KEYPLUG

S1051

Malware.View on attack.mitre.org

About this malware

KEYPLUG is a modular backdoor written in C++, with Windows and Linux variants, that has been used by APT41 since at least June 2021.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

KEYPLUG can use a hardcoded one-byte XOR encoded configuration file.

T1071.001
Web Protocols

KEYPLUG has the ability to communicate over HTTP and WebSocket Protocol (WSS) for C2.

T1090
Proxy

KEYPLUG has used Cloudflare CDN associated infrastructure to redirect C2 communications to malicious domains.

T1095
Non-Application Layer Protocol

KEYPLUG can use TCP and KCP (KERN Communications Protocol) over UDP for C2 communication.

T1102.001
Dead Drop Resolver

The KEYPLUG Windows variant has retrieved C2 addresses from encoded data in posts on tech community forums.

T1124
System Time Discovery

KEYPLUG can obtain the current tick count of an infected computer.

T1140
Deobfuscate/Decode Files or Information

KEYPLUG can decode its configuration file to determine C2 protocols.

T1573.002
Asymmetric Cryptography

KEYPLUG can use TLS-encrypted WebSocket Protocol (WSS) for C2.

Groups that use it1

Campaigns1

References1

  1. Mandiant APT41 Open source
    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.