{"schema":"aeternae-malware-metadata/v1","generated_at":"2026-10-08T08:39:16+00:00","total_matching":1,"page":1,"page_size":200,"records":[{"id":"5976e0fca926b627c88824acc238fe9cc044e82db40ae6b188ad0fbb4c7dc8cd","kind":"reference","title":"PlugX - S0013","family":"PlugX - S0013","category":"Malware intelligence","summary":"Name of ATT&CK software | [PlugX](https://attack.mitre.org/software/S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.(Citation: Lastline PlugX Analysis)(Citation: FireEye Clandestine Fox Part 2)(Citation: New DragonOK)(Citation: Dell TG-3390)","first_seen":1724132334,"last_seen":1759089007,"created_at":1791439727,"updated_at":1791440271,"source_count":1,"data":{"context":"2025/09/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"PlugX - S0013\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2024/09/DragonRank%2C%20a%20Chinese-speaking%20SEO%20manipulator%20service%20provider.json","https://github.com/Cisco-Talos/IOCs/blob/main/2025/09/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking.json"],"filenames":[],"features":[],"related_cves":[],"labels":["PlugX - S0013"]},"observations":[{"source_id":"talos_ioc","source_url":"https://github.com/Cisco-Talos/IOCs/blob/main/2024/09/DragonRank%2C%20a%20Chinese-speaking%20SEO%20manipulator%20service%20provider.json","source_label":"PlugX - S0013","evidence_class":"provider_reported","confidence":null,"observed_at":1724132334,"fetched_at":1791439727,"data":{"context":"2024/09/DragonRank, a Chinese-speaking SEO manipulator service provider.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"PlugX - S0013\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2024/09/DragonRank%2C%20a%20Chinese-speaking%20SEO%20manipulator%20service%20provider.json"],"family":"PlugX - S0013"}},{"source_id":"talos_ioc","source_url":"https://github.com/Cisco-Talos/IOCs/blob/main/2025/09/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking.json","source_label":"PlugX - S0013","evidence_class":"provider_reported","confidence":null,"observed_at":1759089007,"fetched_at":1791440271,"data":{"context":"2025/09/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"PlugX - S0013\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2025/09/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking.json"],"family":"PlugX - S0013"}}],"indicators":[]}]}