SOGU Remote Access Malware
PlugX-Family Tradecraft, DLL Side-Loading, Persistent Access, and Espionage Risk
- Field
- User Topic
- Value
- SOGU remote access malware: initial access, execution, persistence, proof of compromise, response, and attribution boundaries.
- Field
- Interpreted Questions
- Value
- What is SOGU, and how does the name relate to PlugX? Which initial-access paths are directly observed, and which are variant-specific possibilities? What evidence proves artifact presence, loader or implant execution, family identity, persistence, command activity, lateral movement, or data activity? What should defenders collect and do first, and what is required before naming an actor, CVE, victim, or loss outcome?
- Field
- Initial Observations
- Value
- The most authoritative SOGU-specific record is CISA's 2017 multi-victim alert. In that campaign, stolen local and domain administrator credentials, stolen certificates, user impersonation, and IT-service-provider trust were the primary access mechanisms; the malware implant was a secondary persistence and access mechanism on relay and staging systems. CISA described a common three-file execution chain—a non-malicious executable, malicious DLL loader, and encoded payload—with the implant decoded and run in memory. Separate primary vendor cases show malicious Office documents, exploit-driven droppers, post-compromise download, spear phishing, and removable-media LNK execution as delivery paths for particular PlugX variants. Those examples expand the hunt, but they must not be presented as one universal SOGU infection chain. MITRE tracks PlugX as a multi-actor Windows malware family, so family identification and actor attribution remain separate analytic conclusions.1, 2, 3, 9, 10, 11
- Field
- Source Coverage
- Value
- Tier
- Tier 0 - Most Trusted
- Checked
- 6
- Candidate Hits
- 6
- Planner Selected
- 5
- Not Used
- 1
- Tier
- Tier 1 - Authoritative
- Checked
- 8
- Candidate Hits
- 7
- Planner Selected
- 5
- Not Used
- 3
- Tier
- Tier 2 - High-Value Research
- Checked
- 4
- Candidate Hits
- 3
- Planner Selected
- 0
- Not Used
- 4
- Tier
- Tier 3 - Corroborating News
- Checked
- 3
- Candidate Hits
- 2
- Planner Selected
- 0
- Not Used
- 3
- Tier
- Tier 4 - Community Signal
- Checked
- 2
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 2
- Tier
- Tier 5 - Custom Source
- Checked
- 5
- Candidate Hits
- 5
- Planner Selected
- 4
- Not Used
- 1
- Tier
- Tier 6 - Custom Integrations with API/Keys
- Checked
- 1
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 1
- Tier
- Tier 7 - Inner Discovery
- Checked
- 1
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 1
- Tier
- Tier 8 - Expansion Research / AI Agent Delta
- Checked
- 1
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 1
- Tier
- Total
- Checked
- 31
- Candidate Hits
- 23
- Planner Selected
- 14
- Not Used
- 17
Tier Checked Candidate Hits Planner Selected Not Used Tier 0 - Most Trusted 6 6 5 1 Tier 1 - Authoritative 8 7 5 3 Tier 2 - High-Value Research 4 3 0 4 Tier 3 - Corroborating News 3 2 0 3 Tier 4 - Community Signal 2 0 0 2 Tier 5 - Custom Source 5 5 4 1 Tier 6 - Custom Integrations with API/Keys 1 0 0 1 Tier 7 - Inner Discovery 1 0 0 1 Tier 8 - Expansion Research / AI Agent Delta 1 0 0 1 Total 31 23 14 17
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | SOGU remote access malware: initial access, execution, persistence, proof of compromise, response, and attribution boundaries. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | What is SOGU, and how does the name relate to PlugX? Which initial-access paths are directly observed, and which are variant-specific possibilities? What evidence proves artifact presence, loader or implant execution, family identity, persistence, command activity, lateral movement, or data activity? What should defenders collect and do first, and what is required before naming an actor, CVE, victim, or loss outcome? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | The most authoritative SOGU-specific record is CISA's 2017 multi-victim alert. In that campaign, stolen local and domain administrator credentials, stolen certificates, user impersonation, and IT-service-provider trust were the primary access mechanisms; the malware implant was a secondary persistence and access mechanism on relay and staging systems. CISA described a common three-file execution chain—a non-malicious executable, malicious DLL loader, and encoded payload—with the implant decoded and run in memory. Separate primary vendor cases show malicious Office documents, exploit-driven droppers, post-compromise download, spear phishing, and removable-media LNK execution as delivery paths for particular PlugX variants. Those examples expand the hunt, but they must not be presented as one universal SOGU infection chain. MITRE tracks PlugX as a multi-actor Windows malware family, so family identification and actor attribution remain separate analytic conclusions.1, 2, 3, 9, 10, 11 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
|
Primary Platform
Windows
MITRE models PlugX as Windows malware; the retained CISA execution chain also centers on Windows executables and DLL loading.
Core Execution
3 components
Government and vendor reporting converge on a legitimate executable, malicious DLL loader, and encoded payload.
Proof Threshold
Memory + behavior
File presence is a lead. Execution, decoded memory, persistence, command traffic, or module behavior proves progressively more.
Actor Exclusivity
None
PlugX-family malware has been used by multiple threat groups; a family match cannot establish the operator on its own.
SOGU appears in U.S. government reporting as part of a combined PLUGX/SOGU label. The most defensible operational treatment is a source-specific designation within the PlugX-related malware evidence set, not a claim that every publisher uses the term identically or that every PlugX variant is SOGU.1, 2
The central technical pattern is a three-component loader set: a non-malicious—sometimes validly signed—Windows executable, a malicious DLL placed where that program will load it, and an encoded or encrypted payload. The DLL decodes or decrypts the payload and executes the implant in memory; the implant may never exist on disk in decoded form.1, 2, 9, 10
Initial access must be stated at campaign level. CISA's observed campaign emphasized stolen administrative credentials, certificates, user impersonation, and IT-provider trust. Other primary cases document malicious Office documents exploiting CVE-2012-0158, spear-phishing documents, a prior foothold downloading the components, and removable-media LNK execution. These are supported paths for particular cases—not a single universal infection story.1, 9, 10, 11
Once running, the modular implant can provide remote shell access, system and network discovery, file and registry operations, service control, screenshot capture, keylogging, SQL interaction, file transfer, port mapping, and dynamically managed plugins. A responder must determine which modules were present and used rather than assume every documented capability executed.1, 2
This is therefore both a malware-eradication and enterprise-trust investigation. The key questions are whether the loader ran, whether the implant decoded into memory, what persistence and command channels existed, which credentials and systems were reachable, and whether the operator performed lateral movement, collection, staging, or exfiltration.1, 2, 4
CISOs, SOC and threat-hunting teams, incident responders, Windows and endpoint administrators, identity teams, managed service providers, legal and privacy stakeholders, and intelligence analysts. The immediate job is to validate suspicious side-loading chains, preserve volatile and disk evidence, identify persistence and command-and-control activity, scope credentials and systems reachable from the host, and keep attribution separate from containment.1, 2, 4
Research and scoping note
MSPs and other IT service providers require a portfolio lens: inventory management infrastructure, privileged identities, certificates, remote administration paths, client VPNs, shared tooling, and every customer environment reachable from the suspected relay or staging host. A provider compromise creates a plausible downstream path, but each client impact conclusion still requires client-specific access evidence.1, 3, 4
- The strongest SOGU-specific access evidence is credential and trust abuse: In CISA's observed campaign, stolen local and domain administrator credentials, certificates, user impersonation, and access through IT service providers were the primary mechanisms. The implant was used to maintain persistence and additional access on relay and staging systems.1
- Other delivery paths are real but sample-specific: Primary vendor cases document malicious Office documents exploiting CVE-2012-0158, spear-phishing documents, post-compromise component download, and removable-media LNK execution. Use them as scoped hunt hypotheses, not as one universal SOGU entry chain.9, 10, 11
- Preserve evidence before isolation or cleanup: Collect memory, processes, loaded modules, handles, sockets, services, scheduled tasks, autoruns, registry hives, the three-component loader set, DNS/proxy/firewall data, authentication logs, and EDR history. Some observed implants existed only in memory and evaded then-current antivirus signatures.1, 2
- Prove execution—not just file presence: A suspicious executable, DLL, or payload is a lead. Stronger proof includes the legitimate process loading the DLL, the DLL reading or decoding the payload, executable memory or injected code, implant configuration or modules in memory, persistence creation, or characteristic command traffic.1, 2, 9, 10
- Treat confirmed execution as an enterprise-trust incident: The implant can provide remote shell, discovery, keylogging, screenshots, registry and service control, file operations, database access, plugin updates, and file transfer. Scope credentials, administrative paths, domain controllers, file servers, MSP infrastructure, and connected clients.1, 2, 4
- Contain in sequence: Preserve volatile evidence first when operationally safe; then isolate the host, block confirmed command paths, revoke exposed identities, hunt related hosts, remove persistence, rebuild from trusted media where integrity is uncertain, and monitor for re-entry.1, 2
- The 2024-2025 U.S. disruption was remote remediation of a separate USB-propagating PlugX variant: After Sekoia.io sinkholed the variant's hard-coded command server, the FBI used nine rolling warrants beginning in August 2024 to send PlugX's native self-delete command to reachable U.S. systems. DOJ reported approximately 4,258 removals when the U.S. operation ended January 3, 2025. The command stopped PlugX and removed its files, persistence registry keys, malware directory, and temporary cleanup script; the FBI said it collected no victim content and did not affect legitimate files or functions.6, 12, 13
- Removal did not equal complete eradication: The host-only command could not clean infected USB devices, dormant media, air-gapped systems, or hosts that never contacted the sinkhole. The 4,258 figure is the DOJ-reported remediation count—not the total U.S. infection population—and reinfection remained possible. FBI/DOJ notices were routed through victims' internet service providers.6, 12, 13
- Recent-law-enforcement boundary: A review of public FBI/DOJ records found no additional operation in the last three years that explicitly named SOGU. A separate March 2025 DOJ/FBI action alleged APT27-linked actors installed PlugX for persistence, but it did not identify that malware as SOGU and must not be merged with either the historical APT10 PLUGX/SOGU record or the Mustang Panda removal operation.1, 6, 14
- Keep four conclusions separate: Artifact presence, execution, malware-family identification, and actor attribution are different proof levels. A PlugX-family finding does not by itself prove APT10, a government sponsor, a particular CVE, a named victim, or data exfiltration.1, 2, 3, 4, 6
Research and scoping note
The response priority is evidence preservation plus identity and trust recovery—not a filename block. If the suspected system administered other systems or customer environments, assume the scoping boundary extends to every reachable trust path until authentication, network, and endpoint evidence narrows it.1, 4
SOGU appears in CISA reporting as part of the combined PLUGX/SOGU label. For incident response, it should be treated as source-specific PlugX-related nomenclature unless sample analysis establishes a narrower family distinction. MITRE maintains PlugX as a modular Windows backdoor used by multiple groups, which makes the name useful for capability and detection context but insufficient for actor attribution.1, 2
Initial access is not one fixed malware feature. In CISA's multi-victim campaign, the primary mechanisms were stolen local and domain administrator credentials, stolen certificates, user impersonation, and access through compromised IT service providers. The implant was then left on critical relay and staging systems to preserve or expand access. Other primary cases show malicious Office documents and exploits, spear-phishing documents, post-compromise downloads, and removable-media execution; each belongs to its specific sample or campaign until local evidence connects it.1, 9, 10, 11
The most reliable technical model is the three-component loader: a legitimate executable, a malicious DLL named or placed so the executable loads it, and an encoded or encrypted payload. The DLL reads, decodes, decrypts, or decompresses the payload and runs the implant in memory. Trusted signatures on the executable do not make the directory or loaded DLL trustworthy, and the decoded implant may never be written to disk.1, 2, 7, 9, 10
Responders should use a graduated proof standard. Artifact presence means the components exist. Execution is supported when telemetry shows the legitimate process loading the malicious DLL, the DLL reading the payload, decoded executable memory, injection, persistence creation, or command traffic. Family identification requires compatible code, configuration, modules, memory structures, protocol behavior, or authoritative sample analysis. Actor attribution requires additional infrastructure, victimology, delivery, timing, companion tooling, and intelligence evidence.1, 2, 3, 6, 9, 10
A confirmed implant can provide remote shell access, system, process, file, network, and database discovery; keylogging; screenshots; service and registry control; file transfer; port mapping; and runtime plugin changes. The investigation must determine which modules were present, which operator commands ran, and whether the host reached credentials, domain controllers, file servers, management systems, customer networks, or sensitive data.1, 2
Before destructive containment, collect volatile evidence when operationally safe: physical or logical memory, process and thread state, loaded modules, handles, sockets, injected regions, command lines, active logons, and implant configuration. Also preserve the executable/DLL/payload set, signatures and hashes, full paths and timestamps, services, tasks, autoruns, registry hives, prefetch and execution artifacts, EDR history, DNS, proxy, firewall, NetFlow or packet capture, VPN, identity, SMB, RDP, WMI, and file-access evidence.1, 2, 9, 10
The playbook proceeds in gates: preserve evidence; validate access hypotheses and execution; isolate affected hosts; block confirmed command paths; identify and revoke exposed credentials and certificates; hunt for the loader set, persistence, command traffic, administrative-share use, VPN mismatches, and related tooling; scope lateral movement and data activity; eradicate persistence; rebuild systems whose integrity cannot be proven; then monitor for renewed authentication or beaconing.1, 2, 4
APT10 is relevant historical context: MITRE groups menuPass, APT10, Stone Panda, Cicada, and related names under G0045, and DOJ describes global APT10 campaigns against MSPs, technology companies, and government targets. PlugX is not exclusive to that group. DOJ's 2025 removal operation concerned a Mustang Panda version, demonstrating that family identification cannot settle the operator.2, 3, 4, 6
The Mustang Panda operation began from a private-sector sinkhole, not from a newly disclosed SOGU incident. Sekoia.io acquired the abandoned hard-coded command-server address 45.142.166[.]112 in September 2023 and demonstrated that this USB-propagating variant accepted a native self-delete command. French authorities and Sekoia.io supported the FBI, which obtained nine rolling warrants from August 2024 through January 3, 2025 and remotely sent the command when eligible U.S. systems beaconed. DOJ announced the operation on January 14, 2025 and reported approximately 4,258 U.S. computers and networks remediated.6, 12, 13
The court-authorized command stopped the PlugX process; deleted malware-created files, the persistence registry keys, the malware directory, and its temporary cleanup script; and was tested not to collect content or alter legitimate functions or files. The FBI notified affected owners through their ISPs. This was targeted malware deletion, not a forensic examination of victim content, a declaration that no follow-on malware or stolen credentials remained, or proof that data had or had not been exfiltrated.6, 12
The disruption had material limits. The selected low-impact command removed PlugX from online hosts but did not clean infected USB devices; dormant removable media, air-gapped systems, and unreachable hosts could remain infected and reintroduce the worm. DOJ's 4,258 count is the reported remediation total, while the affidavit separately noted at least 45,000 U.S. IP addresses had contacted the sinkhole since September 2023. IP churn, NAT, VPNs, satellite links, and repeated beacons prevent that larger number from being treated as a device count.6, 12, 13
Public FBI/DOJ research for the last three years identified no second operation that explicitly named SOGU. The closest additional PlugX-related legal action was announced March 5, 2025: DOJ and the FBI unsealed charges and disruption measures involving PRC hacker-for-hire and APT27-linked activity in which defendants allegedly installed malware such as PlugX for persistence. That record is useful evidence of PlugX family reuse, but it is not a SOGU-specific operation and does not connect APT27, APT10, or Mustang Panda activity into one campaign.1, 6, 14
A professional conclusion should state exactly what is proven: suspicious artifact present, loader executed, implant identified, persistence confirmed, command-and-control observed, credentials exposed, lateral movement validated, data staged, or exfiltration confirmed. Do not silently convert one finding into a stronger claim about actor, CVE, victim impact, or data loss.1, 2, 3, 4
Research and scoping note
If the suspected endpoint was an administrator workstation, jump host, relay, staging server, domain controller, file server, or MSP management system, elevate severity and widen collection immediately. These systems can expose credentials and trusted routes that make downstream activity appear legitimate to ordinary monitoring.1, 4
Version v1.1 is a full card-by-card rebuild. A future delta must change a source-backed conclusion, behavior, attribution boundary, proof requirement, response action, or public-disclosure fact; routine checks do not count as intelligence updates.
- Update
- Aug 6, 2026 · v1.1
- Source-backed Change
- Rebuilt all 32 cards; added primary Unit 42 and Trend Micro research, access-vector hierarchy, four proof levels, expanded evidence collection, and a gated 13-step IR playbook.
- Update
- Aug 6, 2026 · v1.0
- Source-backed Change
- Published the original 32-card baseline using government, ATT&CK, DOJ, and primary vendor records.
- Update
- Ongoing review
- Source-backed Change
- CARDS actor and malware-source updates remain the review path; dedicated Page Alerts are not enabled for this brief.
