Malware

FBI removes China-linked PlugX Malware from over 4,200 US Systems

0

The FBI, in collaboration with international partners, has successfully removed the Chinese PlugX malware from over 4,200 computers across U.S. networks, according to the U.S. Department of Justice (DoJ).

Operated by China-linked threat actor Mustang Panda (aka Twill Typhoon), PlugX has been active since 2014, targeting entities in the U.S., Europe, and Asia to steal sensitive information. French law enforcement and cybersecurity firm Sekoia.io spearheaded the global effort to combat the malware, uncovering commands to wipe the infections remotely.

After testing the effectiveness of these commands, the FBI obtained court authorization to delete the malware from infected systems in the U.S. Between August 2024 and January 2025, nine warrants allowed the operation to cleanse 4,258 computers. The court-authorized deletions caused no disruption to the normal functioning of affected systems.

The targeted PlugX variant displayed wormable capabilities, spreading through USB drives and infecting various entities, including European shipping firms, governments, dissident groups, and Indo-Pacific organizations such as Taiwan and Japan.

French authorities accessed the command-and-control (C2) server for the malware, issuing a “self-delete” command that removed files, registry keys, and other traces of the infection.

The FBI has notified the affected U.S. system owners, working with internet service providers to inform them of the successful cleanup. This operation highlights the coordinated global effort to mitigate advanced persistent threats targeting critical systems.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

New Campaign exploits suspected Zero-Day in Fortinet Firewalls

Previous article

TikTok, AliExpress, and others face Legal action over unlawful data transfers to China

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *