AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← Catalog
REFERENCEPUBLIC INTELLIGENCE

PlugX - S0013

Name of ATT&CK software | [PlugX](https://attack.mitre.org/software/S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.(Citation: Lastline PlugX Analysis)(Citation: FireEye Clandestine Fox Part 2)(Citation: New DragonOK)(Citation: Dell TG-3390)

Reference details

Primary displayed family label
PlugX - S0013
Source context
2025/09/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking.json
First reported
2024-08-20 05:38 UTC
Last reported
2025-09-28 19:50 UTC
Catalog updated
2026-10-08 06:17 UTC

Source family labels

PlugX - S0013

Tags

misp:galaxy-name="Malware"misp:galaxy-type="mitre-malware"misp-galaxy:mitre-malware="PlugX - S0013"

Published indicators

Network addresses are displayed in defanged form.

No file hashes or network indicators were published in this record.

Source observations

Cisco Talos published IOCs ↗

Evidence class
provider reported
Source family label
PlugX - S0013
Source confidence
Not reported
Observed
2025-09-28 19:50 UTC
Retrieved
2026-10-08 06:17 UTC

Cisco Talos published IOCs ↗

Evidence class
provider reported
Source family label
PlugX - S0013
Source confidence
Not reported
Observed
2024-08-20 05:38 UTC
Retrieved
2026-10-08 06:08 UTC

Research references