- Update
- Material changes only
- Source-backed Change
- New campaigns, samples, infrastructure, CVEs, or actor claims must remain source-specific until reconciled.
| Update | Source-backed Change | Operational Meaning |
|---|---|---|
| Aug 6, 2026 · v1.1 | Rebuilt all 32 cards; added primary Unit 42 and Trend Micro research, access-vector hierarchy, four proof levels, expanded evidence collection, and a gated 13-step IR playbook. | The brief now distinguishes what was observed in the SOGU-specific government record from delivery paths demonstrated only in other PlugX samples or campaigns.1, 9, 10, 11 |
| Aug 6, 2026 · v1.0 | Published the original 32-card baseline using government, ATT&CK, DOJ, and primary vendor records. | Established naming, capability, attribution, and impact boundaries for later improvement.1, 2, 3, 4, 5, 6 |
| Ongoing review | CARDS actor and malware-source updates remain the review path; dedicated Page Alerts are not enabled for this brief. | A source hit does not publish automatically. It must materially change a card and retain traceable evidence.2, 3 |
| Material changes only | New campaigns, samples, infrastructure, CVEs, or actor claims must remain source-specific until reconciled. | This prevents malware-family reuse from collapsing distinct operators and incidents into one record.2, 6 |
- Stakeholder
- Executives
- Why It Matters
- A remote-access implant can turn one Windows endpoint into a path to credentials, sensitive files, administrative systems, or long-term espionage.
- Stakeholder
- SOC / IR
- Why It Matters
- Side-loading and memory-resident execution can evade file-only controls and make a trusted process appear benign.
- Stakeholder
- MSPs / IT providers
- Why It Matters
- Historical APT10 operations abused provider access and stolen administrative credentials to reach client networks.
- Stakeholder
- Legal / privacy
- Why It Matters
- Malware capability, actor identity, access, and data theft are separate evidentiary questions.
| Stakeholder | Why It Matters | Decision It Should Drive |
|---|---|---|
| Executives | A remote-access implant can turn one Windows endpoint into a path to credentials, sensitive files, administrative systems, or long-term espionage. | Fund evidence preservation and blast-radius analysis before treating the event as ordinary malware cleanup.1, 2, 4 |
| SOC / IR | Side-loading and memory-resident execution can evade file-only controls and make a trusted process appear benign. | Collect module, memory, process, identity, persistence, and network evidence together.1, 2, 7 |
| MSPs / IT providers | Historical APT10 operations abused provider access and stolen administrative credentials to reach client networks. | Map every reachable tenant and credential without assuming all clients were accessed.3, 4 |
| Legal / privacy | Malware capability, actor identity, access, and data theft are separate evidentiary questions. | Use confirmed execution and data evidence for notification decisions, not the malware label alone.2, 4, 6 |
This timeline separates malware-family history, observed campaigns, legal attribution, and later family reuse. Dates do not create automatic continuity between operators.
- Date / Period
- At least 2008 onward
- Source-backed Event
- MITRE tracks PlugX as a long-lived modular Windows backdoor used by multiple threat groups.
- Why It Matters
- Defenders need durable behavior detections and cannot rely on one campaign IOC set.
- Boundary
- Family history is not continuous actor attribution.2
- Date / Period
- 2014-2015 samples
- Source-backed Event
- Unit 42 analyzed malicious Office documents that exploited CVE-2012-0158, dropped a signed Samsung executable, malicious DLL, and encrypted configuration/payload, then established service persistence.
- Why It Matters
- This is a concrete example of exploit-driven delivery and proof-bearing loader telemetry.
- Boundary
- It describes particular samples, not every SOGU infection.9
- Date / Period
- May 2016-Apr 2017
- Source-backed Event
- CISA observed a multi-victim campaign using stolen administrative credentials and certificates, provider trust, PowerShell, malware implants, memory-resident execution, and the three-component PlugX loader model.
- Why It Matters
- This is the strongest retained SOGU-specific access, execution, detection, and mitigation record.
- Boundary
- Historical campaign evidence must be reconciled with local telemetry.1
- Date / Period
- Dec 20, 2018
- Source-backed Event
- DOJ announced charges describing APT10 campaigns against MSPs, technology companies, and government agencies.
- Why It Matters
- Explains the provider-to-client trust path, stolen credentials, staging, and alleged data theft.
- Boundary
- Charges are allegations and do not attribute every PlugX-family incident.4
- Date / Period
- 2019-2020
- Source-backed Event
- Trend Micro documented a spear-phishing-led cyberespionage operation that included a three-file PlugX side-loading set alongside other malware.
- Why It Matters
- Supports spear phishing as a campaign-specific delivery hypothesis and shared-infrastructure scoping.
- Boundary
- The operation used multiple backdoors and is not a SOGU-only case.11
- Date / Period
- 2019-2020
- Source-backed Event
- Symantec reported a Cicada/APT10 campaign against Japan-linked organizations using DLL side-loading, credential theft, discovery, lateral movement, and staging.
- Why It Matters
- Provides later actor tradecraft and victimology context.
- Boundary
- The campaign does not prove SOGU use in every victim.5
- Date / Period
- 2021-2023 research
- Source-backed Event
- Unit 42 documented a PlugX variant that used an LNK on removable media to launch a legitimate executable, side-load a malicious DLL, decrypt a payload in memory, and create a recurring scheduled task.
- Why It Matters
- Adds a concrete removable-media execution and persistence hypothesis.
- Boundary
- Only apply when USB/LNK artifacts or compatible sample behavior exists.10
- Date / Period
- Sep 2023
- Source-backed Event
- Sekoia.io acquired and sinkholed 45.142.166[.]112, the hard-coded C2 address for a USB-propagating PlugX variant associated with Mustang Panda, then validated that the implant accepted a native self-delete command.
- Why It Matters
- Created the technical path for sovereign, court-authorized remote remediation when infected hosts beaconed.
- Date / Period
- Aug 2024-Jan 3, 2025
- Source-backed Event
- The FBI obtained nine rolling warrants and, with French authorities and Sekoia.io, sent the native self-delete command to eligible U.S. systems contacting the sinkhole. The command stopped PlugX and removed its files, registry persistence, malware directory, and temporary cleanup script.
- Why It Matters
- Shows a narrowly scoped remote-remediation model that used the malware's own command channel.
- Date / Period
- Jan 14, 2025
- Source-backed Event
- DOJ publicly announced approximately 4,258 U.S. remediations and said affected owners would be notified through their ISPs.
- Why It Matters
- Demonstrates long-lived PlugX reuse, coordinated cleanup, and victim notification at scale.
- Date / Period
- Mar 5, 2025
- Source-backed Event
- DOJ and the FBI announced charges and disruption measures involving PRC hacker-for-hire and APT27-linked activity that allegedly installed malware such as PlugX for persistent access.
- Why It Matters
- Provides another recent U.S. legal record showing that PlugX use crosses actor and campaign boundaries.
- Boundary
- The public action did not name SOGU. Do not merge it with the APT10 PLUGX/SOGU campaign or the Mustang Panda removal operation.14
| Date / Period | Source-backed Event | Why It Matters | Boundary |
|---|---|---|---|
| At least 2008 onward | MITRE tracks PlugX as a long-lived modular Windows backdoor used by multiple threat groups. | Defenders need durable behavior detections and cannot rely on one campaign IOC set. | Family history is not continuous actor attribution.2 |
| 2014-2015 samples | Unit 42 analyzed malicious Office documents that exploited CVE-2012-0158, dropped a signed Samsung executable, malicious DLL, and encrypted configuration/payload, then established service persistence. | This is a concrete example of exploit-driven delivery and proof-bearing loader telemetry. | It describes particular samples, not every SOGU infection.9 |
| May 2016-Apr 2017 | CISA observed a multi-victim campaign using stolen administrative credentials and certificates, provider trust, PowerShell, malware implants, memory-resident execution, and the three-component PlugX loader model. | This is the strongest retained SOGU-specific access, execution, detection, and mitigation record. | Historical campaign evidence must be reconciled with local telemetry.1 |
| Dec 20, 2018 | DOJ announced charges describing APT10 campaigns against MSPs, technology companies, and government agencies. | Explains the provider-to-client trust path, stolen credentials, staging, and alleged data theft. | Charges are allegations and do not attribute every PlugX-family incident.4 |
| 2019-2020 | Trend Micro documented a spear-phishing-led cyberespionage operation that included a three-file PlugX side-loading set alongside other malware. | Supports spear phishing as a campaign-specific delivery hypothesis and shared-infrastructure scoping. | The operation used multiple backdoors and is not a SOGU-only case.11 |
| 2019-2020 | Symantec reported a Cicada/APT10 campaign against Japan-linked organizations using DLL side-loading, credential theft, discovery, lateral movement, and staging. | Provides later actor tradecraft and victimology context. | The campaign does not prove SOGU use in every victim.5 |
| 2021-2023 research | Unit 42 documented a PlugX variant that used an LNK on removable media to launch a legitimate executable, side-load a malicious DLL, decrypt a payload in memory, and create a recurring scheduled task. | Adds a concrete removable-media execution and persistence hypothesis. | Only apply when USB/LNK artifacts or compatible sample behavior exists.10 |
| Sep 2023 | Sekoia.io acquired and sinkholed 45.142.166[.]112, the hard-coded C2 address for a USB-propagating PlugX variant associated with Mustang Panda, then validated that the implant accepted a native self-delete command. | Created the technical path for sovereign, court-authorized remote remediation when infected hosts beaconed. | Private-sector sinkhole telemetry and IP addresses do not provide a stable count of unique devices.12, 13 |
| Aug 2024-Jan 3, 2025 | The FBI obtained nine rolling warrants and, with French authorities and Sekoia.io, sent the native self-delete command to eligible U.S. systems contacting the sinkhole. The command stopped PlugX and removed its files, registry persistence, malware directory, and temporary cleanup script. | Shows a narrowly scoped remote-remediation model that used the malware's own command channel. | The FBI said it collected no victim content and did not affect legitimate files or functions; the action did not establish whether follow-on malware, credential theft, or exfiltration existed.6, 12, 13 |
| Jan 14, 2025 | DOJ publicly announced approximately 4,258 U.S. remediations and said affected owners would be notified through their ISPs. | Demonstrates long-lived PlugX reuse, coordinated cleanup, and victim notification at scale. | The total is a remediation count, not a prevalence estimate. Host deletion did not clean infected USB devices, dormant media, air-gapped systems, or unreachable hosts. This was a Mustang Panda variant, not an APT10 or SOGU continuity claim.6, 12, 13 |
| Mar 5, 2025 | DOJ and the FBI announced charges and disruption measures involving PRC hacker-for-hire and APT27-linked activity that allegedly installed malware such as PlugX for persistent access. | Provides another recent U.S. legal record showing that PlugX use crosses actor and campaign boundaries. | The public action did not name SOGU. Do not merge it with the APT10 PLUGX/SOGU campaign or the Mustang Panda removal operation.14 |
Use this as a gated playbook. Preserve volatile evidence before destructive action when operationally safe. Record who performed each step, timestamps, tools, evidence locations, hashes, and decision rationale.
- Step
- 0 · Activate
- Objective
- Open a controlled investigation
- Actions and Data To Collect
- Assign IR lead, evidence custodian, identity owner, network owner, system owner, legal/privacy contact, and MSP/client liaison. Record alert source, host, user, time window, business role, privileges, network segment, and known management relationships.
- Exit / Proof Gate
- Case identifier, owners, evidence plan, containment authority, and initial severity documented.1
- Step
- 1 · Frame access
- Objective
- Test initial-access hypotheses
- Actions and Data To Collect
- Prioritize: (A) stolen local/domain admin credentials, certificates, VPN identities, user impersonation, or provider trust—the primary CISA campaign path; (B) malicious Office document or exploit-driven dropper; (C) spear-phishing document; (D) components downloaded after another foothold; (E) USB/LNK execution. Collect email, attachment, browser/download, Office child-process, exploit, VPN, certificate, provider-remote-access, removable-media, and first-seen file telemetry.
- Step
- 2 · Preserve volatile
- Objective
- Capture evidence that can disappear
- Actions and Data To Collect
- Acquire memory; process, parent-child, thread, module, handle, token, socket, command-line, environment-variable, named-pipe, and injected-region state; logged-on users; active sessions; network connections; DNS cache; ARP; routing; clipboard where authorized; and implant configuration or decoded payload from memory. Note acquisition tool and hash every output.
- Step
- 3 · Preserve host
- Objective
- Reconstruct loader and persistence
- Actions and Data To Collect
- Collect the legitimate executable, suspicious DLL, encoded/encrypted payload, full directory, signatures, hashes, timestamps, alternate data streams, imports/exports, registry hives, services, scheduled tasks, autoruns, startup items, prefetch, Amcache, Shimcache, SRUM, event logs, EDR timeline, quarantine history, PowerShell logs, and file-system metadata. Preserve any removable-media image or LNK.
- Step
- 4 · Preserve identity
- Objective
- Map exposed trust
- Actions and Data To Collect
- Collect interactive, network, service, scheduled-task, VPN, RDP, SMB, WMI, and cloud sign-ins; privilege changes; certificate issuance/use; Kerberos and NTLM events; password vault access; cached or service credentials; active tokens; admin-share mounts; and client/provider authentication. Identify every credential entered, stored, cached, or reachable on the host.
- Step
- 5 · Preserve network
- Objective
- Identify control, movement, and transfer
- Actions and Data To Collect
- Collect DNS, proxy, firewall, NetFlow, packet capture, TLS metadata, VPN, DHCP, NAC, RDP, SMB, WMI, PSExec/service execution, and egress records. Test for plaintext HTTP on port 443, ports 80/8080/53, dynamic-DNS destinations, spoofed update domains, PlugX header patterns, periodic beacons, bandwidth anomalies, and first-seen destinations.
- Step
- 6 · Prove
- Objective
- Establish what exists and ran
- Actions and Data To Collect
- Classify evidence: Level 1 artifact presence; Level 2 loader/implant execution; Level 3 family identification; Level 4 campaign/actor attribution. Seek module-load events, DLL-to-payload reads, decoded executable memory, injection, implant configuration/modules, service/task creation, compatible YARA/code features, and protocol behavior. Require at least two independent evidence classes for a high-confidence family conclusion where practical.
- Step
- 7 · Contain
- Objective
- Stop control without losing scope
- Actions and Data To Collect
- After critical volatile collection, isolate confirmed hosts; block confirmed malicious domains, IPs, certificates, hashes, and protocol patterns with expiration/review; disable or restrict affected provider paths; revoke active sessions; quarantine removable media; and preserve sinkhole or packet visibility where authorized. Avoid broad blocks based only on shared infrastructure or common signed executables.
- Step
- 8 · Recover identity
- Objective
- Remove usable attacker trust
- Actions and Data To Collect
- Reset or rotate exposed user, admin, service, VPN, API, SSH, certificate, and client credentials in dependency order from clean systems; revoke tokens and sessions; remove unauthorized accounts and role changes; protect privileged users; enforce MFA; and hunt use before and after rotation.
- Step
- 9 · Hunt enterprise
- Objective
- Find related hosts and downstream access
- Actions and Data To Collect
- Search for the exact triad and behavioral variants; unusual signed binaries in wrong directories; low-prevalence DLL loads; encoded payload files; compatible services/tasks/registry keys; memory indicators; command traffic; PowerShell/PowerSploit; admin-share mounts; VPN user/token mismatches; VPS-origin logins; RDP/WMI/SMB movement; and access to relay, staging, domain-controller, file-server, MSP, and client systems.
- Step
- 10 · Scope data
- Objective
- Prove or refute collection and loss
- Actions and Data To Collect
- Review file and directory enumeration, screenshots, keylogs, SQL access, archive utilities, local/remote staging, cloud or file-hosting use, outbound volume, transfer sessions, deleted archives, and sensitive repository access. Map evidence to data owner, classification, time, destination, and affected people or clients.
- Step
- 11 · Eradicate
- Objective
- Remove implant and persistence
- Actions and Data To Collect
- Remove malicious DLLs/payloads, services, tasks, autoruns, registry-stored payloads, unauthorized tools/accounts, and companion malware. Patch only source-supported delivery flaws. Rebuild privileged or uncertain-integrity systems from trusted media; verify application allowlisting, safe directories, endpoint telemetry, segmentation, restricted egress, and remote logging.
