PlugX can enumerate and query for information contained within the Windows Registry.567
tool
PlugX S0013
- Type
- malware
- Platform
- Windows
- Created
- 31 May 2017
- Last modified
- 12 May 2026
PlugX is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.[1][2][3][4]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S0013
PlugX has captured victim IP address details of the targeted machine.89
PlugX can use API hashing and modify the names of strings to evade detection.1011
PlugX has utilized junk code and opaque predicates in payloads to hinder analysis.12
PlugX has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API.13
PlugX has leveraged XOR encryption with the key of 123456789.14
Standing S0013
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
99th percentile · 99% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
100th percentile · None of the 825 ATT&CK software entries has more tactics spanned — the highest in the population.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
29th percentile · 71% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S0013
1277 distinct rules cover the 49 techniques recorded for this tool. The 1391 technique-to-rule mappings resolve to 1277 distinct rules, because one rule can cover several techniques. 881 Sigma · 396 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org