ATT&CKReferencesPalo Alto PlugX June 2017

Palo Alto PlugX June 2017

Lancaster, T. and Idrizovic, E.. (2017, June 27). Paranoid PlugX. Retrieved July 13, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1102.001
Dead Drop Resolver
MalwarePlugX

PlugX uses Pastebin to store C2 addresses.

T1127.001
MSBuild
MalwarePlugX

A version of PlugX loads as shellcode within a .NET Framework project using msbuild.exe, presumably to bypass application control techniques.

T1574.001
DLL
MalwarePlugX

PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.