- Step
- 12 · Monitor and close
- Objective
- Detect re-entry and document confidence
- Actions and Data To Collect
- Monitor for renewed beaconing, failed or successful use of rotated identities, repeated DLL loads, restored tasks/services, new dynamic-DNS or update-themed destinations, remote administration, and data staging. Retain evidence, final timeline, affected-asset and client matrices, notification decisions, lessons learned, and unresolved gaps.
| Step | Objective | Actions and Data To Collect | Exit / Proof Gate |
|---|---|---|---|
| 0 · Activate | Open a controlled investigation | Assign IR lead, evidence custodian, identity owner, network owner, system owner, legal/privacy contact, and MSP/client liaison. Record alert source, host, user, time window, business role, privileges, network segment, and known management relationships. | Case identifier, owners, evidence plan, containment authority, and initial severity documented.1 |
| 1 · Frame access | Test initial-access hypotheses | Prioritize: (A) stolen local/domain admin credentials, certificates, VPN identities, user impersonation, or provider trust—the primary CISA campaign path; (B) malicious Office document or exploit-driven dropper; (C) spear-phishing document; (D) components downloaded after another foothold; (E) USB/LNK execution. Collect email, attachment, browser/download, Office child-process, exploit, VPN, certificate, provider-remote-access, removable-media, and first-seen file telemetry. | Each hypothesis marked supported, contradicted, or unresolved with evidence and confidence.1, 9, 10, 11 |
| 2 · Preserve volatile | Capture evidence that can disappear | Acquire memory; process, parent-child, thread, module, handle, token, socket, command-line, environment-variable, named-pipe, and injected-region state; logged-on users; active sessions; network connections; DNS cache; ARP; routing; clipboard where authorized; and implant configuration or decoded payload from memory. Note acquisition tool and hash every output. | Volatile package acquired or an explicit risk-based reason for omission documented.1, 2 |
| 3 · Preserve host | Reconstruct loader and persistence | Collect the legitimate executable, suspicious DLL, encoded/encrypted payload, full directory, signatures, hashes, timestamps, alternate data streams, imports/exports, registry hives, services, scheduled tasks, autoruns, startup items, prefetch, Amcache, Shimcache, SRUM, event logs, EDR timeline, quarantine history, PowerShell logs, and file-system metadata. Preserve any removable-media image or LNK. | Three-component set and execution/persistence artifacts preserved, or absence documented across named sources.1, 9, 10 |
| 4 · Preserve identity | Map exposed trust | Collect interactive, network, service, scheduled-task, VPN, RDP, SMB, WMI, and cloud sign-ins; privilege changes; certificate issuance/use; Kerberos and NTLM events; password vault access; cached or service credentials; active tokens; admin-share mounts; and client/provider authentication. Identify every credential entered, stored, cached, or reachable on the host. | Credential exposure matrix links identity, privilege, system, client/tenant, evidence, and required recovery action.1, 3, 4 |
| 5 · Preserve network | Identify control, movement, and transfer | Collect DNS, proxy, firewall, NetFlow, packet capture, TLS metadata, VPN, DHCP, NAC, RDP, SMB, WMI, PSExec/service execution, and egress records. Test for plaintext HTTP on port 443, ports 80/8080/53, dynamic-DNS destinations, spoofed update domains, PlugX header patterns, periodic beacons, bandwidth anomalies, and first-seen destinations. | Network timeline ties process and identity activity to destinations, protocol, bytes, and direction.1, 2, 9 |
| 6 · Prove | Establish what exists and ran | Classify evidence: Level 1 artifact presence; Level 2 loader/implant execution; Level 3 family identification; Level 4 campaign/actor attribution. Seek module-load events, DLL-to-payload reads, decoded executable memory, injection, implant configuration/modules, service/task creation, compatible YARA/code features, and protocol behavior. Require at least two independent evidence classes for a high-confidence family conclusion where practical. | Finding states the highest proven level, evidence IDs, confidence, and what remains unproven.1, 2, 9, 10 |
| 7 · Contain | Stop control without losing scope | After critical volatile collection, isolate confirmed hosts; block confirmed malicious domains, IPs, certificates, hashes, and protocol patterns with expiration/review; disable or restrict affected provider paths; revoke active sessions; quarantine removable media; and preserve sinkhole or packet visibility where authorized. Avoid broad blocks based only on shared infrastructure or common signed executables. | No active command channel or uncontrolled spread; containment scope and business exceptions documented.1, 2 |
| 8 · Recover identity | Remove usable attacker trust | Reset or rotate exposed user, admin, service, VPN, API, SSH, certificate, and client credentials in dependency order from clean systems; revoke tokens and sessions; remove unauthorized accounts and role changes; protect privileged users; enforce MFA; and hunt use before and after rotation. | Every exposed trust item is revoked, rotated, validated, or explicitly accepted by an accountable owner.1, 4 |
| 9 · Hunt enterprise | Find related hosts and downstream access | Search for the exact triad and behavioral variants; unusual signed binaries in wrong directories; low-prevalence DLL loads; encoded payload files; compatible services/tasks/registry keys; memory indicators; command traffic; PowerShell/PowerSploit; admin-share mounts; VPN user/token mismatches; VPS-origin logins; RDP/WMI/SMB movement; and access to relay, staging, domain-controller, file-server, MSP, and client systems. | Hunt coverage register lists data sources, time range, assets, queries, hits, gaps, and disposition.1, 2, 3, 4 |
| 10 · Scope data | Prove or refute collection and loss | Review file and directory enumeration, screenshots, keylogs, SQL access, archive utilities, local/remote staging, cloud or file-hosting use, outbound volume, transfer sessions, deleted archives, and sensitive repository access. Map evidence to data owner, classification, time, destination, and affected people or clients. | Separate conclusions for access, collection, staging, attempted transfer, and confirmed exfiltration.1, 2, 4, 5 |
| 11 · Eradicate | Remove implant and persistence | Remove malicious DLLs/payloads, services, tasks, autoruns, registry-stored payloads, unauthorized tools/accounts, and companion malware. Patch only source-supported delivery flaws. Rebuild privileged or uncertain-integrity systems from trusted media; verify application allowlisting, safe directories, endpoint telemetry, segmentation, restricted egress, and remote logging. | Independent validation finds no persistence, implant execution, unauthorized trust, or unaddressed delivery path.1, 2, 9, 10 |
| 12 · Monitor and close | Detect re-entry and document confidence | Monitor for renewed beaconing, failed or successful use of rotated identities, repeated DLL loads, restored tasks/services, new dynamic-DNS or update-themed destinations, remote administration, and data staging. Retain evidence, final timeline, affected-asset and client matrices, notification decisions, lessons learned, and unresolved gaps. | Defined clean-observation period completed; closure approved by IR, identity, system owner, and legal/privacy as applicable.1, 2, 4 |
- Term
- SOGU
- Definition
- Source-specific name appearing in CISA's combined PLUGX/SOGU label.
- Operational Use
- Use for matching the cited government record and local analyst nomenclature.
- Boundary
- Do not assume every publisher uses it identically.1
- Term
- PlugX
- Definition
- Modular Windows remote-access malware tracked by MITRE as S0013.
- Operational Use
- Use for capability, technique, software, and multi-actor context.
- Boundary
- Family identification is not actor attribution.2
- Term
- Three-component loader
- Definition
- Legitimate executable, malicious DLL loader, and encoded or encrypted payload.
- Operational Use
- Collect and correlate all components, their directory, execution, and module-load evidence.
- Term
- DLL side-loading
- Definition
- A legitimate program loads an attacker-placed DLL because of name, location, or search-order behavior.
- Operational Use
- Detect trusted processes loading unexpected libraries from unusual or writable paths.
- Term
- Memory-resident implant
- Definition
- Decoded or executable malicious code runs in process memory with limited decoded content on disk.
- Operational Use
- Prioritize memory and module evidence before cleanup.
- Term
- Relay / staging system
- Definition
- A compromised host used to preserve access, route activity, hold tools, or stage collected data.
- Operational Use
- Expand scope to credentials, systems, and clients reachable from it.
- Term
- Proof level
- Definition
- A controlled distinction among artifact presence, execution, family identification, and attribution.
- Operational Use
- State the highest proven level and the evidence required for promotion.
| Term | Definition | Operational Use | Boundary |
|---|---|---|---|
| SOGU | Source-specific name appearing in CISA's combined PLUGX/SOGU label. | Use for matching the cited government record and local analyst nomenclature. | Do not assume every publisher uses it identically.1 |
| PlugX | Modular Windows remote-access malware tracked by MITRE as S0013. | Use for capability, technique, software, and multi-actor context. | Family identification is not actor attribution.2 |
| Three-component loader | Legitimate executable, malicious DLL loader, and encoded or encrypted payload. | Collect and correlate all components, their directory, execution, and module-load evidence. | Files alone do not prove execution.1, 9, 10 |
| DLL side-loading | A legitimate program loads an attacker-placed DLL because of name, location, or search-order behavior. | Detect trusted processes loading unexpected libraries from unusual or writable paths. | The technique is widely used and not actor-specific.1, 7 |
| Memory-resident implant | Decoded or executable malicious code runs in process memory with limited decoded content on disk. | Prioritize memory and module evidence before cleanup. | A negative disk scan does not refute execution.1, 2 |
| Relay / staging system | A compromised host used to preserve access, route activity, hold tools, or stage collected data. | Expand scope to credentials, systems, and clients reachable from it. | Role must be proven with network, file, and identity evidence.1, 4 |
| Proof level | A controlled distinction among artifact presence, execution, family identification, and attribution. | State the highest proven level and the evidence required for promotion. | Do not merge the levels in reporting.1, 2, 3 |
Rows distinguish implant capability from campaign-level access and post-compromise behavior. A technique is included only when the retained source set supports it; local occurrence still requires telemetry.
- ATT&CK / Behavior
- T1078 · Valid Accounts
- Source-backed Evidence
- CISA and DOJ describe stolen administrator credentials, user impersonation, and provider/client access.
- Hunt / Detection
- VPN, RDP, SMB, WMI, service, and interactive logons; impossible travel; VPS sources; account/token mismatch.
- ATT&CK / Behavior
- T1566.001 · Spearphishing Attachment
- Source-backed Evidence
- Unit 42 and Trend Micro document malicious Office or DOCX delivery in particular PlugX-related campaigns.
- Hunt / Detection
- Email gateway, attachment hash, Office child process, exploit, dropper, and decoy-document evidence.
- ATT&CK / Behavior
- T1574.001 · DLL side-loading
- Source-backed Evidence
- Legitimate executable loads a malicious DLL that decodes the payload into memory.
- Hunt / Detection
- Image-load events, unusual paths, unsigned/low-prevalence DLLs, adjacent payload reads, signed-binary path mismatch.
- ATT&CK / Behavior
- T1027 · Obfuscated Files or Information
- Source-backed Evidence
- Encoded/encrypted payloads, changing decoder stubs, protected strings, and memory-only decoded form frustrate signatures.
- Hunt / Detection
- High-entropy adjacent files, decoder loops, executable memory, unpacked code, configuration extraction.
- ATT&CK / Behavior
- T1543.003 / T1053.005 · Service or Task
- Source-backed Evidence
- Reported samples create a Windows service or recurring scheduled task to relaunch the legitimate executable and side-load the implant.
- Hunt / Detection
- New services/tasks referencing unusual binaries or directories; creation events near the first loader execution.
- ATT&CK / Behavior
- T1059.003 · Windows Command Shell
- Source-backed Evidence
- CISA and MITRE describe remote shell and command execution capability.
- Hunt / Detection
- Unexpected cmd.exe children, named pipes, command bursts, service or remote-execution parents.
- ATT&CK / Behavior
- T1082 / T1083 / T1016 · Discovery
- Source-backed Evidence
- Host, drive, file, process, network, resource, and endpoint enumeration are supported modules.
- Hunt / Detection
- Correlated enumeration shortly after loader execution or beaconing.
- ATT&CK / Behavior
- T1056.001 · Keylogging
- Source-backed Evidence
- CISA's module list and MITRE report keylogging capability.
- Hunt / Detection
- Input hooks, keylog files, suspicious handles, keyboard APIs, and subsequent credential use.
- ATT&CK / Behavior
- T1071 / T1095 · Command and Control
- Source-backed Evidence
- HTTP, DNS, encrypted or non-application traffic and non-standard ports are reported; CISA observed plaintext HTTP on port 443 and ports 80/8080/53.
- Hunt / Detection
- Port/protocol mismatch, PlugX header patterns, periodic POSTs, dynamic DNS, spoofed update domains, process/network mismatch.
- ATT&CK / Behavior
- T1041 · Exfiltration Over C2
- Source-backed Evidence
- Family capability and historical campaigns support file transfer and staged exfiltration.
- Hunt / Detection
- Archive/staging creation followed by outbound volume, cloud/file-hosting access, or command-channel transfer.
| ATT&CK / Behavior | Source-backed Evidence | Hunt / Detection | Scope Boundary |
|---|---|---|---|
| T1078 · Valid Accounts | CISA and DOJ describe stolen administrator credentials, user impersonation, and provider/client access. | VPN, RDP, SMB, WMI, service, and interactive logons; impossible travel; VPS sources; account/token mismatch. | Campaign/actor behavior, not an intrinsic implant module.1, 3, 4 |
| T1566.001 · Spearphishing Attachment | Unit 42 and Trend Micro document malicious Office or DOCX delivery in particular PlugX-related campaigns. | Email gateway, attachment hash, Office child process, exploit, dropper, and decoy-document evidence. | Sample-specific delivery; do not assume it for every case.9, 11 |
| T1574.001 · DLL side-loading | Legitimate executable loads a malicious DLL that decodes the payload into memory. | Image-load events, unusual paths, unsigned/low-prevalence DLLs, adjacent payload reads, signed-binary path mismatch. | Strong execution mechanism, weak actor discriminator.1, 2, 7, 9, 10 |
| T1027 · Obfuscated Files or Information | Encoded/encrypted payloads, changing decoder stubs, protected strings, and memory-only decoded form frustrate signatures. | High-entropy adjacent files, decoder loops, executable memory, unpacked code, configuration extraction. | Encoding varies by variant.1, 2, 9 |
| T1543.003 / T1053.005 · Service or Task | Reported samples create a Windows service or recurring scheduled task to relaunch the legitimate executable and side-load the implant. | New services/tasks referencing unusual binaries or directories; creation events near the first loader execution. | Persistence mechanism varies by sample.2, 9, 10 |
| T1059.003 · Windows Command Shell | CISA and MITRE describe remote shell and command execution capability. | Unexpected cmd.exe children, named pipes, command bursts, service or remote-execution parents. | Capability does not prove commands ran.1, 2 |
| T1082 / T1083 / T1016 · Discovery | Host, drive, file, process, network, resource, and endpoint enumeration are supported modules. | Correlated enumeration shortly after loader execution or beaconing. | Module availability varies.1, 2 |
| T1056.001 · Keylogging | CISA's module list and MITRE report keylogging capability. | Input hooks, keylog files, suspicious handles, keyboard APIs, and subsequent credential use. | Do not declare credential theft without module or behavior evidence.1, 2 |
| T1071 / T1095 · Command and Control | HTTP, DNS, encrypted or non-application traffic and non-standard ports are reported; CISA observed plaintext HTTP on port 443 and ports 80/8080/53. | Port/protocol mismatch, PlugX header patterns, periodic POSTs, dynamic DNS, spoofed update domains, process/network mismatch. | Network format differs by variant.1, 2, 9 |
| T1041 · Exfiltration Over C2 | Family capability and historical campaigns support file transfer and staged exfiltration. | Archive/staging creation followed by outbound volume, cloud/file-hosting access, or command-channel transfer. | Requires local proof of data and transfer.2, 4, 5 |
- Question
- Is SOGU exactly the same as PlugX?
- Question
- Does a SOGU detection prove APT10?
- Question
- What should responders preserve first?
- Source-bound Answer
- When operationally safe, acquire memory and volatile process/module/socket state before isolation or cleanup. Then preserve the full executable/DLL/payload directory, signatures, hashes, timestamps, services, tasks, registry hives, execution artifacts, EDR history, network records, and identity/provider/client authentication telemetry.1, 2, 7, 9, 10
- Question
- How do we prove SOGU exists?
- Source-bound Answer
- State the proof level. File presence is Level 1. Level 2 needs loader or implant execution such as module loads, payload reads, decoded executable memory, injection, persistence, modules, or command traffic. Level 3 family identification should combine code/configuration, memory, plugin, YARA, decoder, or protocol evidence. Level 4 attribution needs separate campaign and intelligence evidence.1, 2, 9, 10
- Question
- What initial-access vectors should we investigate?
- Source-bound Answer
- Start with stolen administrator credentials, certificates, VPN/user impersonation, and provider trust for the CISA campaign. Then test sample-specific possibilities—malicious Office document/exploit, spear-phishing document, post-compromise download, or USB/LNK execution—only where local artifacts support them.1, 9, 10, 11
- Question
- Which CVE should be patched for SOGU?
- Question
- Does a clean antivirus scan close the case?
- Source-bound Answer
- No. CISA described variants with limited on-disk evidence and potential signature evasion. Closure requires behavioral, memory, persistence, network, identity, and downstream-system review.1
- Question
- Does execution prove data theft?
| Question | Source-bound Answer |
|---|---|
| Is SOGU exactly the same as PlugX? | CISA used the combined PLUGX/SOGU label. MITRE maintains PlugX as the software object. Treat SOGU as source-specific PlugX-related nomenclature unless sample analysis establishes a narrower distinction.1, 2 |
| Does a SOGU detection prove APT10? | No. APT10 is historically relevant, but PlugX-family malware is reused. Attribution needs campaign-specific evidence such as infrastructure, delivery, tooling combinations, victimology, code lineage, and timing.2, 3, 4, 6 |
| What should responders preserve first? | When operationally safe, acquire memory and volatile process/module/socket state before isolation or cleanup. Then preserve the full executable/DLL/payload directory, signatures, hashes, timestamps, services, tasks, registry hives, execution artifacts, EDR history, network records, and identity/provider/client authentication telemetry.1, 2, 7, 9, 10 |
| How do we prove SOGU exists? | State the proof level. File presence is Level 1. Level 2 needs loader or implant execution such as module loads, payload reads, decoded executable memory, injection, persistence, modules, or command traffic. Level 3 family identification should combine code/configuration, memory, plugin, YARA, decoder, or protocol evidence. Level 4 attribution needs separate campaign and intelligence evidence.1, 2, 9, 10 |
| What initial-access vectors should we investigate? | Start with stolen administrator credentials, certificates, VPN/user impersonation, and provider trust for the CISA campaign. Then test sample-specific possibilities—malicious Office document/exploit, spear-phishing document, post-compromise download, or USB/LNK execution—only where local artifacts support them.1, 9, 10, 11 |
| Which CVE should be patched for SOGU? | There is no malware-family CVE. Identify the actual delivery or privilege path in the incident, patch any supported vulnerability, and still complete malware eradication, credential recovery, and historical hunting.1, 2, 5 |
| Does a clean antivirus scan close the case? | No. CISA described variants with limited on-disk evidence and potential signature evasion. Closure requires behavioral, memory, persistence, network, identity, and downstream-system review.1 |
| Does execution prove data theft? | No. Execution creates capability and risk. Confirm collection, staging, archive creation, transfer, destination, timing, and affected data before making an exfiltration claim.2, 4, 5 |
SOGU is malware, not a vulnerability. CVEs enter the brief only as delivery or escalation facts in a specific campaign or sample and must not be generalized to the family.
