{"id":1829,"date":"2021-02-05T23:59:37","date_gmt":"2021-02-06T04:59:37","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=1829"},"modified":"2021-02-05T23:59:39","modified_gmt":"2021-02-06T04:59:39","slug":"plugx-know-as-a-modular-tailgate","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/","title":{"rendered":"PlugX &#8211; know as a modular tailgate"},"content":{"rendered":"\n<p>The PlugX family of malware is well known to researchers, with samples dating back to 2008, according to Trend Micro researchers. PlugX is a Trojan remote access tool with features such as file upload, download and modification, keystroke logging, webcam control, and access to a remote cmd.exe shell. This is commonly used by different threat groups in targeted attacks. PlugX is also known as KORPLUG, SOGU, DestroyRAT and is a modular backdoor that is designed to rely on executing signed and legitimate executables to load malicious code.<\/p>\n\n\n\n<p>As we know, this allows cyber attackers to perform various malicious operations on a system without the user&#8217;s permission or authorization, such as copying and modifying files, logging keys, stealing passwords, and capturing screens of user activity. \u201cPlugX, like other remote access tools, is used for discreet theft and to collect sensitive or profitable information for malicious purposes.<\/p>\n\n\n\n<p>The different versions of PlugX malware maintained consistent methodologies for encryption, configuration, and persistence, despite the evolution of the tool&#8217;s development over the years. In 2014, there was a resurgence of this malware family, making it the most used family of that year.<\/p>\n\n\n\n<p>Until the end of 2016, the methodology of this typical PlugX infection was the same: the malware payload was typically delivered via a phishing campaign, either as a self-extracting RAR file attached, a link to a file, or embedded. Although there have been several variants over the years, it is understood that although there are new variants the &#8220;original&#8221; PlugX variant is still in use today. Despite the evolution of methodologies and techniques of this, the classic variant of this continues to be successful and, as a result, they are still used in adverse campaigns which gives us to understand how dangerous this is since although years have passed, this version is still used.<\/p>\n\n\n\n<p>Check also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/emotet-trojan-increase-considerably-in-september\/\">Emotet Trojan considerably increased in September<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/what-are-trojans-and-how-do-they-affect-us\/\">What are Trojans and how do they affect us?<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The PlugX family of malware is well known to researchers, with samples dating back to 2008, according to Trend Micro researchers. PlugX is a Trojan remote access tool with features such as file upload, download and modification, keystroke logging, webcam control, and access to a remote cmd.exe shell. This is commonly used by different threat [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1830,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36,299],"class_list":["post-1829","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-plugx"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>PlugX - know as a modular tailgate - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"PlugX a tool used by cybercriminals capable of allowing access to various malicious operations on a system which we must be prevented from...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PlugX - know as a modular tailgate - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"PlugX a tool used by cybercriminals capable of allowing access to various malicious operations on a system which we must be prevented from...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-02-06T04:59:37+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-02-06T04:59:39+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/mls.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1140\" \/>\n\t<meta property=\"og:image:height\" content=\"643\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/plugx-know-as-a-modular-tailgate\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/plugx-know-as-a-modular-tailgate\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"PlugX &#8211; know as a modular tailgate\",\"datePublished\":\"2021-02-06T04:59:37+00:00\",\"dateModified\":\"2021-02-06T04:59:39+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/plugx-know-as-a-modular-tailgate\\\/\"},\"wordCount\":326,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/plugx-know-as-a-modular-tailgate\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/mls.jpg\",\"keywords\":[\"Cybersecurity\",\"PlugX\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/plugx-know-as-a-modular-tailgate\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/plugx-know-as-a-modular-tailgate\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/plugx-know-as-a-modular-tailgate\\\/\",\"name\":\"PlugX - know as a modular tailgate - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/plugx-know-as-a-modular-tailgate\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/plugx-know-as-a-modular-tailgate\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/mls.jpg\",\"datePublished\":\"2021-02-06T04:59:37+00:00\",\"dateModified\":\"2021-02-06T04:59:39+00:00\",\"description\":\"PlugX a tool used by cybercriminals capable of allowing access to various malicious operations on a system which we must be prevented from...\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/plugx-know-as-a-modular-tailgate\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/plugx-know-as-a-modular-tailgate\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/plugx-know-as-a-modular-tailgate\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/mls.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/mls.jpg\",\"width\":1140,\"height\":643},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/plugx-know-as-a-modular-tailgate\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PlugX &#8211; know as a modular tailgate\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PlugX - know as a modular tailgate - Truxgo Server Blog","description":"PlugX a tool used by cybercriminals capable of allowing access to various malicious operations on a system which we must be prevented from...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/","og_locale":"es_MX","og_type":"article","og_title":"PlugX - know as a modular tailgate - Truxgo Server Blog","og_description":"PlugX a tool used by cybercriminals capable of allowing access to various malicious operations on a system which we must be prevented from...","og_url":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-02-06T04:59:37+00:00","article_modified_time":"2021-02-06T04:59:39+00:00","og_image":[{"width":1140,"height":643,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/mls.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"PlugX &#8211; know as a modular tailgate","datePublished":"2021-02-06T04:59:37+00:00","dateModified":"2021-02-06T04:59:39+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/"},"wordCount":326,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/mls.jpg","keywords":["Cybersecurity","PlugX"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/","url":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/","name":"PlugX - know as a modular tailgate - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/mls.jpg","datePublished":"2021-02-06T04:59:37+00:00","dateModified":"2021-02-06T04:59:39+00:00","description":"PlugX a tool used by cybercriminals capable of allowing access to various malicious operations on a system which we must be prevented from...","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/mls.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/02\/mls.jpg","width":1140,"height":643},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/plugx-know-as-a-modular-tailgate\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"PlugX &#8211; know as a modular tailgate"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1829","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=1829"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1829\/revisions"}],"predecessor-version":[{"id":1835,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/1829\/revisions\/1835"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/1830"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=1829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=1829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=1829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}