Unplugging PlugX: Sinkholing the PlugX USB worm botnet
ID: 3b5fa005-3448-5850-a792-0faac0fa26df
STIX ID: report--3b5fa005-3448-5850-a792-0faac0fa26df
Feed Name: Sekoia.com
This report documents sinkholing and analysis of a wormable PlugX variant (linked to Mustang Panda) that propagates via infected USB drives to bypass air-gapped networks. The authors sinkholed a PlugX C2 IP and observed sustained global beaconing (90–100k unique IPs/day, presence in 170+ countries), reverse-engineered the communication encryption and self-deletion command, proposed coordinated "sovereign disinfection" with CERTs/LEAs, and published IOCs and YARA rules for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