- Reference
- SOGU / PlugX family
- Role
- Malware identification
- What It Establishes
- A remote-access implant and loader architecture, not a software flaw.
- Reference
- CVE-2012-0158
- Role
- Sample-specific document delivery
- What It Establishes
- Unit 42 analyzed malicious Word and Excel documents exploiting this flaw to execute droppers that installed a PlugX triad.
- Boundary
- It applies to those samples; it is not the universal SOGU entry vector.9
- Reference
- CVE-2013-3906
- Role
- Historical campaign infrastructure context
- What It Establishes
- Unit 42 noted prior PlugX delivery associated with infrastructure also seen in its analyzed samples.
- Boundary
- Shared infrastructure history does not prove this CVE in another incident.9
- Reference
- CVE-2020-1472 · ZeroLogon
- Role
- Separate APT10 campaign escalation
- What It Establishes
- Symantec saw a tool capable of exploiting ZeroLogon in a 2019-2020 Cicada/APT10 campaign.
- Boundary
- It is not an inherent SOGU vulnerability and does not prove the implant's delivery.5
- Reference
- Local CVE hypothesis
- Role
- Incident-specific entry or privilege path
- What It Establishes
- Only verified product/version exposure, exploitation telemetry, compatible artifacts, and timing can connect a CVE to the incident.
| Reference | Role | What It Establishes | Boundary |
|---|---|---|---|
| SOGU / PlugX family | Malware identification | A remote-access implant and loader architecture, not a software flaw. | There is no dedicated family CVE or family-level KEV entry.1, 2 |
| CVE-2012-0158 | Sample-specific document delivery | Unit 42 analyzed malicious Word and Excel documents exploiting this flaw to execute droppers that installed a PlugX triad. | It applies to those samples; it is not the universal SOGU entry vector.9 |
| CVE-2013-3906 | Historical campaign infrastructure context | Unit 42 noted prior PlugX delivery associated with infrastructure also seen in its analyzed samples. | Shared infrastructure history does not prove this CVE in another incident.9 |
| CVE-2020-1472 · ZeroLogon | Separate APT10 campaign escalation | Symantec saw a tool capable of exploiting ZeroLogon in a 2019-2020 Cicada/APT10 campaign. | It is not an inherent SOGU vulnerability and does not prove the implant's delivery.5 |
| Local CVE hypothesis | Incident-specific entry or privilege path | Only verified product/version exposure, exploitation telemetry, compatible artifacts, and timing can connect a CVE to the incident. | Patching closes the flaw, not implant persistence, stolen credentials, or historical access.1, 2 |
Concrete indicators are grouped by their exact source and variant. Defang network values for publication; normalize them only inside approved security tooling. A match is a hunt lead, not automatic proof of execution or attribution. Validate current IP/domain ownership, file role, path, signature, and surrounding telemetry before blocking or declaring compromise.
- IOC Type
- IPv4 · C2 / sinkhole
- Specific Indicator(s)
- 45.142.166[.]112
- Source / Hunt Context
- Hard-coded C2 for the USB-propagating Mustang Panda PlugX variant. Sekoia.io acquired and sinkholed it in September 2023; the FBI/French operation used it to deliver the native self-delete command.
- IOC Type
- IPv4 · Related
- Specific Indicator(s)
- 45.251.240[.]55; 103.56.53[.]46; 43.254.217[.]165
- Source / Hunt Context
- Published by Sekoia.io with the separate Mustang Panda-associated PlugX worm IOC set.
- Lifecycle / Boundary
- Variant-specific and historical. 103.56.53[.]46 appeared sinkholed when researched. Validate current ownership and traffic context before blocking.13
- IOC Type
- Domain · C2
- Specific Indicator(s)
- windowsupdates.dnset[.]com
- Source / Hunt Context
- CISA's 2017 PLUGX/SOGU record includes sample implant communication to this spoofed update-themed domain.
- Lifecycle / Boundary
- Historical SOGU-specific campaign observable. Recheck present resolution, ownership, and passive-DNS history before control action.1
- IOC Type
- Domains · C2
- Specific Indicator(s)
- capser.zues[.]info; casper.bacguarp[.]com; auto.bacguarp[.]com; fas2t.bacguarp[.]com; fast.bacguarp[.]com; fast2.bacguarp[.]com; ftp.bacguarp[.]com; istore.bacguarp[.]com; line.bacguarp[.]com; rfa.bacguarp[.]com; scqf.bacguarp[.]com; ser.bacguarp[.]com; web.bacguarp[.]com; www1.bacguarp[.]com
- Source / Hunt Context
- Unit 42 Samsung RunHelp / ssMUIDLL PlugX configurations and related historical infrastructure.
- Lifecycle / Boundary
- 2014-2015 sample-specific infrastructure; not a universal SOGU list. Validate present ownership and avoid retroactive actor merging.9
- IOC Type
- SHA-256 · Malware
- Specific Indicator(s)
- 432a07eb49473fa8c71d50ccaf2bc980b692d458ec4aaedd52d739cb377f3428; e8f55d0f327fd1d5f26428b890ef7fe878e135d494acda24ef01c695a2e9136d; 3a53bd36b24bc40bdce289d26f1b6965c0a5e71f26b05d19c7aa73d9e3cfa6ff; 2304891f176a92c62f43d9fd30cae943f1521394dce792c6de0e097d10103d45; 8b8adc6c14ed3bbeacd9f39c4d1380835eaf090090f6f826341a018d6b2ad450; 6bb959c33fdfc0086ac48586a73273a0a1331f1c4f0053ef021eebe7f377a292; b9f3cf9d63d2e3ce1821f2e3eb5acd6e374ea801f9c212eebfa734bd649bec7a
- Source / Hunt Context
- Sekoia.io's published PlugX USB-worm malware set used to support detection and the sovereign-disinfection research.
- Lifecycle / Boundary
- Separate Mustang Panda-associated variant. A match does not identify historical PLUGX/SOGU or APT10 activity.13
- IOC Type
- SHA-256 · Malware
- Specific Indicator(s)
- 8ec37dac2beaa494dcefec62f0bf4ae30a6ce44b27a588169d8f0476bbc94115; e72e49dc1d95efabc2c12c46df373173f2e20dab715caf58b1be9ca41ec0e172; 0e9071714a4af0be1f96cffc3b0e58520b827d9e58297cb0e02d97551eca3799; 39280139735145ba6f0918b684ab664a3de7f93b1e3ebcdd071a5300486b8d20; 41a0407371124bcad7cab56227078ccd635ba6e6b4374b973754af96b7f58119; 02aa5b52137410de7cc26747f26e07b65c936d019ee2e1afae268a00e78a1f7f; 2a07877cb53404888e1b6f81bb07a35bc804daa1439317bccde9c498a521644c; 5d98d1193fcbb2479668a24697023829fc9dc1f7d31833c3c42b8380ef859ff1
- Source / Hunt Context
- Unit 42's 2023 known PlugX USB sample set. e72e49... is the documented x32bridge.dat encrypted payload; 5b4969... is a related in-memory DLL variant with document-copying capability.
- Lifecycle / Boundary
- USB-variant-specific. Use exact hash plus file role, path, and execution evidence.10
- IOC Type
- MD5 · Loader triad
- Specific Indicator(s)
- VeetlePlayer.exe — 9d0da088d2bb135611b5450554c99672; libvlc.dll — 9a8c76271210324d97a232974ca0a6a3; mtcReport.ktc — 3045e77e1e9cf9d9657aea71ab5e8947
- Source / Hunt Context
- Exact three-file execution set published in CISA's 2017 multi-victim record: legitimate launcher, malicious DLL loader/decoder, and encoded shellcode/implant file.
- Lifecycle / Boundary
- Historical PLUGX/SOGU campaign set. VeetlePlayer.exe must be interpreted by hash, path, adjacency, and module load—not filename alone.1
- IOC Type
- SHA-256 · DLL
- Specific Indicator(s)
- ssMUIDLL.dll — 968e62874d105132bb542e7a72f5416886ed23dc75e52a673e2d23ad905fecf6; ssMUIDLL.dll — 94defa567302c753d9c4f7f3573270eff0b1e4a5d8ec6873887e680a93ed6ddb
- Source / Hunt Context
- Malicious PlugX DLL loaders side-loaded by Samsung's legitimate RunHelp.exe in two analyzed samples.
- Lifecycle / Boundary
- Malicious sample hashes. RunHelp.exe itself is a legitimate signed application and must not be blocked generically.9
- IOC Type
- SHA-256 · Payload
- Specific Indicator(s)
- ssMUIDLL.dll.conf — 92c806d3a98ddced7f3790fcf33c77e573d46ca85a43403bf2c97670f68d05e3; ssMUIDLL.dll.conf — 423d1da057ac708c9ba2f9b1243fcbecd8772e0b06f87d011f6e1868393fe9f5
- Source / Hunt Context
- Encrypted PlugX functional-code files decrypted by the malicious ssMUIDLL.dll loaders.
- Lifecycle / Boundary
- Sample-specific malicious payloads; collect alongside the loader and launcher.9
- IOC Type
- SHA-256 · Delivery
- Specific Indicator(s)
- 雨傘達動後教會生 態.doc — 57dba34482a0aa3ae2c092a40c709f7e5e5ba5c8a06202a6b1716fa1fdbd1a77; 1.xls — c97c3d53e9ac95ba01aa8bc85c6c8cb792b2d3dba68d7d8912e01f1e62645b71; word.exe — b560b974497bc64f68e6a1cebc6f137f73d6e2b282de9b6627a707ae7722fd7d; 7.tmp — be855efc2a5f7dcee98a7870e009747940a231f5389380a72565759ca6fdb68f
- Source / Hunt Context
- Unit 42 delivery documents and droppers exploiting CVE-2012-0158 in the Samsung side-loading cases.
- Lifecycle / Boundary
- 2014-2015 delivery samples; not the universal SOGU access vector.9
- IOC Type
- Files · USB chain
- Specific Indicator(s)
- x32dbg.exe; x32dbge.exe; Mediae.exe; Aug.exe; Precious.exe; SafeGuard.exe; Dism.exe; x32bridge.dll; x32bridge.dat; akm.dat; precious.dat; Groza_1.dat; desktop.ini
- Source / Hunt Context
- Unit 42 observed benign executables abused for loading plus malicious DLL/encrypted-payload and USB-masquerading filenames. Correlate exact combinations: x32dbg.exe → x32bridge.dll → x32bridge.dat is one documented chain.
- Lifecycle / Boundary
- Several executable names are legitimate or easily renamed. Require path, signature, adjacent components, module loads, and hashes.10
- IOC Type
- Paths · USB / host
- Specific Indicator(s)
- <USB>:\u00A0\u00A0\RECYCLER.BIN\files; <USB>:\u00A0\u00A0\RECYCLER.BIN\files\da520e5; RECYCLER.BIN\1\CEFHelper.exe; C:\ProgramData\UsersDate\Windows_NT\Windows\user\Desktop\; C:\Users\Public\Public Mediae\; %USERPROFILE%\AvastSvcpCP\
- Source / Hunt Context
- Hidden no-break-space USB paths, document-staging folder, Sekoia LNK target, and known host directories from Unit 42/Sekoia worm research.
- IOC Type
- Persistence
- Specific Indicator(s)
- HKCU\...\CurrentVersion\Run; HKLM\SOFTWARE\BINARY\ssMUIDLL.dll.conf; HKCU\SOFTWARE\BINARY\ssMUIDLL.dll.conf; service ABC; scheduled tasks LKUFORYOU_1 and PRECIOUS_0.1
- Source / Hunt Context
- Mustang Panda worm autorun; Samsung sample registry-stored payload and service; Unit 42 USB-variant scheduled tasks.
- IOC Type
- Mutexes
- Specific Indicator(s)
- LKU_Test_0.1; LKU_Test_0.2; TCP_0.1
- Source / Hunt Context
- Known Windows mutex names published with Unit 42's PlugX USB sample set.
- Lifecycle / Boundary
- Variant-specific runtime leads; absence does not exclude another PlugX variant.10
- IOC Type
- LNK / YARA string
- Specific Indicator(s)
- RECYCLER.BIN\1\CEFHelper.exe; LNK file size < 2 KB; big-endian header check 0x4c000000
- Source / Hunt Context
- Sekoia.io's public apt_MustangPanda_PlugXWorm_lnk rule detects the embedded wide-string path in a small Windows shortcut.
- Lifecycle / Boundary
- High-value worm-specific artifact. Confirm the full LNK target, arguments, volume path, and associated triad.13
- IOC Type
- HTTP · Beacon
- Specific Indicator(s)
- POST /[a-f0-9]{8}; jsp-se; jsp-st; jsp-si; jsp-sn; hard-coded User-Agent 'Mozilla/5.0 (Windows NT 10.0;Win64;x64)AppleWebKit/537.36'; TCP/HTTP ports 110, 443, and 80
- Source / Hunt Context
- Sekoia.io discriminators for the Mustang Panda-associated PlugX worm contacting 45.142.166[.]112.
- Lifecycle / Boundary
- Protocol and variant-specific. Header-name combinations and process-to-destination mapping are stronger than the common User-Agent alone.13
- IOC Type
- HTTP/TCP · Protocol
- Specific Indicator(s)
- POST /update?id=<8 hex>; HX1/HX2/HX3/HX4; X-Session/X-Status/X-Size/X-Sn; MJ1X/MJ2X/MJ3X/MJ4X; plaintext HTTP observed on TCP 443; ports 80, 8080, and 53
- Source / Hunt Context
- CISA-published historical PLUGX network signatures and port observations.
- Lifecycle / Boundary
- Historical variant signatures. Validate full header sequence, flow direction, process, destination, and payload before escalation.1
- IOC Type
- File · Remediation
- Specific Indicator(s)
- %TEMP%\del_AsvastSvcpCP.bat; native command ID 0x1005
- Source / Hunt Context
- Temporary batch file and native self-delete command documented in Sekoia.io's reverse engineering and the FBI removal workflow.
