
Historical campaign evidence must be reconciled with local telemetry.1
Date / Period
Dec 20, 2018
Source-backed Event
DOJ announced charges describing APT10 campaigns against MSPs, technology companies, and government agencies.
Why It Matters
Explains the provider-to-client trust path, stolen credentials, staging, and alleged data theft.
Boundary
Charges are allegations and do not attribute every PlugX-family incident.4
Date / Period
2019-2020
Source-backed Event
Trend Micro documented a spear-phishing-led cyberespionage operation that included a three-file PlugX side-loading set alongside other malware.
Why It Matters
Supports spear phishing as a campaign-specific delivery hypothesis and shared-infrastructure scoping.
Boundary
The operation used multiple backdoors and is not a SOGU-only case.11
Date / Period
2019-2020
Source-backed Event
Symantec reported a Cicada/APT10 campaign against Japan-linked organizations using DLL side-loading, credential theft, discovery, lateral movement, and staging.
Why It Matters
Provides later actor tradecraft and victimology context.
Boundary
The campaign does not prove SOGU use in every victim.5
Date / Period
2021-2023 research
Source-backed Event
Unit 42 documented a PlugX variant that used an LNK on removable media to launch a legitimate executable, side-load a malicious DLL, decrypt a payload in memory, and create a recurring scheduled task.
Why It Matters
Adds a concrete removable-media execution and persistence hypothesis.
Boundary
Only apply when USB/LNK artifacts or compatible sample behavior exists.10
Date / Period
Sep 2023
Source-backed Event
Sekoia.io acquired and sinkholed 45.142.166[.]112, the hard-coded C2 address for a USB-propagating PlugX variant associated with Mustang Panda, then validated that the implant accepted a native self-delete command.
Why It Matters
Created the technical path for sovereign, court-authorized remote remediation when infected hosts beaconed.
Boundary
Private-sector sinkhole telemetry and IP addresses do not provide a stable count of unique devices.12, 13
Date / Period
Aug 2024-Jan 3, 2025
Source-backed Event
The FBI obtained nine rolling warrants and, with French authorities and Sekoia.io, sent the native self-delete command to eligible U.S. systems contacting the sinkhole. The command stopped PlugX and removed its files, registry persistence, malware directory, and temporary cleanup script.
Why It Matters
Shows a narrowly scoped remote-remediation model that used the malware's own command channel.
Boundary
The FBI said it collected no victim content and did not affect legitimate files or functions; the action did not establish whether follow-on malware, credential theft, or exfiltration existed.6, 12, 13
Date / Period
Jan 14, 2025
Source-backed Event
DOJ publicly announced approximately 4,258 U.S. remediations and said affected owners would be notified through their ISPs.
Why It Matters
Demonstrates long-lived PlugX reuse, coordinated cleanup, and victim notification at scale.
Boundary
The total is a remediation count, not a prevalence estimate. Host deletion did not clean infected USB devices, dormant media, air-gapped systems, or unreachable hosts. This was a Mustang Panda variant, not an APT10 or SOGU continuity claim.6, 12, 13
Date / Period
Mar 5, 2025
Source-backed Event
DOJ and the FBI announced charges and disruption measures involving PRC hacker-for-hire and APT27-linked activity that allegedly installed malware such as PlugX for persistent access.
Why It Matters
Provides another recent U.S. legal record showing that PlugX use crosses actor and campaign boundaries.
Boundary
The public action did not name SOGU. Do not merge it with the APT10 PLUGX/SOGU campaign or the Mustang Panda removal operation.14

Use this as a gated playbook. Preserve volatile evidence before destructive action when operationally safe. Record who performed each step, timestamps, tools, evidence locations, hashes, and decision rationale.

Step
0 · Activate
Objective
Open a controlled investigation
Actions and Data To Collect
Assign IR lead, evidence custodian, identity owner, network owner, system owner, legal/privacy contact, and MSP/client liaison. Record alert source, host, user, time window, business role, privileges, network segment, and known management relationships.
