Threat Database Backdoors BKDR_PLUGX.AI

BKDR_PLUGX.AI

By GoldSparrow in Backdoors

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 28
First Seen: April 26, 2013
Last Seen: October 17, 2021
OS(es) Affected: Windows

BKDR_PLUGX.AI is a backdoor Trojan that affects genuine programs, which involve Microsoft, Lenovo, and McAfee. BKDR_PLUGX.AI uses typical programs to load its malevolent .DLL components on the victimized PC. BKDR_PLUGX.AI can use any executable file and recognized applications. BKDR_PLUGX.AI also uses a specific vulnerability found in an executable when .DLLs are loaded, particularly on how executable files load the first .DLL file in a specific folder. BKDR_PLUGX.DMI uses numerous genuine files to load its infected components on the vulnerable computer. BKDR_PLUGX.AI uses 'CamMute.exe', which is a Lenovo software product connected with Camera Mute Control Service for ThinkPad. BKDR_PLUGX.AI loads 'CommFunc.dll', which then loads 'CommFunc.jax'. Both two files are identified as BKDR_PLUGX.AI. BKDR_PLUGX.AI pairs a specific .DLL file with an executable file. BKDR_PLUGX.AI loads the encrypted file with the same file name with an additional extension.

File System Details

BKDR_PLUGX.AI may create the following file(s):
# File Name Detections
1. CommFunc.dll
2. CamMute.exe
3. CommFunc.jax

Trending

Most Viewed

Loading...