| IOC Type | Specific Indicator(s) | Source / Hunt Context | Lifecycle / Boundary |
|---|---|---|---|
| IPv4 · C2 / sinkhole | 45.142.166[.]112 | Hard-coded C2 for the USB-propagating Mustang Panda PlugX variant. Sekoia.io acquired and sinkholed it in September 2023; the FBI/French operation used it to deliver the native self-delete command. | Sinkholed / remediation infrastructure after September 2023. Historical contact remains high-value evidence; do not describe the current address as attacker-controlled without revalidation.6, 12, 13 |
| IPv4 · Related | 45.251.240[.]55; 103.56.53[.]46; 43.254.217[.]165 | Published by Sekoia.io with the separate Mustang Panda-associated PlugX worm IOC set. | Variant-specific and historical. 103.56.53[.]46 appeared sinkholed when researched. Validate current ownership and traffic context before blocking.13 |
| Domain · C2 | windowsupdates.dnset[.]com | CISA's 2017 PLUGX/SOGU record includes sample implant communication to this spoofed update-themed domain. | Historical SOGU-specific campaign observable. Recheck present resolution, ownership, and passive-DNS history before control action.1 |
| Domains · C2 | capser.zues[.]info; casper.bacguarp[.]com; auto.bacguarp[.]com; fas2t.bacguarp[.]com; fast.bacguarp[.]com; fast2.bacguarp[.]com; ftp.bacguarp[.]com; istore.bacguarp[.]com; line.bacguarp[.]com; rfa.bacguarp[.]com; scqf.bacguarp[.]com; ser.bacguarp[.]com; web.bacguarp[.]com; www1.bacguarp[.]com | Unit 42 Samsung RunHelp / ssMUIDLL PlugX configurations and related historical infrastructure. | 2014-2015 sample-specific infrastructure; not a universal SOGU list. Validate present ownership and avoid retroactive actor merging.9 |
| SHA-256 · Malware | 432a07eb49473fa8c71d50ccaf2bc980b692d458ec4aaedd52d739cb377f3428; e8f55d0f327fd1d5f26428b890ef7fe878e135d494acda24ef01c695a2e9136d; 3a53bd36b24bc40bdce289d26f1b6965c0a5e71f26b05d19c7aa73d9e3cfa6ff; 2304891f176a92c62f43d9fd30cae943f1521394dce792c6de0e097d10103d45; 8b8adc6c14ed3bbeacd9f39c4d1380835eaf090090f6f826341a018d6b2ad450; 6bb959c33fdfc0086ac48586a73273a0a1331f1c4f0053ef021eebe7f377a292; b9f3cf9d63d2e3ce1821f2e3eb5acd6e374ea801f9c212eebfa734bd649bec7a | Sekoia.io's published PlugX USB-worm malware set used to support detection and the sovereign-disinfection research. | Separate Mustang Panda-associated variant. A match does not identify historical PLUGX/SOGU or APT10 activity.13 |
| SHA-256 · Malware | 8ec37dac2beaa494dcefec62f0bf4ae30a6ce44b27a588169d8f0476bbc94115; e72e49dc1d95efabc2c12c46df373173f2e20dab715caf58b1be9ca41ec0e172; 0e9071714a4af0be1f96cffc3b0e58520b827d9e58297cb0e02d97551eca3799; 39280139735145ba6f0918b684ab664a3de7f93b1e3ebcdd071a5300486b8d20; 41a0407371124bcad7cab56227078ccd635ba6e6b4374b973754af96b7f58119; 02aa5b52137410de7cc26747f26e07b65c936d019ee2e1afae268a00e78a1f7f; 2a07877cb53404888e1b6f81bb07a35bc804daa1439317bccde9c498a521644c; 5d98d1193fcbb2479668a24697023829fc9dc1f7d31833c3c42b8380ef859ff1 | Unit 42's 2023 known PlugX USB sample set. e72e49... is the documented x32bridge.dat encrypted payload; 5b4969... is a related in-memory DLL variant with document-copying capability. | USB-variant-specific. Use exact hash plus file role, path, and execution evidence.10 |
| MD5 · Loader triad | VeetlePlayer.exe — 9d0da088d2bb135611b5450554c99672; libvlc.dll — 9a8c76271210324d97a232974ca0a6a3; mtcReport.ktc — 3045e77e1e9cf9d9657aea71ab5e8947 | Exact three-file execution set published in CISA's 2017 multi-victim record: legitimate launcher, malicious DLL loader/decoder, and encoded shellcode/implant file. | Historical PLUGX/SOGU campaign set. VeetlePlayer.exe must be interpreted by hash, path, adjacency, and module load—not filename alone.1 |
| SHA-256 · DLL | ssMUIDLL.dll — 968e62874d105132bb542e7a72f5416886ed23dc75e52a673e2d23ad905fecf6; ssMUIDLL.dll — 94defa567302c753d9c4f7f3573270eff0b1e4a5d8ec6873887e680a93ed6ddb | Malicious PlugX DLL loaders side-loaded by Samsung's legitimate RunHelp.exe in two analyzed samples. | Malicious sample hashes. RunHelp.exe itself is a legitimate signed application and must not be blocked generically.9 |
| SHA-256 · Payload | ssMUIDLL.dll.conf — 92c806d3a98ddced7f3790fcf33c77e573d46ca85a43403bf2c97670f68d05e3; ssMUIDLL.dll.conf — 423d1da057ac708c9ba2f9b1243fcbecd8772e0b06f87d011f6e1868393fe9f5 | Encrypted PlugX functional-code files decrypted by the malicious ssMUIDLL.dll loaders. | Sample-specific malicious payloads; collect alongside the loader and launcher.9 |
| SHA-256 · Delivery | 雨傘達動後教會生 態.doc — 57dba34482a0aa3ae2c092a40c709f7e5e5ba5c8a06202a6b1716fa1fdbd1a77; 1.xls — c97c3d53e9ac95ba01aa8bc85c6c8cb792b2d3dba68d7d8912e01f1e62645b71; word.exe — b560b974497bc64f68e6a1cebc6f137f73d6e2b282de9b6627a707ae7722fd7d; 7.tmp — be855efc2a5f7dcee98a7870e009747940a231f5389380a72565759ca6fdb68f | Unit 42 delivery documents and droppers exploiting CVE-2012-0158 in the Samsung side-loading cases. | 2014-2015 delivery samples; not the universal SOGU access vector.9 |
| Files · USB chain | x32dbg.exe; x32dbge.exe; Mediae.exe; Aug.exe; Precious.exe; SafeGuard.exe; Dism.exe; x32bridge.dll; x32bridge.dat; akm.dat; precious.dat; Groza_1.dat; desktop.ini | Unit 42 observed benign executables abused for loading plus malicious DLL/encrypted-payload and USB-masquerading filenames. Correlate exact combinations: x32dbg.exe → x32bridge.dll → x32bridge.dat is one documented chain. | Several executable names are legitimate or easily renamed. Require path, signature, adjacent components, module loads, and hashes.10 |
| Paths · USB / host | <USB>:\u00A0\u00A0\RECYCLER.BIN\files; <USB>:\u00A0\u00A0\RECYCLER.BIN\files\da520e5; RECYCLER.BIN\1\CEFHelper.exe; C:\ProgramData\UsersDate\Windows_NT\Windows\user\Desktop\; C:\Users\Public\Public Mediae\; %USERPROFILE%\AvastSvcpCP\ | Hidden no-break-space USB paths, document-staging folder, Sekoia LNK target, and known host directories from Unit 42/Sekoia worm research. | Preserve Unicode U+00A0 exactly. Inspect USB media with forensic or Unix-like tooling because Windows Explorer and cmd.exe may conceal the structure.10, 13 |
| Persistence | HKCU\...\CurrentVersion\Run; HKLM\SOFTWARE\BINARY\ssMUIDLL.dll.conf; HKCU\SOFTWARE\BINARY\ssMUIDLL.dll.conf; service ABC; scheduled tasks LKUFORYOU_1 and PRECIOUS_0.1 | Mustang Panda worm autorun; Samsung sample registry-stored payload and service; Unit 42 USB-variant scheduled tasks. | These belong to different variants. Preserve full key value, executable path, task XML, service image path, timestamps, and creator telemetry.9, 10, 12, 13 |
| Mutexes | LKU_Test_0.1; LKU_Test_0.2; TCP_0.1 | Known Windows mutex names published with Unit 42's PlugX USB sample set. | Variant-specific runtime leads; absence does not exclude another PlugX variant.10 |
| LNK / YARA string | RECYCLER.BIN\1\CEFHelper.exe; LNK file size < 2 KB; big-endian header check 0x4c000000 | Sekoia.io's public apt_MustangPanda_PlugXWorm_lnk rule detects the embedded wide-string path in a small Windows shortcut. | High-value worm-specific artifact. Confirm the full LNK target, arguments, volume path, and associated triad.13 |
| HTTP · Beacon | POST /[a-f0-9]{8}; jsp-se; jsp-st; jsp-si; jsp-sn; hard-coded User-Agent 'Mozilla/5.0 (Windows NT 10.0;Win64;x64)AppleWebKit/537.36'; TCP/HTTP ports 110, 443, and 80 | Sekoia.io discriminators for the Mustang Panda-associated PlugX worm contacting 45.142.166[.]112. | Protocol and variant-specific. Header-name combinations and process-to-destination mapping are stronger than the common User-Agent alone.13 |
| HTTP/TCP · Protocol | POST /update?id=<8 hex>; HX1/HX2/HX3/HX4; X-Session/X-Status/X-Size/X-Sn; MJ1X/MJ2X/MJ3X/MJ4X; plaintext HTTP observed on TCP 443; ports 80, 8080, and 53 | CISA-published historical PLUGX network signatures and port observations. | Historical variant signatures. Validate full header sequence, flow direction, process, destination, and payload before escalation.1 |
| File · Remediation | %TEMP%\del_AsvastSvcpCP.bat; native command ID 0x1005 | Temporary batch file and native self-delete command documented in Sekoia.io's reverse engineering and the FBI removal workflow. | Can indicate court-authorized or other self-deletion rather than active attacker execution. Correlate with January 2025 ISP/FBI notice, sinkhole contact, process termination, and surrounding evidence.6, 12, 13 |
- Actor / Label
- menuPass / APT10 / Stone Panda / Cicada
- Relationship To This Brief
- MITRE-associated names for G0045; historically relevant to provider targeting, PlugX-related activity, side-loading, credential theft, and espionage.
- Permitted Analytic Use
- Historical threat model and attribution hypothesis when compatible campaign evidence exists.
- Actor / Label
- Mustang Panda / Twill Typhoon
- Relationship To This Brief
- DOJ attributed a specific PlugX version removed in the 2025 court-authorized operation to this separate actor.
- Permitted Analytic Use
- Demonstrates multi-actor family reuse and informs variant-specific scoping.
- Boundary
- Do not merge this operator with APT10.6
- Actor / Label
- Other PlugX users
- Relationship To This Brief
- MITRE documents the family across multiple groups and campaigns.
- Permitted Analytic Use
- Pivot to sample code, configuration, delivery, infrastructure, victimology, and companion tools.
- Boundary
- The family is not an exclusive actor fingerprint.2
- Actor / Label
- Government sponsorship
- Relationship To This Brief
- Government and vendor sources make actor-specific sponsorship assessments in particular records.
- Permitted Analytic Use
- Retain the source, confidence, time, and evidentiary basis of the specific assessment.
| Actor / Label | Relationship To This Brief | Permitted Analytic Use | Boundary |
|---|---|---|---|
| menuPass / APT10 / Stone Panda / Cicada | MITRE-associated names for G0045; historically relevant to provider targeting, PlugX-related activity, side-loading, credential theft, and espionage. | Historical threat model and attribution hypothesis when compatible campaign evidence exists. | SOGU or PlugX presence alone does not prove G0045.3, 4, 5 |
| Mustang Panda / Twill Typhoon | DOJ attributed a specific PlugX version removed in the 2025 court-authorized operation to this separate actor. | Demonstrates multi-actor family reuse and informs variant-specific scoping. | Do not merge this operator with APT10.6 |
| Other PlugX users | MITRE documents the family across multiple groups and campaigns. | Pivot to sample code, configuration, delivery, infrastructure, victimology, and companion tools. | The family is not an exclusive actor fingerprint.2 |
| Government sponsorship | Government and vendor sources make actor-specific sponsorship assessments in particular records. | Retain the source, confidence, time, and evidentiary basis of the specific assessment. | Local malware detection does not inherit sponsorship automatically.4, 5, 6 |
- Audience
- Executives / board
- Decision-ready Message
- We are investigating a potential remote-access and espionage foothold. The immediate business question is whether it reached privileged identities, management systems, clients, or sensitive data—not who we think operated it.
- Evidence To Have Ready
- Proof level, affected systems, trust paths, containment state, material data findings, and major gaps.
- Audience
- SOC / threat hunting
- Decision-ready Message
- Hunt the full chain: access hypothesis, legitimate executable, malicious DLL, encoded payload, memory execution, persistence, command channel, identity use, lateral movement, and staging.
- Evidence To Have Ready
- EDR, memory, module loads, host artifacts, DNS/proxy/PCAP, identity and remote-service logs.
- Audience
- IT / endpoint
- Decision-ready Message
- Do not delete the triad or rebuild before volatile collection unless operational risk requires immediate isolation. Preserve exact paths, signatures, timestamps, services, tasks, and registry state.
- Evidence To Have Ready
- Chain of custody, acquisition log, hashes, system role, backup state, and recovery image provenance.
- Audience
- Identity / network
- Decision-ready Message
- Treat the host's credentials, certificates, active sessions, and administrative reach as potentially exposed; recover trust from clean systems in dependency order.
- Evidence To Have Ready
- Credential matrix, privilege map, sign-in timeline, token/session inventory, provider/client reachability.
- Audience
- MSP / provider leadership
- Decision-ready Message
- A management or staging-host compromise creates a downstream client path. Scope each tenant and connection separately and communicate from confirmed reachability and access evidence.
- Evidence To Have Ready
- Tenant map, shared credentials/certificates, remote administration logs, client-specific access and data findings.
- Audience
- Legal / privacy / communications
- Decision-ready Message
- Use graduated language: artifact present, execution confirmed, family identified, access validated, persistence confirmed, data collected, or transfer confirmed.
- Evidence To Have Ready
- Source-backed timeline, data map, affected-party matrix, attribution confidence, and unresolved gaps.
| Audience | Decision-ready Message | Evidence To Have Ready | Avoid Saying |
|---|---|---|---|
| Executives / board | We are investigating a potential remote-access and espionage foothold. The immediate business question is whether it reached privileged identities, management systems, clients, or sensitive data—not who we think operated it. | Proof level, affected systems, trust paths, containment state, material data findings, and major gaps. | A malware name proves a nation-state breach.1, 2, 4 |
| SOC / threat hunting | Hunt the full chain: access hypothesis, legitimate executable, malicious DLL, encoded payload, memory execution, persistence, command channel, identity use, lateral movement, and staging. | EDR, memory, module loads, host artifacts, DNS/proxy/PCAP, identity and remote-service logs. | No hash hit means no compromise.1, 2, 9, 10 |
| IT / endpoint | Do not delete the triad or rebuild before volatile collection unless operational risk requires immediate isolation. Preserve exact paths, signatures, timestamps, services, tasks, and registry state. | Chain of custody, acquisition log, hashes, system role, backup state, and recovery image provenance. | The signed executable is malicious by itself.1, 9 |
| Identity / network | Treat the host's credentials, certificates, active sessions, and administrative reach as potentially exposed; recover trust from clean systems in dependency order. | Credential matrix, privilege map, sign-in timeline, token/session inventory, provider/client reachability. | Password reset alone closes the incident.1, 4 |
| MSP / provider leadership | A management or staging-host compromise creates a downstream client path. Scope each tenant and connection separately and communicate from confirmed reachability and access evidence. | Tenant map, shared credentials/certificates, remote administration logs, client-specific access and data findings. | Every managed client was compromised.1, 4 |
| Legal / privacy / communications | Use graduated language: artifact present, execution confirmed, family identified, access validated, persistence confirmed, data collected, or transfer confirmed. | Source-backed timeline, data map, affected-party matrix, attribution confidence, and unresolved gaps. | Capability equals actual data theft or attribution.2, 4, 6 |
- Decision
- Declare or expand an incident
- Minimum Evidence / Trigger
- Confirmed side-loaded execution, implant memory, command traffic, persistence, credential access, or related lateral movement.
- Likely Owner
- SOC / IR
- Decision
- Isolate a host or segment
- Minimum Evidence / Trigger
- Active control traffic, operator commands, additional payload transfer, spread, or sensitive-system reachability.
- Likely Owner
- IR / network operations
- Decision
- Rotate credentials
- Minimum Evidence / Trigger
- Keylogging, credential-store access, administrative use on the host, stolen-account behavior, or uncertain credential exposure on a confirmed implant.
- Likely Owner
- Identity / system owners
- Decision
- Rebuild or restore
- Minimum Evidence / Trigger
- Integrity cannot be proven, persistence is broad, privileged execution occurred, or critical evidence gaps prevent trustworthy eradication.
- Likely Owner
- IR / endpoint operations
- Decision
- Notify clients, regulators, or affected parties
- Minimum Evidence / Trigger
- Confirmed access, credential use, data exposure, contractual threshold, or legal reporting duty—not the malware name alone.
- Likely Owner
- Legal / privacy / leadership
| Decision | Minimum Evidence / Trigger | Likely Owner | Required Output |
|---|---|---|---|
| Declare or expand an incident | Confirmed side-loaded execution, implant memory, command traffic, persistence, credential access, or related lateral movement. | SOC / IR | Preserved evidence, incident timeline, affected assets, and confidence-rated scope.1, 2 |
| Isolate a host or segment | Active control traffic, operator commands, additional payload transfer, spread, or sensitive-system reachability. | IR / network operations | Containment record that preserves evidence and documents business impact.1, 2 |
| Rotate credentials | Keylogging, credential-store access, administrative use on the host, stolen-account behavior, or uncertain credential exposure on a confirmed implant. | Identity / system owners | Dependency-aware revocation, rotation, session invalidation, and reuse monitoring.2, 4 |
| Rebuild or restore | Integrity cannot be proven, persistence is broad, privileged execution occurred, or critical evidence gaps prevent trustworthy eradication. | IR / endpoint operations | Trusted image, controlled restoration, validation evidence, and heightened monitoring.1, 2 |
| Notify clients, regulators, or affected parties | Confirmed access, credential use, data exposure, contractual threshold, or legal reporting duty—not the malware name alone. | Legal / privacy / leadership | Evidence-based impact matrix and approved communication language.4, 5 |
- Technology / Trust Risk
- Unsafe DLL search and writable directories
- How It Is Exploited
- A trusted executable loads an attacker-placed DLL from the same, searched, or writable directory.
- Priority Control
- Directory-based application allowlisting, least-writable software paths, and image-load monitoring.
- Technology / Trust Risk
- Trust in signed executables
- How It Is Exploited
- A validly signed legitimate binary is abused as the loader, making process-name or signature-only allow rules insufficient.
- Priority Control
- Evaluate binary, path, loaded modules, parent, command line, and behavior together.
- Technology / Trust Risk
- Missing memory and module telemetry
- How It Is Exploited
- The decoded implant can execute only in memory and evade disk-focused scanning.
- Priority Control
- EDR image-load/memory visibility, volatile acquisition readiness, and centralized retention.
- Technology / Trust Risk
- Credential and certificate concentration
- How It Is Exploited
- Stolen administrator credentials, certificates, cached secrets, and provider identities create legitimate-looking access.
- Priority Control
- Least privilege, MFA, privileged-access workstations, restricted admin, certificate governance, and session monitoring.
- Technology / Trust Risk
- MSP and shared management trust
- How It Is Exploited
- A compromised provider system or identity can reach multiple customer environments.
- Priority Control
- Tenant isolation, unique credentials, jump hosts, scoped support access, and client-specific logging.
- Technology / Trust Risk
- Unrestricted server and endpoint egress
- How It Is Exploited
- Implants can communicate over web, DNS, encrypted or non-standard traffic, including protocol/port mismatch.
