logo

Unplugging PlugX: Sinkholing the PlugX USB worm botnet

ID: 3b5fa005-3448-5850-a792-0faac0fa26df

STIX ID: report--3b5fa005-3448-5850-a792-0faac0fa26df

Feed Name: Sekoia.com

Threat Score
80/100

Date Published: 2024-04-25

Date Updated: 2026-07-20

...
...

This report documents sinkholing and analysis of a wormable PlugX variant (linked to Mustang Panda) that propagates via infected USB drives to bypass air-gapped networks. The authors sinkholed a PlugX C2 IP and observed sustained global beaconing (90–100k unique IPs/day, presence in 170+ countries), reverse-engineered the communication encryption and self-deletion command, proposed coordinated "sovereign disinfection" with CERTs/LEAs, and published IOCs and YARA rules for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.