logo

FBI wipes Chinese PlugX malware from over 4,000 US computers

ID: 6a5f0d8a-8f97-5b12-b054-39dfe035f447

STIX ID: report--6a5f0d8a-8f97-5b12-b054-39dfe035f447

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-01-14

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

The U.S. Department of Justice and FBI, working with French law enforcement and security firm Sekoia, conducted a court-authorized operation that removed a PlugX RAT variant from roughly 4,258 U.S. computers; the malware—attributed to Mustang Panda/Twill Typhoon—had a wormable USB-spreading component, persistent registry-based autostart, and capabilities for file transfer, keystroke logging, and remote command execution, with C2 infrastructure (notably 45.142.166.112) showing widespread global connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.