- Priority Control
- Restrict egress, log process-to-network context, retain NetFlow/PCAP, and alert on first-seen destinations.
- Technology / Trust Risk
- Uncontrolled removable media
- How It Is Exploited
- A supported variant used hidden USB content and an LNK to launch the side-loading chain and copy it to the host.
- Priority Control
- Device control, LNK monitoring, removable-media imaging, and user execution restrictions.
- Validation Evidence
- USB serial/mount history, LNK target, copied triad, task creation, and module load.10
- Technology / Trust Risk
- Short or incomplete log retention
- How It Is Exploited
- Long dwell time and legitimate-looking credential use can outlast default endpoint, VPN, and network retention.
- Priority Control
- Centralize critical logs; retain sufficient host, identity, NetFlow, and packet evidence for historical review.
| Technology / Trust Risk | How It Is Exploited | Priority Control | Validation Evidence |
|---|---|---|---|
| Unsafe DLL search and writable directories | A trusted executable loads an attacker-placed DLL from the same, searched, or writable directory. | Directory-based application allowlisting, least-writable software paths, and image-load monitoring. | Binary path, DLL resolution, signature, ACL, installer provenance, and module-load event.1, 7, 9, 10 |
| Trust in signed executables | A validly signed legitimate binary is abused as the loader, making process-name or signature-only allow rules insufficient. | Evaluate binary, path, loaded modules, parent, command line, and behavior together. | Signer, catalog status, original path, loaded DLLs, adjacent files, and process behavior.1, 9 |
| Missing memory and module telemetry | The decoded implant can execute only in memory and evade disk-focused scanning. | EDR image-load/memory visibility, volatile acquisition readiness, and centralized retention. | Memory image, executable regions, injected code, threads, sockets, and decoded configuration.1, 2 |
| Credential and certificate concentration | Stolen administrator credentials, certificates, cached secrets, and provider identities create legitimate-looking access. | Least privilege, MFA, privileged-access workstations, restricted admin, certificate governance, and session monitoring. | Credential exposure matrix, sign-in timeline, privilege changes, token/certificate use, and reachability.1, 4 |
| MSP and shared management trust | A compromised provider system or identity can reach multiple customer environments. | Tenant isolation, unique credentials, jump hosts, scoped support access, and client-specific logging. | Provider/client topology, remote-access records, shared identities, and per-tenant activity.1, 4 |
| Unrestricted server and endpoint egress | Implants can communicate over web, DNS, encrypted or non-standard traffic, including protocol/port mismatch. | Restrict egress, log process-to-network context, retain NetFlow/PCAP, and alert on first-seen destinations. | DNS, proxy, firewall, NetFlow, PCAP, destination age, protocol, bytes, and process mapping.1, 2 |
| Uncontrolled removable media | A supported variant used hidden USB content and an LNK to launch the side-loading chain and copy it to the host. | Device control, LNK monitoring, removable-media imaging, and user execution restrictions. | USB serial/mount history, LNK target, copied triad, task creation, and module load.10 |
| Short or incomplete log retention | Long dwell time and legitimate-looking credential use can outlast default endpoint, VPN, and network retention. | Centralize critical logs; retain sufficient host, identity, NetFlow, and packet evidence for historical review. | Coverage matrix with source, fields, time span, integrity, and known gaps.1, 5 |
Source tiers express role, not a universal quality score. Government and primary technical sources control observed facts; framework records normalize behavior; secondary and social material can create leads but cannot expand confirmed scope.
- Tier
- Tier 0
- Trust Role
- Government incident, legal, and disruption authority
- Retained Sources
- CISA / US-CERT; U.S. Department of Justice
- What It Supports
- Observed campaign mechanics, access hierarchy, loader architecture, mitigations, charged APT10 conduct, separate removal-operation facts.
- Tier
- Tier 1
- Trust Role
- Primary vendor malware and campaign research
- Retained Sources
- Symantec / Broadcom; Palo Alto Networks Unit 42; Trend Micro
- What It Supports
- Sample-specific delivery, execution, persistence, code and protocol behavior, victimology, and attribution confidence.
- Tier
- Tier 2
- Trust Role
- Specialist corroboration
- Retained Sources
- Reviewed but not needed for core claims
- What It Supports
- Potential newer campaigns, sample pivots, and operational context.
- Tier
- Tier 3-4
- Trust Role
- News and broad awareness
- Retained Sources
- No baseline source selected
- What It Supports
- Discovery of public events and possible disclosures.
- Caveat
- Cannot establish code behavior, actor identity, victim impact, or remediation alone.1
- Tier
- Tier 5
- Trust Role
- Authoritative framework normalization
- Retained Sources
- MITRE ATT&CK software, group, loader, and technique records
- What It Supports
- Living capability, technique, group-name, and multi-actor context.
- Tier
- Tier 6-8
- Trust Role
- Community, social, and raw collection leads
- Retained Sources
- No source used for a core conclusion
- What It Supports
- Hash, filename, infrastructure, or victim leads for validation.
| Tier | Trust Role | Retained Sources | What It Supports | Caveat |
|---|---|---|---|---|
| Tier 0 | Government incident, legal, and disruption authority | CISA / US-CERT; U.S. Department of Justice | Observed campaign mechanics, access hierarchy, loader architecture, mitigations, charged APT10 conduct, separate removal-operation facts. | Historical records and legal allegations must retain dates and stated boundaries.1, 4, 6 |
| Tier 1 | Primary vendor malware and campaign research | Symantec / Broadcom; Palo Alto Networks Unit 42; Trend Micro | Sample-specific delivery, execution, persistence, code and protocol behavior, victimology, and attribution confidence. | One sample or campaign cannot define every SOGU or PlugX variant.5, 9, 10, 11 |
| Tier 2 | Specialist corroboration | Reviewed but not needed for core claims | Potential newer campaigns, sample pivots, and operational context. | Must trace claims back to primary evidence before changing the brief.1, 2 |
| Tier 3-4 | News and broad awareness | No baseline source selected | Discovery of public events and possible disclosures. | Cannot establish code behavior, actor identity, victim impact, or remediation alone.1 |
| Tier 5 | Authoritative framework normalization | MITRE ATT&CK software, group, loader, and technique records | Living capability, technique, group-name, and multi-actor context. | Aggregated capability is not proof that a behavior occurred locally.2, 3, 7, 8 |
| Tier 6-8 | Community, social, and raw collection leads | No source used for a core conclusion | Hash, filename, infrastructure, or victim leads for validation. | High collision, staleness, context loss, and attribution risk; never outranks local telemetry or primary reporting.1, 2 |
This card records where the retained sources agree, where they describe different layers, and which source controls when claims appear to conflict.
- Source Issue
- SOGU versus PlugX
- Agreement / Difference
- CISA uses a combined label; MITRE maintains PlugX as the current software object.
- Tension or Contradiction
- Public taxonomies do not consistently model SOGU as a separate object or universal alias.
- Source Issue
- Initial access
- Agreement / Difference
- CISA's observed campaign emphasizes stolen credentials, certificates, impersonation, and provider trust; vendor cases show document, exploit, download, and USB paths.
- Tension or Contradiction
- Those vectors come from different samples and campaigns.
- Source Issue
- Loader architecture
- Agreement / Difference
- Government and vendor sources repeatedly describe the legitimate executable, malicious DLL, and encoded payload model with memory decoding.
- Tension or Contradiction
- Names, binaries, encodings, services, tasks, directories, and protocol formats vary.
- Source Issue
- Disk scan versus execution
- Agreement / Difference
- Decoded implant content may exist only in memory and variants can resist static signatures.
- Tension or Contradiction
- A clean disk or antivirus result may coexist with strong volatile or network evidence.
- Source Issue
- Capability versus action
- Agreement / Difference
- CISA and MITRE document extensive modular capability.
- Tension or Contradiction
- Not every variant contains every module and capability does not prove operator use.
- Source Issue
- Family versus actor
- Agreement / Difference
- APT10 is historically relevant, while MITRE and DOJ also support broader family reuse.
- Tension or Contradiction
- A family match can be technically correct and actor attribution still wrong.
- Source Issue
- Malware versus CVE
- Agreement / Difference
- The malware family has no dedicated CVE; particular campaigns may exploit vulnerabilities.
- Tension or Contradiction
- A sample case can be misreported as a universal CVE relationship.
- Source Issue
- Access versus data loss
- Agreement / Difference
- The implant can search, capture, stage, and transfer data; historical campaigns include alleged or observed theft.
- Tension or Contradiction
- Capability, collection, staging, and exfiltration are different findings.
| Source Issue | Agreement / Difference | Tension or Contradiction | How To Use It |
|---|---|---|---|
| SOGU versus PlugX | CISA uses a combined label; MITRE maintains PlugX as the current software object. | Public taxonomies do not consistently model SOGU as a separate object or universal alias. | Treat SOGU as source-specific PlugX-related nomenclature and preserve the publisher's exact usage.1, 2 |
| Initial access | CISA's observed campaign emphasizes stolen credentials, certificates, impersonation, and provider trust; vendor cases show document, exploit, download, and USB paths. | Those vectors come from different samples and campaigns. | Rank CISA's credential/trust path highest for that campaign; test other vectors only when local evidence supports them.1, 9, 10, 11 |
| Loader architecture | Government and vendor sources repeatedly describe the legitimate executable, malicious DLL, and encoded payload model with memory decoding. | Names, binaries, encodings, services, tasks, directories, and protocol formats vary. | Detect the behavior pattern and retain sample-specific artifacts as scoped indicators.1, 9, 10, 11 |
| Disk scan versus execution | Decoded implant content may exist only in memory and variants can resist static signatures. | A clean disk or antivirus result may coexist with strong volatile or network evidence. | Do not close without memory, module, persistence, network, and identity review.1, 2 |
| Capability versus action | CISA and MITRE document extensive modular capability. | Not every variant contains every module and capability does not prove operator use. | Report modules and actions separately: available, observed, attempted, or confirmed.1, 2 |
| Family versus actor | APT10 is historically relevant, while MITRE and DOJ also support broader family reuse. | A family match can be technically correct and actor attribution still wrong. | Require infrastructure, delivery, code lineage, victimology, timing, and companion-tool evidence for attribution.2, 3, 4, 6 |
| Malware versus CVE | The malware family has no dedicated CVE; particular campaigns may exploit vulnerabilities. | A sample case can be misreported as a universal CVE relationship. | Track each delivery CVE only with affected-product, timing, exposure, and forensic support.1, 5, 9 |
| Access versus data loss | The implant can search, capture, stage, and transfer data; historical campaigns include alleged or observed theft. | Capability, collection, staging, and exfiltration are different findings. | Require local data, destination, byte, time, and repository evidence before declaring loss.1, 2, 4, 5 |
- Contributor
- CISA / US-CERT
- Who They Are / Role
- U.S. government incident and defensive authority
- Contribution and Why It Matters
- Controls the combined label, access hierarchy, three-file loader, memory-resident caveat, modules, network patterns, detection methods, and layered mitigations.
- Limit
- Historical campaign record; sample indicators can age.1
- Contributor
- MITRE ATT&CK
- Who They Are / Role
- Authoritative behavior and relationship framework
- Contribution and Why It Matters
- Normalizes PlugX software capability, DLL side-loading, HUI Loader, menuPass/APT10 naming, and multi-actor reuse.
- Contributor
- U.S. Department of Justice - APT10
- Who They Are / Role
- Government legal and attribution record
- Contribution and Why It Matters
- Provides the charged MSP and technology-theft campaign, credential and client-trust abuse, lateral movement, staging, sectors, and allegation boundary.
- Limit
- Charges are allegations and historical conduct.4
- Contributor
- Symantec / Broadcom
- Who They Are / Role
- Primary threat-hunting and campaign research
- Contribution and Why It Matters
- Provides later Cicada/APT10 campaign victimology, DLL side-loading, credential theft, living-off-the-land, staging, hashes, and medium-confidence attribution.
- Limit
- Multi-tool campaign; not every behavior is SOGU-specific.5
- Contributor
- U.S. Department of Justice - removal operation
- Who They Are / Role
- Government disruption and notification record
- Contribution and Why It Matters
- Shows a distinct Mustang Panda PlugX version, technical removal, U.S. scope, and victim notification.
- Limit
- Separate operator and variant from APT10.6
- Contributor
- Unit 42 - Samsung side-loading analysis
- Who They Are / Role
- Primary malware reverse engineering
- Contribution and Why It Matters
- Documents an exploit-driven malicious document, signed executable, DLL, encrypted payload, registry storage, Windows service persistence, and encrypted HTTP Cookie traffic.
- Limit
- Specific 2014-2015 samples.9
- Contributor
- Unit 42 - USB variant analysis
- Who They Are / Role
- Primary malware and removable-media research
- Contribution and Why It Matters
- Documents LNK execution, three-file side-loading, in-memory decryption, host/USB propagation, and scheduled-task persistence.
- Limit
- Specific variant; USB behavior is not universal.10
- Contributor
- Trend Micro
- Who They Are / Role
- Primary cyberespionage campaign research
- Contribution and Why It Matters
- Documents spear-phishing DOCX access and a three-file PlugX set used alongside other backdoors and shared infrastructure.
- Limit
- Campaign is broader than SOGU and includes multiple malware families.11
| Contributor | Who They Are / Role | Contribution and Why It Matters | Limit |
|---|---|---|---|
| CISA / US-CERT | U.S. government incident and defensive authority | Controls the combined label, access hierarchy, three-file loader, memory-resident caveat, modules, network patterns, detection methods, and layered mitigations. | Historical campaign record; sample indicators can age.1 |
| MITRE ATT&CK | Authoritative behavior and relationship framework | Normalizes PlugX software capability, DLL side-loading, HUI Loader, menuPass/APT10 naming, and multi-actor reuse. | Aggregates open-source reporting; does not prove local occurrence.2, 3, 7, 8 |
| U.S. Department of Justice - APT10 | Government legal and attribution record | Provides the charged MSP and technology-theft campaign, credential and client-trust abuse, lateral movement, staging, sectors, and allegation boundary. | Charges are allegations and historical conduct.4 |
| Symantec / Broadcom | Primary threat-hunting and campaign research | Provides later Cicada/APT10 campaign victimology, DLL side-loading, credential theft, living-off-the-land, staging, hashes, and medium-confidence attribution. | Multi-tool campaign; not every behavior is SOGU-specific.5 |
| U.S. Department of Justice - removal operation | Government disruption and notification record | Shows a distinct Mustang Panda PlugX version, technical removal, U.S. scope, and victim notification. | Separate operator and variant from APT10.6 |
| Unit 42 - Samsung side-loading analysis | Primary malware reverse engineering | Documents an exploit-driven malicious document, signed executable, DLL, encrypted payload, registry storage, Windows service persistence, and encrypted HTTP Cookie traffic. | Specific 2014-2015 samples.9 |
| Unit 42 - USB variant analysis | Primary malware and removable-media research | Documents LNK execution, three-file side-loading, in-memory decryption, host/USB propagation, and scheduled-task persistence. | Specific variant; USB behavior is not universal.10 |
| Trend Micro | Primary cyberespionage campaign research | Documents spear-phishing DOCX access and a three-file PlugX set used alongside other backdoors and shared infrastructure. | Campaign is broader than SOGU and includes multiple malware families.11 |
- Example
- 2017 multi-victim intrusions
- What It Shows
- Credential-led access, PLUGX/SOGU and RedLeaves deployment, memory-resident cases, and DLL side-loading across multiple victims.
- What It Does Not Prove
- It does not identify every affected organization or define every later SOGU sample.1
- Example
- Signed Samsung loader samples
- What It Shows
- Malicious Office documents exploited CVE-2012-0158, dropped a signed Samsung executable, malicious DLL, and encrypted payload, then stored payload material in the registry and created service persistence.
- What It Does Not Prove
- The signed Samsung file is legitimate; the abuse depends on malicious adjacent components and applies to the analyzed samples.9
- Example
- Removable-media PlugX variant
- What It Shows
- A USB LNK launched a legitimate executable, side-loaded a malicious DLL, decrypted a payload in memory, copied the chain to the host, and created scheduled-task persistence.
- What It Does Not Prove
- USB propagation is variant-specific and should not be assumed without matching artifacts.10
- Example
- DRBControl spear-phishing operation
- What It Shows
- Spear-phishing DOCX files established access in a broader cyberespionage operation that included a three-file PlugX set and other backdoors.
- What It Does Not Prove
- Shared campaign infrastructure and multi-malware use do not make every event SOGU-specific.11
- Example
- APT10 MSP theft campaign
- What It Shows
- How provider compromise, stolen administrative credentials, lateral movement, staging, and exfiltration can create downstream client risk.
- What It Does Not Prove
- It does not prove a current SOGU detection is APT10 or that every client was accessed.4
- Example
- Cicada Japan-linked campaign
- What It Shows
- Long dwell time, side-loading, living-off-the-land activity, domain-controller and file-server access, and intelligence collection.
- What It Does Not Prove
- The campaign used multiple tools and does not make every described behavior SOGU-specific.5
- Example
- 2025 PlugX removal operation
- What It Shows
- A distinct Mustang Panda version persisted on thousands of U.S. systems and required coordinated technical disruption and victim notice.