Exit / Proof Gate
Case identifier, owners, evidence plan, containment authority, and initial severity documented.1
Step
1 · Frame access
Objective
Test initial-access hypotheses
Actions and Data To Collect
Prioritize: (A) stolen local/domain admin credentials, certificates, VPN identities, user impersonation, or provider trust—the primary CISA campaign path; (B) malicious Office document or exploit-driven dropper; (C) spear-phishing document; (D) components downloaded after another foothold; (E) USB/LNK execution. Collect email, attachment, browser/download, Office child-process, exploit, VPN, certificate, provider-remote-access, removable-media, and first-seen file telemetry.
Exit / Proof Gate
Each hypothesis marked supported, contradicted, or unresolved with evidence and confidence.1, 9, 10, 11
Step
2 · Preserve volatile
Objective
Capture evidence that can disappear
Actions and Data To Collect
Acquire memory; process, parent-child, thread, module, handle, token, socket, command-line, environment-variable, named-pipe, and injected-region state; logged-on users; active sessions; network connections; DNS cache; ARP; routing; clipboard where authorized; and implant configuration or decoded payload from memory. Note acquisition tool and hash every output.
Exit / Proof Gate
Volatile package acquired or an explicit risk-based reason for omission documented.1, 2
Step
3 · Preserve host
Objective
Reconstruct loader and persistence
Actions and Data To Collect
Collect the legitimate executable, suspicious DLL, encoded/encrypted payload, full directory, signatures, hashes, timestamps, alternate data streams, imports/exports, registry hives, services, scheduled tasks, autoruns, startup items, prefetch, Amcache, Shimcache, SRUM, event logs, EDR timeline, quarantine history, PowerShell logs, and file-system metadata. Preserve any removable-media image or LNK.
Exit / Proof Gate
Three-component set and execution/persistence artifacts preserved, or absence documented across named sources.1, 9, 10
Step
4 · Preserve identity
Objective
Map exposed trust
Actions and Data To Collect
Collect interactive, network, service, scheduled-task, VPN, RDP, SMB, WMI, and cloud sign-ins; privilege changes; certificate issuance/use; Kerberos and NTLM events; password vault access; cached or service credentials; active tokens; admin-share mounts; and client/provider authentication. Identify every credential entered, stored, cached, or reachable on the host.
Exit / Proof Gate
Credential exposure matrix links identity, privilege, system, client/tenant, evidence, and required recovery action.1, 3, 4
Step
5 · Preserve network
Objective
Identify control, movement, and transfer
Actions and Data To Collect
Collect DNS, proxy, firewall, NetFlow, packet capture, TLS metadata, VPN, DHCP, NAC, RDP, SMB, WMI, PSExec/service execution, and egress records. Test for plaintext HTTP on port 443, ports 80/8080/53, dynamic-DNS destinations, spoofed update domains, PlugX header patterns, periodic beacons, bandwidth anomalies, and first-seen destinations.
Exit / Proof Gate
Network timeline ties process and identity activity to destinations, protocol, bytes, and direction.1, 2, 9
Step
6 · Prove
Objective
Establish what exists and ran
Actions and Data To Collect
Classify evidence: Level 1 artifact presence; Level 2 loader/implant execution; Level 3 family identification; Level 4 campaign/actor attribution. Seek module-load events, DLL-to-payload reads, decoded executable memory, injection, implant configuration/modules, service/task creation, compatible YARA/code features, and protocol behavior. Require at least two independent evidence classes for a high-confidence family conclusion where practical.
Exit / Proof Gate
Finding states the highest proven level, evidence IDs, confidence, and what remains unproven.1, 2, 9, 10
Step
7 · Contain
Objective
Stop control without losing scope
Actions and Data To Collect
After critical volatile collection, isolate confirmed hosts; block confirmed malicious domains, IPs, certificates, hashes, and protocol patterns with expiration/review; disable or restrict affected provider paths; revoke active sessions; quarantine removable media; and preserve sinkhole or packet visibility where authorized. Avoid broad blocks based only on shared infrastructure or common signed executables.
