Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0013
MITRE ATT&CK Malware

PlugX (S0013)

ThoperTVTDestroyRATSoguKabaKorplug
ShareXLinkedInRedditHN

[PlugX](https://attack.mitre.org/software/S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.(Citation: Lastline PlugX Analysis)(Citation: FireEye Clandestine Fox Part 2)(Citation: New DragonOK)(Citation: Dell TG-3390)

Platforms: Windows

▪Techniques implemented (49)

T1622Debugger EvasionT1112Modify RegistryT1083File and Directory DiscoveryT1614System Location DiscoveryT1036.004Masquerade Task or ServiceT1091Replication Through Removable MediaT1480.002Mutual ExclusionT1016System Network Configuration DiscoveryT1564.001Hidden Files and DirectoriesT1095Non-Application Layer ProtocolT1204.002Malicious FileT1680Local Storage DiscoveryT1056.001KeyloggingT1102.001Dead Drop ResolverT1124System Time DiscoveryT1620Reflective Code LoadingT1057Process DiscoveryT1012Query RegistryT1574.001DLLT1070.009Clear PersistenceT1135Network Share DiscoveryT1127.001MSBuildT1071.001Web ProtocolsT1543.003Windows ServiceT1059.003Windows Command ShellT1105Ingress Tool TransferT1686Disable or Modify System FirewallT1082System Information DiscoveryT1074.001Local Data StagingT1497.001System ChecksT1049System Network Connections DiscoveryT1036.005Match Legitimate Resource Name or LocationT1547.001Registry Run Keys / Startup FolderT1027.001Binary PaddingT1071.004DNST1070.004File DeletionT1113Screen CaptureT1053.005Scheduled TaskT1573.001Symmetric CryptographyT1571Non-Standard PortT1027.007Dynamic API ResolutionT1140Deobfuscate/Decode Files or InformationT1564.003Hidden WindowT1120Peripheral Device DiscoveryT1041Exfiltration Over C2 ChannelT1106Native APIT1027Obfuscated Files or InformationT1033System Owner/User DiscoveryT1027.013Encrypted/Encoded File

▪Used by groups (15)

G1047Velvet AntG1034DaggerflyG0096APT41G0022APT3G0126HigaisaG0027Threat Group-3390G1021Cinnamon TempestG0093GALLIUMG0001AxiomG0045menuPassG0062TA459G1014LuminousMothG0017DragonOKG0044Winnti GroupG0129Mustang Panda
S0013on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.