logo

PlugX worm disinfection campaign feedbacks

ID: efb88433-0899-554b-a124-d95d5b59fa63

STIX ID: report--efb88433-0899-554b-a124-d95d5b59fa63

Feed Name: Sekoia.io Blog

Threat Score
65/100

Date Published: 2024-12-26

Date Updated: 2026-04-29

Author: Sekoia TDR

...
...

Sekoia.io TDR describes taking control of a PlugX worm C2 IP, developing a sinkhole and an ergonomic disinfection portal to enable "sovereign disinfection," coordinating with the Paris Public Prosecutor’s Office and the French Gendarmerie National Cyber Unit and executing a campaign in which the non-intrusive self-delete disinfection payload was delivered 59,475 times to 5,539 IPs at the request of multiple countries; the report outlines the technical approach, legal constraints, and outcomes of the operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.