Exit / Proof Gate
No active command channel or uncontrolled spread; containment scope and business exceptions documented.1, 2
Step
8 · Recover identity
Objective
Remove usable attacker trust
Actions and Data To Collect
Reset or rotate exposed user, admin, service, VPN, API, SSH, certificate, and client credentials in dependency order from clean systems; revoke tokens and sessions; remove unauthorized accounts and role changes; protect privileged users; enforce MFA; and hunt use before and after rotation.
Exit / Proof Gate
Every exposed trust item is revoked, rotated, validated, or explicitly accepted by an accountable owner.1, 4
Step
9 · Hunt enterprise
Objective
Find related hosts and downstream access
Actions and Data To Collect
Search for the exact triad and behavioral variants; unusual signed binaries in wrong directories; low-prevalence DLL loads; encoded payload files; compatible services/tasks/registry keys; memory indicators; command traffic; PowerShell/PowerSploit; admin-share mounts; VPN user/token mismatches; VPS-origin logins; RDP/WMI/SMB movement; and access to relay, staging, domain-controller, file-server, MSP, and client systems.
Exit / Proof Gate
Hunt coverage register lists data sources, time range, assets, queries, hits, gaps, and disposition.1, 2, 3, 4
Step
10 · Scope data
Objective
Prove or refute collection and loss
Actions and Data To Collect
Review file and directory enumeration, screenshots, keylogs, SQL access, archive utilities, local/remote staging, cloud or file-hosting use, outbound volume, transfer sessions, deleted archives, and sensitive repository access. Map evidence to data owner, classification, time, destination, and affected people or clients.
Exit / Proof Gate
Separate conclusions for access, collection, staging, attempted transfer, and confirmed exfiltration.1, 2, 4, 5
Step
11 · Eradicate
Objective
Remove implant and persistence
Actions and Data To Collect
Remove malicious DLLs/payloads, services, tasks, autoruns, registry-stored payloads, unauthorized tools/accounts, and companion malware. Patch only source-supported delivery flaws. Rebuild privileged or uncertain-integrity systems from trusted media; verify application allowlisting, safe directories, endpoint telemetry, segmentation, restricted egress, and remote logging.
Exit / Proof Gate
Independent validation finds no persistence, implant execution, unauthorized trust, or unaddressed delivery path.1, 2, 9, 10
Step
12 · Monitor and close
Objective
Detect re-entry and document confidence
Actions and Data To Collect
Monitor for renewed beaconing, failed or successful use of rotated identities, repeated DLL loads, restored tasks/services, new dynamic-DNS or update-themed destinations, remote administration, and data staging. Retain evidence, final timeline, affected-asset and client matrices, notification decisions, lessons learned, and unresolved gaps.
Exit / Proof Gate
Defined clean-observation period completed; closure approved by IR, identity, system owner, and legal/privacy as applicable.1, 2, 4

Concrete indicators are grouped by their exact source and variant. Defang network values for publication; normalize them only inside approved security tooling. A match is a hunt lead, not automatic proof of execution or attribution. Validate current IP/domain ownership, file role, path, signature, and surrounding telemetry before blocking or declaring compromise.

IOC Type
IPv4 · C2 / sinkhole
Specific Indicator(s)
45.142.166[.]112
Source / Hunt Context
Hard-coded C2 for the USB-propagating Mustang Panda PlugX variant. Sekoia.io acquired and sinkholed it in September 2023; the FBI/French operation used it to deliver the native self-delete command.
Lifecycle / Boundary
Sinkholed / remediation infrastructure after September 2023. Historical contact remains high-value evidence; do not describe the current address as attacker-controlled without revalidation.6, 12, 13
IOC Type
IPv4 · Related
Specific Indicator(s)
45.251.240[.]55; 103.56.53[.]46; 43.254.217[.]165
Source / Hunt Context
Published by Sekoia.io with the separate Mustang Panda-associated PlugX worm IOC set.
