n April 2025 we observed an attack campaign, using a new PlugX variant, by the RedFoxtrot (also known as NOMAD PANDA, Moshen Dragon, and possibly Space Pirates) or Calypso threat actor, which targets some Japanese technology trading companies. During this campaign, the APT actor exploited known vulnerabilities to compromise edge devices such as firewalls and VPNs. Afterwards, they expanded their intrusion within the target organization's systems. Regarding the malware, we have confirmed two variants of PlugX. The first is known as Talisman PlugX. This PlugX variant was reported by Trellix [1] in March 2022. The other is a new variant of PlugX that we called MetaRAT. It contains configuration data that is 0x1BFA bytes in size, and the structure of this file differs from those found in existing PlugX malware. In addition, its functionality has been updated, including the implementation of new C2 command IDs and modifications to the encryption algorithms used for strings and configuration data.