- What It Does Not Prove
- That population and actor attribution are separate from the historical APT10 record.6
| Example | What It Shows | What It Does Not Prove |
|---|---|---|
| 2017 multi-victim intrusions | Credential-led access, PLUGX/SOGU and RedLeaves deployment, memory-resident cases, and DLL side-loading across multiple victims. | It does not identify every affected organization or define every later SOGU sample.1 |
| Signed Samsung loader samples | Malicious Office documents exploited CVE-2012-0158, dropped a signed Samsung executable, malicious DLL, and encrypted payload, then stored payload material in the registry and created service persistence. | The signed Samsung file is legitimate; the abuse depends on malicious adjacent components and applies to the analyzed samples.9 |
| Removable-media PlugX variant | A USB LNK launched a legitimate executable, side-loaded a malicious DLL, decrypted a payload in memory, copied the chain to the host, and created scheduled-task persistence. | USB propagation is variant-specific and should not be assumed without matching artifacts.10 |
| DRBControl spear-phishing operation | Spear-phishing DOCX files established access in a broader cyberespionage operation that included a three-file PlugX set and other backdoors. | Shared campaign infrastructure and multi-malware use do not make every event SOGU-specific.11 |
| APT10 MSP theft campaign | How provider compromise, stolen administrative credentials, lateral movement, staging, and exfiltration can create downstream client risk. | It does not prove a current SOGU detection is APT10 or that every client was accessed.4 |
| Cicada Japan-linked campaign | Long dwell time, side-loading, living-off-the-land activity, domain-controller and file-server access, and intelligence collection. | The campaign used multiple tools and does not make every described behavior SOGU-specific.5 |
| 2025 PlugX removal operation | A distinct Mustang Panda version persisted on thousands of U.S. systems and required coordinated technical disruption and victim notice. | That population and actor attribution are separate from the historical APT10 record.6 |
This is a disclosure boundary, not a victim list. Organization-specific impact requires first-party confirmation or local evidence.
- Publicly Described Set
- 2017 multiple victims and sectors
- Status
- Aggregate government reporting
- How To Use It
- Use for campaign-era behavior and mitigation context; no complete public victim list is asserted.1
- Publicly Described Set
- APT10 MSP, technology, and government targets
- Status
- DOJ charges and allegations
- How To Use It
- Use the public legal record with its stated allegation boundary; do not transfer it to another incident.4
- Publicly Described Set
- Japan-linked organizations across 17 regions
- Status
- Vendor-observed campaign
- How To Use It
- Use sectors and geography for prioritization; do not infer unnamed organizations or current compromise.5
- Publicly Described Set
- Approximately 4,258 U.S. computers and networks
- Status
- Court-authorized malware removal
- How To Use It
- This figure applies to the specific Mustang Panda PlugX version removed in the operation, not to SOGU or PlugX globally.6
| Publicly Described Set | Status | How To Use It |
|---|---|---|
| 2017 multiple victims and sectors | Aggregate government reporting | Use for campaign-era behavior and mitigation context; no complete public victim list is asserted.1 |
| APT10 MSP, technology, and government targets | DOJ charges and allegations | Use the public legal record with its stated allegation boundary; do not transfer it to another incident.4 |
| Japan-linked organizations across 17 regions | Vendor-observed campaign | Use sectors and geography for prioritization; do not infer unnamed organizations or current compromise.5 |
| Approximately 4,258 U.S. computers and networks | Court-authorized malware removal | This figure applies to the specific Mustang Panda PlugX version removed in the operation, not to SOGU or PlugX globally.6 |
- Item
- SOGU / PlugX
- Status
- Malware, not a CVE
- Item
- CISA KEV
- Status
- No family-level entry
- Item
- CVE-2012-0158
- Status
- Exploit-driven delivery in analyzed Unit 42 samples
- Operational Meaning
- Hunt malicious Office documents, child processes, droppers, and the resulting triad only when the sample path and vulnerable product exposure align.9
- Item
- CVE-2020-1472
- Status
- Separate tool use in a Symantec-observed APT10 campaign
- Operational Meaning
- Treat as a campaign-specific escalation hypothesis, not a SOGU family property.5
- Item
- Other campaign-linked CVEs
- Status
- Source-specific
- Item
- Patch completion
- Status
- Not incident closure
| Item | Status | Operational Meaning |
|---|---|---|
| SOGU / PlugX | Malware, not a CVE | Track execution, persistence, credentials, command traffic, and data activity separately from vulnerability remediation.1, 2 |
| CISA KEV | No family-level entry | KEV is a vulnerability catalog and does not certify or rank malware families.1, 2 |
| CVE-2012-0158 | Exploit-driven delivery in analyzed Unit 42 samples | Hunt malicious Office documents, child processes, droppers, and the resulting triad only when the sample path and vulnerable product exposure align.9 |
| CVE-2020-1472 | Separate tool use in a Symantec-observed APT10 campaign | Treat as a campaign-specific escalation hypothesis, not a SOGU family property.5 |
| Other campaign-linked CVEs | Source-specific | Retain a CVE only when delivery, exploitation, timing, affected product, and local exposure are supported.1, 2, 3 |
| Patch completion | Not incident closure | Even when a delivery CVE is patched, responders must eradicate malware, rotate exposed credentials, and investigate historical access.1, 2 |
- Lifecycle Phase
- Initial access
- Source-backed Behavior
- CISA's campaign prioritized stolen administrator credentials, certificates, impersonation, and provider trust. Separate primary cases support malicious documents/exploits, spear phishing, post-compromise download, and USB/LNK execution.
- Lifecycle Phase
- Execution
- Source-backed Behavior
- A legitimate executable loads a malicious DLL that decodes and executes the implant payload.
- Lifecycle Phase
- Persistence
- Source-backed Behavior
- Reported variants can use services, scheduled tasks, registry autoruns, and startup locations.
- Defensive Breakpoint
- Baseline autoruns and validate every new persistence item against signed software deployment records.2
- Lifecycle Phase
- Defense evasion
- Source-backed Behavior
- Side-loading, masquerading, obfuscation, hidden execution, and memory-resident behavior can reduce signature visibility.
- Lifecycle Phase
- Discovery
- Source-backed Behavior
- Host, user, process, drive, file, network, service, software, and security-tool enumeration can prepare follow-on action.
- Lifecycle Phase
- Credential access
- Source-backed Behavior
- Some variants support keylogging; actor campaigns also use credential theft and stolen valid accounts.
- Lifecycle Phase
- Lateral movement
- Source-backed Behavior
- Related actor campaigns use valid accounts, RDP, WMI, SMB, provider trust, and remote administration paths.
- Lifecycle Phase
- Collection / staging
- Source-backed Behavior
- File search, screen or input capture, archive creation, and local or remote staging can prepare data for removal.
- Lifecycle Phase
- Command and control
- Source-backed Behavior
- Variants can use web, DNS, encrypted, non-application, or non-standard protocol channels.
- Defensive Breakpoint
- Restrict egress and alert on uncommon destinations, process-to-network anomalies, and encoded or beacon-like traffic.2
- Lifecycle Phase
- Exfiltration
- Source-backed Behavior
- PlugX-family capability and historical actor campaigns support transfer over command channels and staged exfiltration.
| Lifecycle Phase | Source-backed Behavior | Defensive Breakpoint |
|---|---|---|
| Initial access | CISA's campaign prioritized stolen administrator credentials, certificates, impersonation, and provider trust. Separate primary cases support malicious documents/exploits, spear phishing, post-compromise download, and USB/LNK execution. | Protect privileged and provider identities, govern certificates and remote access, inspect document/Office child processes, control removable media, and patch only supported delivery flaws.1, 9, 10, 11 |
| Execution | A legitimate executable loads a malicious DLL that decodes and executes the implant payload. | Alert on abnormal module loads, writable-directory execution, low-prevalence DLLs, and encoded adjacent files.1, 2, 7 |
| Persistence | Reported variants can use services, scheduled tasks, registry autoruns, and startup locations. | Baseline autoruns and validate every new persistence item against signed software deployment records.2 |
| Defense evasion | Side-loading, masquerading, obfuscation, hidden execution, and memory-resident behavior can reduce signature visibility. | Correlate signed-process behavior, image loads, memory, endpoint, and network telemetry.1, 2 |
| Discovery | Host, user, process, drive, file, network, service, software, and security-tool enumeration can prepare follow-on action. | Detect unusual discovery bursts after a new module load or first-seen outbound connection.2, 5 |
| Credential access | Some variants support keylogging; actor campaigns also use credential theft and stolen valid accounts. | Protect privileged sessions, limit credential exposure, monitor theft behaviors, and rotate based on host reachability.2, 4 |
| Lateral movement | Related actor campaigns use valid accounts, RDP, WMI, SMB, provider trust, and remote administration paths. | Segment administration, constrain provider access, and alert on new remote logons and service execution.3, 4, 5 |
| Collection / staging | File search, screen or input capture, archive creation, and local or remote staging can prepare data for removal. | Monitor sensitive repositories, archive utilities, staging directories, and unusual file-access volume.2, 4, 5 |
| Command and control | Variants can use web, DNS, encrypted, non-application, or non-standard protocol channels. | Restrict egress and alert on uncommon destinations, process-to-network anomalies, and encoded or beacon-like traffic.2 |
| Exfiltration | PlugX-family capability and historical actor campaigns support transfer over command channels and staged exfiltration. | Correlate staging with outbound volume, destination, authentication, and data-classification evidence.2, 4, 5 |
- Source
- CISA / US-CERT 2017 alert
- Weight
- Highest for observed alert
- Best Use
- Combined label, loader chain, memory caveat, campaign-era behaviors, mitigations, and public indicators.
- Limit
- Historical and campaign-specific; not a complete taxonomy of all variants.1
- Source
- MITRE PlugX S0013
- Weight
- High framework weight
- Best Use
- Living software capabilities, techniques, platforms, and multi-group use.
- Limit
- Aggregates reporting across variants; capability is not proof of action.2
- Source
- MITRE menuPass G0045
- Weight
- High actor-context weight
- Best Use
- APT10 aliases, sectors, historical techniques, software, and references.
- Limit
- Actor record does not attribute every PlugX-family incident.3
- Source
- DOJ APT10 case
- Weight
- High government attribution context
- Best Use
- Charged campaign scope, MSP path, credential theft, lateral movement, staging, and target sectors.
- Limit
- Legal allegations and historical conduct; not local compromise evidence.4
- Source
- Symantec Cicada research
- Weight
- High campaign research
- Best Use
- Observed victimology, side-loading, living-off-the-land activity, hashes, and medium-confidence attribution.
- Limit
- Multi-tool campaign; not every behavior is SOGU-specific.5
- Source
- DOJ 2025 removal
- Weight
- High for disruption facts
- Best Use
- Distinct Mustang Panda PlugX version, removal scope, and victim notification.
- Limit
- Separate operator and variant; not evidence for APT10 attribution.6
- Source
- MITRE DLL side-loading
- Weight
- High technique context
- Best Use
- Execution-flow definition and defensive mapping.
- Limit
- Technique is widely used and not actor-specific.7
- Source
- MITRE HUI Loader
- Weight
- Supporting context
- Best Use
- menuPass loader relationship, PlugX deployment, and DLL hijacking behavior.
- Limit
- HUI Loader is a separate malware object and should not be treated as SOGU itself.8
- Source
- Unit 42 Samsung side-loading analysis
- Weight
- High sample-analysis weight
- Best Use
- Exploit-driven delivery, signed-binary abuse, triad execution, memory decoding, registry storage, service persistence, and HTTP Cookie C2.
- Limit
- Specific samples and infrastructure; not universal family behavior.9
- Source
- Unit 42 USB variant analysis
- Weight
- High sample-analysis weight
- Best Use
- LNK execution, removable-media propagation, triad evidence, memory decryption, and scheduled-task persistence.
- Limit
- Variant-specific; USB behavior requires matching evidence.10
- Source
- Trend Micro DRBControl research
- Weight
- High campaign-research weight
- Best Use
- Spear-phishing access, three-file PlugX delivery, shared infrastructure, and multi-backdoor campaign context.
- Limit
- Broader operation; not every finding is SOGU-specific.11
| Source | Weight | Best Use | Limit |
|---|---|---|---|
| CISA / US-CERT 2017 alert | Highest for observed alert | Combined label, loader chain, memory caveat, campaign-era behaviors, mitigations, and public indicators. | Historical and campaign-specific; not a complete taxonomy of all variants.1 |
| MITRE PlugX S0013 | High framework weight | Living software capabilities, techniques, platforms, and multi-group use. | Aggregates reporting across variants; capability is not proof of action.2 |
| MITRE menuPass G0045 | High actor-context weight | APT10 aliases, sectors, historical techniques, software, and references. | Actor record does not attribute every PlugX-family incident.3 |
| DOJ APT10 case | High government attribution context | Charged campaign scope, MSP path, credential theft, lateral movement, staging, and target sectors. | Legal allegations and historical conduct; not local compromise evidence.4 |
| Symantec Cicada research | High campaign research | Observed victimology, side-loading, living-off-the-land activity, hashes, and medium-confidence attribution. | Multi-tool campaign; not every behavior is SOGU-specific.5 |
| DOJ 2025 removal | High for disruption facts | Distinct Mustang Panda PlugX version, removal scope, and victim notification. | Separate operator and variant; not evidence for APT10 attribution.6 |
| MITRE DLL side-loading | High technique context | Execution-flow definition and defensive mapping. | Technique is widely used and not actor-specific.7 |
| MITRE HUI Loader | Supporting context | menuPass loader relationship, PlugX deployment, and DLL hijacking behavior. | HUI Loader is a separate malware object and should not be treated as SOGU itself.8 |
| Unit 42 Samsung side-loading analysis | High sample-analysis weight | Exploit-driven delivery, signed-binary abuse, triad execution, memory decoding, registry storage, service persistence, and HTTP Cookie C2. | Specific samples and infrastructure; not universal family behavior.9 |
| Unit 42 USB variant analysis | High sample-analysis weight | LNK execution, removable-media propagation, triad evidence, memory decryption, and scheduled-task persistence. | Variant-specific; USB behavior requires matching evidence.10 |
| Trend Micro DRBControl research | High campaign-research weight | Spear-phishing access, three-file PlugX delivery, shared infrastructure, and multi-backdoor campaign context. | Broader operation; not every finding is SOGU-specific.11 |
CARDS Actor
Stone Panda / APT10 Actor Card
Canonical actor profile for associated names, source-backed targeting, tools, behaviors, indicators, and historical campaign context.
CARDS Directory
Threat Actor Directory
Browse actor and campaign records while keeping malware-family, campaign, and attribution identities distinct.
Published research notes
Public, read-only, source-backed context retained with this brief. No account or sign-in is required.
What the 2025 operation involved
The operation concerned a USB-propagating PlugX worm variant that the FBI attributed to Mustang Panda / Twill Typhoon. It was not identified as SOGU and was separate from the historical APT10 PLUGX/SOGU campaign. The variant infected Windows hosts and attached USB devices, used registry keys for startup persistence, and supported host identification, file-system exploration, and uploading, downloading, moving, or deleting files—capabilities that could support collection, staging, and exfiltration.1, 6, 12
How defenders gained control of the command path
Sekoia.io acquired the abandoned hard-coded C2 address 45.142.166[.]112 in September 2023 for approximately $7 and sinkholed it. The company observed the worm continuing to beacon at global scale and reverse engineered a native self-delete command, identified as command 0x1005. French law enforcement and Sekoia.io then supported participating national authorities, including the FBI.12, 13
U.S. legal authority and operating period
The FBI obtained the first of nine rolling remote-access warrants in the Eastern District of Pennsylvania in August 2024 under Federal Rule of Criminal Procedure 41(b)(6)(B). The final warrant expired January 3, 2025, ending the U.S. portion of the operation; DOJ announced it publicly on January 14, 2025. Warrants were repeated so commands could be sent whenever eligible infected systems contacted the sinkhole.6, 12
What the deletion command did
The operation used PlugX's native command channel to request non-content identifying information and deliver the self-delete instruction. On the host, the instruction deleted malware-created files and PlugX startup registry keys, created a temporary script, stopped the PlugX application, deleted the malware directory, and removed the temporary script. Sekoia.io's reverse engineering describes the variant deleting its service-related registry key and using %TEMP%/del_AsvastSvcpCP.bat to finish cleanup.12, 13
What the FBI said it did not do
The FBI tested the self-delete command and represented that it did not collect content information from affected computers, alter their operating systems, or affect legitimate functions or files beyond the expressly authorized malware removal. This was remote malware deletion, not a general forensic search of victim content.6, 12
How to interpret 4,258 versus 45,000
DOJ reported that the operation deleted PlugX from approximately 4,258 U.S.-based computers and networks. The warrant affidavit separately stated that at least 45,000 U.S. IP addresses had contacted the C2 since September 2023. Those figures are not equivalent: 4,258 is the reported remediation total, while IP churn, NAT, VPN and satellite egress, repeated beacons, and changing addresses prevent 45,000 IPs from being treated as a unique-device count or total infection population.6, 12, 13
Cleanup limits and reinfection risk
Authorities selected the lower-impact host-only native deletion command. Because this PlugX variant contacted C2 only while executing on a host, the command did not remove PlugX from infected USB devices. Dormant removable media, air-gapped systems, offline hosts, and systems that never reached the sinkhole were not remediated; an infected USB device could therefore reintroduce the worm. Sekoia.io had designed a more intrusive USB-cleaning payload but did not use it in the sovereign disinfection campaign because it would upload code and modify the drive's directory structure.12, 13
Victim notification
The FBI sent notices and warrant receipts to the internet service providers associated with affected IP addresses and asked those ISPs to notify their customers. DOJ also issued public notice. Notification did not mean the FBI had established the full incident scope, the presence or absence of companion malware, credential exposure, or data theft on each system.6, 12
Other recent FBI/DOJ actions reviewed
Public FBI/DOJ research for the last three years found no additional operation that explicitly named SOGU. The closest additional PlugX-related action was announced March 5, 2025, when DOJ and the FBI unsealed charges and other disruption measures involving PRC hacker-for-hire and APT27-linked activity; court allegations said actors installed malware such as PlugX for persistence. That is adjacent family-reuse evidence only. It is not a SOGU-specific operation and does not join APT27, APT10, or Mustang Panda into one campaign.1, 6, 14
Confidence assessment: SOGU, PlugX, shared TTPs, and IOCs
These are calibrated analytic-confidence ranges, not statistical probabilities. MITRE lists Sogu as associated software under PlugX, and CISA used the combined PLUGX/SOGU designation. That supports a strong family relationship and substantial behavioral overlap, but it does not make hashes, infrastructure, filenames, persistence artifacts, delivery paths, or actor attribution interchangeable across variants and campaigns.1, 2, 6, 12, 13
| Question | Confidence | Assessment |
|---|---|---|
| SOGU and PlugX are related | 95–99% | Very high confidence. Authoritative reporting treats Sogu as a PlugX-associated name or variant. |
| They share core TTPs | 80–95% | Strong overlap in DLL side-loading, encoded payloads, in-memory execution, modular RAT functions, persistence, discovery, file operations, and command-and-control behavior. |
| They share campaign-specific TTPs | 30–60% | Initial access, USB propagation, scheduled tasks, registry paths, persistence mechanisms, and C2 protocols vary by operator and variant. |
| They share exact hashes, IPs, or domains | Usually below 20% | Atomic IOCs normally identify a particular build, infrastructure set, or campaign rather than the entire PlugX family. |
| One IOC proves both labels | Very low | A match may identify a known sample, but it should not automatically label every PlugX variant as SOGU or establish actor attribution. |
- #
- 1
- Tier
- Tier 0 - Government alert
- Publisher
- CISA / US-CERT
- Published
- April 6, 2017; revised
- Why Used
- Primary public source for the PLUGX/SOGU label, memory-resident caveat, three-file DLL side-loading chain, credential-led access, RedLeaves relationship, mitigations, and government-provided indicators.