Lifecycle / Boundary
Variant-specific and historical. 103.56.53[.]46 appeared sinkholed when researched. Validate current ownership and traffic context before blocking.13
IOC Type
Domain · C2
Specific Indicator(s)
windowsupdates.dnset[.]com
Source / Hunt Context
CISA's 2017 PLUGX/SOGU record includes sample implant communication to this spoofed update-themed domain.
Lifecycle / Boundary
Historical SOGU-specific campaign observable. Recheck present resolution, ownership, and passive-DNS history before control action.1
IOC Type
Domains · C2
Specific Indicator(s)
capser.zues[.]info; casper.bacguarp[.]com; auto.bacguarp[.]com; fas2t.bacguarp[.]com; fast.bacguarp[.]com; fast2.bacguarp[.]com; ftp.bacguarp[.]com; istore.bacguarp[.]com; line.bacguarp[.]com; rfa.bacguarp[.]com; scqf.bacguarp[.]com; ser.bacguarp[.]com; web.bacguarp[.]com; www1.bacguarp[.]com
Source / Hunt Context
Unit 42 Samsung RunHelp / ssMUIDLL PlugX configurations and related historical infrastructure.
Lifecycle / Boundary
2014-2015 sample-specific infrastructure; not a universal SOGU list. Validate present ownership and avoid retroactive actor merging.9
IOC Type
SHA-256 · Malware
Specific Indicator(s)
432a07eb49473fa8c71d50ccaf2bc980b692d458ec4aaedd52d739cb377f3428; e8f55d0f327fd1d5f26428b890ef7fe878e135d494acda24ef01c695a2e9136d; 3a53bd36b24bc40bdce289d26f1b6965c0a5e71f26b05d19c7aa73d9e3cfa6ff; 2304891f176a92c62f43d9fd30cae943f1521394dce792c6de0e097d10103d45; 8b8adc6c14ed3bbeacd9f39c4d1380835eaf090090f6f826341a018d6b2ad450; 6bb959c33fdfc0086ac48586a73273a0a1331f1c4f0053ef021eebe7f377a292; b9f3cf9d63d2e3ce1821f2e3eb5acd6e374ea801f9c212eebfa734bd649bec7a
Source / Hunt Context
Sekoia.io's published PlugX USB-worm malware set used to support detection and the sovereign-disinfection research.
Lifecycle / Boundary
Separate Mustang Panda-associated variant. A match does not identify historical PLUGX/SOGU or APT10 activity.13
IOC Type
SHA-256 · Malware
Specific Indicator(s)
8ec37dac2beaa494dcefec62f0bf4ae30a6ce44b27a588169d8f0476bbc94115; e72e49dc1d95efabc2c12c46df373173f2e20dab715caf58b1be9ca41ec0e172; 0e9071714a4af0be1f96cffc3b0e58520b827d9e58297cb0e02d97551eca3799; 39280139735145ba6f0918b684ab664a3de7f93b1e3ebcdd071a5300486b8d20; 41a0407371124bcad7cab56227078ccd635ba6e6b4374b973754af96b7f58119; 02aa5b52137410de7cc26747f26e07b65c936d019ee2e1afae268a00e78a1f7f; 2a07877cb53404888e1b6f81bb07a35bc804daa1439317bccde9c498a521644c; 5d98d1193fcbb2479668a24697023829fc9dc1f7d31833c3c42b8380ef859ff1
Source / Hunt Context
Unit 42's 2023 known PlugX USB sample set. e72e49... is the documented x32bridge.dat encrypted payload; 5b4969... is a related in-memory DLL variant with document-copying capability.
