ATT&CKReferencesDOJ Affidavit Search and Seizure PlugX December 2024

DOJ Affidavit Search and Seizure PlugX December 2024

DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwarePlugX

PlugX has captured victim IP address details of the targeted machine.

T1041
Exfiltration Over C2 Channel
MalwarePlugX

PlugX has exfiltrated stolen data and files to its C2 server.

T1070.004
File Deletion
MalwarePlugX

PlugX has the remove itself and other artifacts.

T1074.001
Local Data Staging
MalwarePlugX

PlugX has collected and staged the victim’s computer files for exfiltration.

T1083
File and Directory Discovery
MalwarePlugX

PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution.

T1091
Replication Through Removable Media
MalwarePlugX

PlugX has copied itself to infected removable drives for propagation to other victim devices.

T1105
Ingress Tool Transfer
MalwarePlugX

PlugX has a module to download and execute files on the compromised machine.

T1112
Modify Registry
MalwarePlugX

PlugX has a module to create, delete, or modify Registry keys.

T1120
Peripheral Device Discovery
MalwarePlugX

PlugX can identify removable media attached to compromised hosts.

T1547.001
Registry Run Keys / Startup Folder
MalwarePlugX

PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.