logo

FBI Deletes PlugX Malware from Thousands of Computers

ID: 24601a97-e4c8-5096-aaa5-6df2190c4aaa

STIX ID: report--24601a97-e4c8-5096-aaa5-6df2190c4aaa

Feed Name: Schneier on Security

Threat Score
80/100

Date Published: 2025-01-16

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

The FBI conducted an international operation, using a technique discovered by French intelligence and access to PlugX command-and-control servers, to issue a self-destruct command that removed the PlugX RAT from roughly 4,258 U.S.-based computers; the report notes PlugX had exchanged traffic with about 45,000 U.S. IP addresses since September 2023 and is linked to Chinese-backed operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.