Lifecycle / Boundary
USB-variant-specific. Use exact hash plus file role, path, and execution evidence.10
IOC Type
MD5 · Loader triad
Specific Indicator(s)
VeetlePlayer.exe — 9d0da088d2bb135611b5450554c99672; libvlc.dll — 9a8c76271210324d97a232974ca0a6a3; mtcReport.ktc — 3045e77e1e9cf9d9657aea71ab5e8947
Source / Hunt Context
Exact three-file execution set published in CISA's 2017 multi-victim record: legitimate launcher, malicious DLL loader/decoder, and encoded shellcode/implant file.
Lifecycle / Boundary
Historical PLUGX/SOGU campaign set. VeetlePlayer.exe must be interpreted by hash, path, adjacency, and module load—not filename alone.1
IOC Type
SHA-256 · DLL
Specific Indicator(s)
ssMUIDLL.dll — 968e62874d105132bb542e7a72f5416886ed23dc75e52a673e2d23ad905fecf6; ssMUIDLL.dll — 94defa567302c753d9c4f7f3573270eff0b1e4a5d8ec6873887e680a93ed6ddb
Source / Hunt Context
Malicious PlugX DLL loaders side-loaded by Samsung's legitimate RunHelp.exe in two analyzed samples.
Lifecycle / Boundary
Malicious sample hashes. RunHelp.exe itself is a legitimate signed application and must not be blocked generically.9
IOC Type
SHA-256 · Payload
Specific Indicator(s)
ssMUIDLL.dll.conf — 92c806d3a98ddced7f3790fcf33c77e573d46ca85a43403bf2c97670f68d05e3; ssMUIDLL.dll.conf — 423d1da057ac708c9ba2f9b1243fcbecd8772e0b06f87d011f6e1868393fe9f5
Source / Hunt Context
Encrypted PlugX functional-code files decrypted by the malicious ssMUIDLL.dll loaders.
Lifecycle / Boundary
Sample-specific malicious payloads; collect alongside the loader and launcher.9
IOC Type
SHA-256 · Delivery
Specific Indicator(s)
雨傘達動後教會生 態.doc — 57dba34482a0aa3ae2c092a40c709f7e5e5ba5c8a06202a6b1716fa1fdbd1a77; 1.xls — c97c3d53e9ac95ba01aa8bc85c6c8cb792b2d3dba68d7d8912e01f1e62645b71; word.exe — b560b974497bc64f68e6a1cebc6f137f73d6e2b282de9b6627a707ae7722fd7d; 7.tmp — be855efc2a5f7dcee98a7870e009747940a231f5389380a72565759ca6fdb68f
Source / Hunt Context
Unit 42 delivery documents and droppers exploiting CVE-2012-0158 in the Samsung side-loading cases.
Lifecycle / Boundary
2014-2015 delivery samples; not the universal SOGU access vector.9
IOC Type
Files · USB chain
Specific Indicator(s)
x32dbg.exe; x32dbge.exe; Mediae.exe; Aug.exe; Precious.exe; SafeGuard.exe; Dism.exe; x32bridge.dll; x32bridge.dat; akm.dat; precious.dat; Groza_1.dat; desktop.ini
Source / Hunt Context
Unit 42 observed benign executables abused for loading plus malicious DLL/encrypted-payload and USB-masquerading filenames. Correlate exact combinations: x32dbg.exe → x32bridge.dll → x32bridge.dat is one documented chain.
Lifecycle / Boundary
Several executable names are legitimate or easily renamed. Require path, signature, adjacent components, module loads, and hashes.10
IOC Type
Paths · USB / host
Specific Indicator(s)
<USB>:\u00A0\u00A0\RECYCLER.BIN\files; <USB>:\u00A0\u00A0\RECYCLER.BIN\files\da520e5; RECYCLER.BIN\1\CEFHelper.exe; C:\ProgramData\UsersDate\Windows_NT\Windows\user\Desktop\; C:\Users\Public\Public Mediae\; %USERPROFILE%\AvastSvcpCP\
Source / Hunt Context
Hidden no-break-space USB paths, document-staging folder, Sekoia LNK target, and known host directories from Unit 42/Sekoia worm research.
Lifecycle / Boundary
Preserve Unicode U+00A0 exactly. Inspect USB media with forensic or Unix-like tooling because Windows Explorer and cmd.exe may conceal the structure.10, 13
IOC Type
Persistence
Specific Indicator(s)
HKCU\...\CurrentVersion\Run; HKLM\SOFTWARE\BINARY\ssMUIDLL.dll.conf; HKCU\SOFTWARE\BINARY\ssMUIDLL.dll.conf; service ABC; scheduled tasks LKUFORYOU_1 and PRECIOUS_0.1
Source / Hunt Context
Mustang Panda worm autorun; Samsung sample registry-stored payload and service; Unit 42 USB-variant scheduled tasks.
Lifecycle / Boundary
These belong to different variants. Preserve full key value, executable path, task XML, service image path, timestamps, and creator telemetry.9, 10, 12, 13
IOC Type
Mutexes
Specific Indicator(s)
LKU_Test_0.1; LKU_Test_0.2; TCP_0.1
Source / Hunt Context
Known Windows mutex names published with Unit 42's PlugX USB sample set.
Lifecycle / Boundary
Variant-specific runtime leads; absence does not exclude another PlugX variant.10
IOC Type
LNK / YARA string
Specific Indicator(s)
RECYCLER.BIN\1\CEFHelper.exe; LNK file size < 2 KB; big-endian header check 0x4c000000
Source / Hunt Context
Sekoia.io's public apt_MustangPanda_PlugXWorm_lnk rule detects the embedded wide-string path in a small Windows shortcut.
Lifecycle / Boundary
High-value worm-specific artifact. Confirm the full LNK target, arguments, volume path, and associated triad.13
IOC Type
HTTP · Beacon
Specific Indicator(s)
POST /[a-f0-9]{8}; jsp-se; jsp-st; jsp-si; jsp-sn; hard-coded User-Agent 'Mozilla/5.0 (Windows NT 10.0;Win64;x64)AppleWebKit/537.36'; TCP/HTTP ports 110, 443, and 80
Source / Hunt Context
Sekoia.io discriminators for the Mustang Panda-associated PlugX worm contacting 45.142.166[.]112.
Lifecycle / Boundary
Protocol and variant-specific. Header-name combinations and process-to-destination mapping are stronger than the common User-Agent alone.13
IOC Type
HTTP/TCP · Protocol
Specific Indicator(s)
POST /update?id=<8 hex>; HX1/HX2/HX3/HX4; X-Session/X-Status/X-Size/X-Sn; MJ1X/MJ2X/MJ3X/MJ4X; plaintext HTTP observed on TCP 443; ports 80, 8080, and 53
Source / Hunt Context
CISA-published historical PLUGX network signatures and port observations.
Lifecycle / Boundary
Historical variant signatures. Validate full header sequence, flow direction, process, destination, and payload before escalation.1
IOC Type
File · Remediation
Specific Indicator(s)
%TEMP%\del_AsvastSvcpCP.bat; native command ID 0x1005
Source / Hunt Context
Temporary batch file and native self-delete command documented in Sekoia.io's reverse engineering and the FBI removal workflow.
Lifecycle / Boundary
Can indicate court-authorized or other self-deletion rather than active attacker execution. Correlate with January 2025 ISP/FBI notice, sinkhole contact, process termination, and surrounding evidence.6, 12, 13
#
1
Tier
Tier 0 - Government alert
Publisher
CISA / US-CERT
Published
April 6, 2017; revised
Why Used
Primary public source for the PLUGX/SOGU label, memory-resident caveat, three-file DLL side-loading chain, credential-led access, RedLeaves relationship, mitigations, and government-provided indicators.
#
2
Tier
Tier 0 - Authoritative framework
Publisher
MITRE ATT&CK
Published
Living record
Why Used
Maintained software-family record for Windows platform scope, modular capabilities, ATT&CK techniques, reported use by multiple groups, and sample-specific caution.