- #
- 2
- Tier
- Tier 0 - Authoritative framework
- Publisher
- MITRE ATT&CK
- Published
- Living record
- Why Used
- Maintained software-family record for Windows platform scope, modular capabilities, ATT&CK techniques, reported use by multiple groups, and sample-specific caution.
- Source
- PlugX - Software S0013
- #
- 3
- Tier
- Tier 0 - Authoritative framework
- Publisher
- MITRE ATT&CK
- Published
- Living record; modified May 12, 2026
- Why Used
- Maintained actor record for the menuPass, APT10, Stone Panda, Cicada, Red Apollo, and related naming set; target sectors; software; and campaign behaviors.
- Source
- menuPass - Group G0045
- #
- 4
- Tier
- Tier 0 - Government attribution
- Publisher
- U.S. Department of Justice
- Published
- December 20, 2018
- Why Used
- Government legal record for APT10 aliases, charged MSP and technology-theft campaigns, credential theft, lateral movement, staging and exfiltration allegations, sectors, and stated legal caveats.
- #
- 5
- Tier
- Tier 1 - Primary vendor research
- Publisher
- Symantec / Broadcom
- Published
- November 17, 2020
- Why Used
- Primary campaign research for Cicada/APT10 attribution confidence, Japan-linked victimology, DLL side-loading, discovery, credential theft, living-off-the-land tools, staging, data access, and public sample hashes.
- #
- 6
- Tier
- Tier 0 - Government disruption
- Publisher
- U.S. Department of Justice
- Published
- January 14, 2025; updated July 7, 2026
- Why Used
- Primary source for the separate Mustang Panda PlugX variant, court-authorized U.S. removal operation, approximately 4,258 remediated computers and networks, and notification context.
- #
- 7
- Tier
- Tier 5 - Framework technique
- Publisher
- MITRE ATT&CK
- Published
- Living record
- Why Used
- Authoritative technique context for malicious DLL search-order hijacking and side-loading, including PlugX procedure examples.
- #
- 8
- Tier
- Tier 5 - Framework software
- Publisher
- MITRE ATT&CK
- Published
- Living record
- Why Used
- Supporting menuPass context for a distinct loader used to deploy PlugX and other payloads through DLL search-order hijacking; retained without merging the loader and implant identities.
- #
- 9
- Tier
- Tier 1 - Primary malware research
- Publisher
- Palo Alto Networks Unit 42
- Published
- June 22, 2015
- Why Used
- Primary reverse engineering for a malicious Office document exploiting CVE-2012-0158, the signed Samsung executable/malicious DLL/encrypted payload chain, memory decoding, registry payload storage, Windows service persistence, anti-analysis behavior, and encrypted HTTP Cookie traffic.
- #
- 10
- Tier
- Tier 1 - Primary malware research
- Publisher
- Palo Alto Networks Unit 42
- Published
- January 25, 2023
- Why Used
- Primary research for a removable-media variant using hidden files and an LNK, three-component DLL side-loading, in-memory payload decryption, host and USB propagation, and recurring scheduled-task persistence.
- #
- 11
- Tier
- Tier 1 - Primary campaign research
- Publisher
- Trend Micro
- Published
- January 14, 2020
- Why Used
- Primary campaign research for spear-phishing DOCX initial access and a PlugX variant delivered through a legitimate executable, malicious DLL, and third encrypted payload file within a broader multi-backdoor operation.
- #
- 12
- Tier
- Tier 0 - Government court record
- Publisher
- U.S. Department of Justice / FBI
- Published
- December 20, 2024; unsealed January 2025
- Why Used
- Primary legal and technical record for the USB-propagating Mustang Panda PlugX variant, C2 address, warrant authority, rolling execution, host-side deletion steps, non-content limitation, U.S. IP observation, victim notification, and scope boundaries.
- #
- 13
- Tier
- Tier 1 - Primary malware and disruption research
- Publisher
- Sekoia.io
- Published
- April 25, 2024
- Why Used
- Primary reverse engineering and sinkhole record for the hard-coded C2, native 0x1005 self-delete command, host-cleaning mechanics, IP-count limitations, infected-USB constraint, alternative USB-cleaning payload, and reinfection risk.
- #
- 14
- Tier
- Tier 0 - Government legal action
- Publisher
- U.S. Department of Justice / FBI
- Published
- March 5, 2025
- Why Used
- Primary government record for separate PRC hacker-for-hire and APT27-linked charges and disruption measures involving alleged use of malware such as PlugX for persistent access; retained as family-reuse context, not as a SOGU attribution.
| # | Tier | Publisher | Published | Why Used | Source |
|---|---|---|---|---|---|
| 1 | Tier 0 - Government alert | CISA / US-CERT | April 6, 2017; revised | Primary public source for the PLUGX/SOGU label, memory-resident caveat, three-file DLL side-loading chain, credential-led access, RedLeaves relationship, mitigations, and government-provided indicators. | Intrusions Affecting Multiple Victims Across Multiple Sectors |
| 2 | Tier 0 - Authoritative framework | MITRE ATT&CK | Living record | Maintained software-family record for Windows platform scope, modular capabilities, ATT&CK techniques, reported use by multiple groups, and sample-specific caution. | PlugX - Software S0013 |
| 3 | Tier 0 - Authoritative framework | MITRE ATT&CK | Living record; modified May 12, 2026 | Maintained actor record for the menuPass, APT10, Stone Panda, Cicada, Red Apollo, and related naming set; target sectors; software; and campaign behaviors. | menuPass - Group G0045 |
| 4 | Tier 0 - Government attribution | U.S. Department of Justice | December 20, 2018 | Government legal record for APT10 aliases, charged MSP and technology-theft campaigns, credential theft, lateral movement, staging and exfiltration allegations, sectors, and stated legal caveats. | Two Chinese Hackers Associated With the Ministry of State Security Charged With Global Computer Intrusion Campaigns |
| 5 | Tier 1 - Primary vendor research | Symantec / Broadcom | November 17, 2020 | Primary campaign research for Cicada/APT10 attribution confidence, Japan-linked victimology, DLL side-loading, discovery, credential theft, living-off-the-land tools, staging, data access, and public sample hashes. | Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign |
| 6 | Tier 0 - Government disruption | U.S. Department of Justice | January 14, 2025; updated July 7, 2026 | Primary source for the separate Mustang Panda PlugX variant, court-authorized U.S. removal operation, approximately 4,258 remediated computers and networks, and notification context. | Justice Department and FBI Conduct International Operation to Delete Malware Used by China-Backed Hackers |
| 7 | Tier 5 - Framework technique | MITRE ATT&CK | Living record | Authoritative technique context for malicious DLL search-order hijacking and side-loading, including PlugX procedure examples. | T1574.001 - Hijack Execution Flow: DLL |
| 8 | Tier 5 - Framework software | MITRE ATT&CK | Living record | Supporting menuPass context for a distinct loader used to deploy PlugX and other payloads through DLL search-order hijacking; retained without merging the loader and implant identities. | HUI Loader - Software S1097 |
| 9 | Tier 1 - Primary malware research | Palo Alto Networks Unit 42 | June 22, 2015 | Primary reverse engineering for a malicious Office document exploiting CVE-2012-0158, the signed Samsung executable/malicious DLL/encrypted payload chain, memory decoding, registry payload storage, Windows service persistence, anti-analysis behavior, and encrypted HTTP Cookie traffic. | PlugX Uses Legitimate Samsung Application for DLL Side-Loading |
| 10 | Tier 1 - Primary malware research | Palo Alto Networks Unit 42 | January 25, 2023 | Primary research for a removable-media variant using hidden files and an LNK, three-component DLL side-loading, in-memory payload decryption, host and USB propagation, and recurring scheduled-task persistence. | Chinese PlugX Malware Hidden in Your USB Devices? |
| 11 | Tier 1 - Primary campaign research | Trend Micro | January 14, 2020 | Primary campaign research for spear-phishing DOCX initial access and a PlugX variant delivered through a legitimate executable, malicious DLL, and third encrypted payload file within a broader multi-backdoor operation. | Operation DRBControl: Cyberespionage Targeting Gambling Companies in Southeast Asia |
| 12 | Tier 0 - Government court record | U.S. Department of Justice / FBI | December 20, 2024; unsealed January 2025 | Primary legal and technical record for the USB-propagating Mustang Panda PlugX variant, C2 address, warrant authority, rolling execution, host-side deletion steps, non-content limitation, U.S. IP observation, victim notification, and scope boundaries. | Affidavit in Support of an Application for a Ninth Search and Seizure Warrant |
| 13 | Tier 1 - Primary malware and disruption research | Sekoia.io | April 25, 2024 | Primary reverse engineering and sinkhole record for the hard-coded C2, native 0x1005 self-delete command, host-cleaning mechanics, IP-count limitations, infected-USB constraint, alternative USB-cleaning payload, and reinfection risk. | Unplugging PlugX: Sinkholing the PlugX USB Worm Botnet |
| 14 | Tier 0 - Government legal action | U.S. Department of Justice / FBI | March 5, 2025 | Primary government record for separate PRC hacker-for-hire and APT27-linked charges and disruption measures involving alleged use of malware such as PlugX for persistent access; retained as family-reuse context, not as a SOGU attribution. | Justice Department Charges 12 Chinese Contract Hackers and Law Enforcement Officers in Global Computer Intrusion Campaigns |
- Version
- v1.7
- Date
- Aug 6, 2026
- Changes
- Added a source-backed confidence table to the public Notes card separating the high-confidence SOGU/PlugX family relationship and shared core TTPs from lower-confidence campaign-specific overlap and generally non-transferable atomic IOCs.
- Version
- v1.6
- Date
- Aug 6, 2026
- Changes
- Cleared the AI Agent Delta Updates card because no active page-monitoring AI agent is configured. Agent status and synthetic fallback updates are no longer shown when Page Alerts are disabled; this change remains documented only in the Version Change Log.
- Version
- v1.5
- Date
- Aug 6, 2026
- Changes
- Rebuilt Card 13 as a concrete IOC and observable registry. Reconciled the CISA PLUGX/SOGU triad and protocol markers, Unit 42 Samsung and USB sample hashes, filenames, directories, registry and task artifacts, and the separate Sekoia.io / DOJ Mustang Panda worm infrastructure and cleanup artifacts. Added lifecycle and attribution boundaries for historical, sinkholed, legitimate-but-abused, and variant-specific indicators.
- Version
- v1.4
- Date
- Aug 6, 2026
- Changes
- Expanded the BLUF, Executive Summary, Timeline, and Notes with the 2023-2025 PlugX sinkhole and court-authorized removal record; added the DOJ warrant affidavit, Sekoia.io technical analysis, USB-remediation limits, scale caveats, victim-notification process, and a separate 2025 APT27 PlugX legal-action boundary. Research found no additional FBI/DOJ operation in the last three years that explicitly named SOGU.
- Version
- v1.3
- Date
- Aug 6, 2026
- Changes
- Set the fresh-reader view to cards 2, 4, 5, 6, 9, 10, 13, 15, and 31, with only cards 5, 6, 9, 10, 15, and 31 expanded. Advanced the reader-preference version so the published defaults take effect independently of the prior view configuration.
- Version
- v1.2
- Date
- Aug 6, 2026
- Changes
- Refined Research Framing to the established Flash Threat Brief reading standard: shortened the interpreted questions, restored the complete Tier 0 through Tier 8 source audit with centered counts and a bold total row, removed unnecessary table minimum widths, and aligned the Expansion Research treatment with the reference format.
- Version
- v1.1
- Date
- Aug 6, 2026
- Changes
- Professional 32-card rebuild against the reference contract. Reworked Research Framing, Topic, audience, BLUF, and Executive Summary; separated primary credential/trust access from sample-specific document, exploit, download, and USB vectors; added a 13-step incident-response playbook; defined four proof levels; expanded collection requirements, observables, ATT&CK, technology risks, source tiers, reconciliation, contributors, real-world examples, decision gates, and source weighting; added three primary malware/campaign sources.
- Version
- v1.0
- Date
- Aug 6, 2026
- Changes
- Initial 32-card source-backed brief. Added malware-family and actor attribution boundaries, plain-language execution flow, behavior-led observables, response actions, ATT&CK mapping, public-disclosure limits, source reconciliation, and reciprocal links to the APT10 actor record.
| Version | Date | Changes |
|---|---|---|
| v1.7 | Aug 6, 2026 | Added a source-backed confidence table to the public Notes card separating the high-confidence SOGU/PlugX family relationship and shared core TTPs from lower-confidence campaign-specific overlap and generally non-transferable atomic IOCs. |
| v1.6 | Aug 6, 2026 | Cleared the AI Agent Delta Updates card because no active page-monitoring AI agent is configured. Agent status and synthetic fallback updates are no longer shown when Page Alerts are disabled; this change remains documented only in the Version Change Log. |
| v1.5 | Aug 6, 2026 | Rebuilt Card 13 as a concrete IOC and observable registry. Reconciled the CISA PLUGX/SOGU triad and protocol markers, Unit 42 Samsung and USB sample hashes, filenames, directories, registry and task artifacts, and the separate Sekoia.io / DOJ Mustang Panda worm infrastructure and cleanup artifacts. Added lifecycle and attribution boundaries for historical, sinkholed, legitimate-but-abused, and variant-specific indicators. |
| v1.4 | Aug 6, 2026 | Expanded the BLUF, Executive Summary, Timeline, and Notes with the 2023-2025 PlugX sinkhole and court-authorized removal record; added the DOJ warrant affidavit, Sekoia.io technical analysis, USB-remediation limits, scale caveats, victim-notification process, and a separate 2025 APT27 PlugX legal-action boundary. Research found no additional FBI/DOJ operation in the last three years that explicitly named SOGU. |
| v1.3 | Aug 6, 2026 | Set the fresh-reader view to cards 2, 4, 5, 6, 9, 10, 13, 15, and 31, with only cards 5, 6, 9, 10, 15, and 31 expanded. Advanced the reader-preference version so the published defaults take effect independently of the prior view configuration. |
| v1.2 | Aug 6, 2026 | Refined Research Framing to the established Flash Threat Brief reading standard: shortened the interpreted questions, restored the complete Tier 0 through Tier 8 source audit with centered counts and a bold total row, removed unnecessary table minimum widths, and aligned the Expansion Research treatment with the reference format. |
| v1.1 | Aug 6, 2026 | Professional 32-card rebuild against the reference contract. Reworked Research Framing, Topic, audience, BLUF, and Executive Summary; separated primary credential/trust access from sample-specific document, exploit, download, and USB vectors; added a 13-step incident-response playbook; defined four proof levels; expanded collection requirements, observables, ATT&CK, technology risks, source tiers, reconciliation, contributors, real-world examples, decision gates, and source weighting; added three primary malware/campaign sources. |
| v1.0 | Aug 6, 2026 | Initial 32-card source-backed brief. Added malware-family and actor attribution boundaries, plain-language execution flow, behavior-led observables, response actions, ATT&CK mapping, public-disclosure limits, source reconciliation, and reciprocal links to the APT10 actor record. |
