KEYPLUG — Malware Profile
KEYPLUG is a modular backdoor written in C++, with Windows and Linux variants, that has been used by APT41 since at least June 2021.
MITRE ATT&CK techniques (8)
- T1027.013 Encrypted/Encoded File
- T1071.001 Web Protocols
- T1090 Proxy
- T1095 Non-Application Layer Protocol
- T1102.001 Dead Drop Resolver
- T1124 System Time Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1573.002 Asymmetric Cryptography