#
3
Tier
Tier 0 - Authoritative framework
Publisher
MITRE ATT&CK
Published
Living record; modified May 12, 2026
Why Used
Maintained actor record for the menuPass, APT10, Stone Panda, Cicada, Red Apollo, and related naming set; target sectors; software; and campaign behaviors.
#
4
Tier
Tier 0 - Government attribution
Publisher
U.S. Department of Justice
Published
December 20, 2018
Why Used
Government legal record for APT10 aliases, charged MSP and technology-theft campaigns, credential theft, lateral movement, staging and exfiltration allegations, sectors, and stated legal caveats.
#
5
Tier
Tier 1 - Primary vendor research
Publisher
Symantec / Broadcom
Published
November 17, 2020
Why Used
Primary campaign research for Cicada/APT10 attribution confidence, Japan-linked victimology, DLL side-loading, discovery, credential theft, living-off-the-land tools, staging, data access, and public sample hashes.
#
6
Tier
Tier 0 - Government disruption
Publisher
U.S. Department of Justice
Published
January 14, 2025; updated July 7, 2026
Why Used
Primary source for the separate Mustang Panda PlugX variant, court-authorized U.S. removal operation, approximately 4,258 remediated computers and networks, and notification context.
#
7
Tier
Tier 5 - Framework technique
Publisher
MITRE ATT&CK
Published
Living record
Why Used
Authoritative technique context for malicious DLL search-order hijacking and side-loading, including PlugX procedure examples.
#
8
Tier
Tier 5 - Framework software
Publisher
MITRE ATT&CK
Published
Living record
Why Used
Supporting menuPass context for a distinct loader used to deploy PlugX and other payloads through DLL search-order hijacking; retained without merging the loader and implant identities.
#
9
Tier
Tier 1 - Primary malware research
Publisher
Palo Alto Networks Unit 42
Published
June 22, 2015
Why Used
Primary reverse engineering for a malicious Office document exploiting CVE-2012-0158, the signed Samsung executable/malicious DLL/encrypted payload chain, memory decoding, registry payload storage, Windows service persistence, anti-analysis behavior, and encrypted HTTP Cookie traffic.
#
10
Tier
Tier 1 - Primary malware research
Publisher
Palo Alto Networks Unit 42
Published
January 25, 2023
Why Used
Primary research for a removable-media variant using hidden files and an LNK, three-component DLL side-loading, in-memory payload decryption, host and USB propagation, and recurring scheduled-task persistence.
#
11
Tier
Tier 1 - Primary campaign research
Publisher
Trend Micro
Published
January 14, 2020
Why Used
Primary campaign research for spear-phishing DOCX initial access and a PlugX variant delivered through a legitimate executable, malicious DLL, and third encrypted payload file within a broader multi-backdoor operation.
#
12
Tier
Tier 0 - Government court record
Publisher
U.S. Department of Justice / FBI
Published
December 20, 2024; unsealed January 2025
Why Used
Primary legal and technical record for the USB-propagating Mustang Panda PlugX variant, C2 address, warrant authority, rolling execution, host-side deletion steps, non-content limitation, U.S. IP observation, victim notification, and scope boundaries.
#
13
Tier
Tier 1 - Primary malware and disruption research
Publisher
Sekoia.io
Published
April 25, 2024
Why Used
Primary reverse engineering and sinkhole record for the hard-coded C2, native 0x1005 self-delete command, host-cleaning mechanics, IP-count limitations, infected-USB constraint, alternative USB-cleaning payload, and reinfection risk.
#
14
Tier
Tier 0 - Government legal action
Publisher
U.S. Department of Justice / FBI
Published
March 5, 2025
Why Used
Primary government record for separate PRC hacker-for-hire and APT27-linked charges and disruption measures involving alleged use of malware such as PlugX for persistent access; retained as family-reuse context, not as a SOGU attribution.