logo

PlugX malware deleted from thousands of systems by FBI

ID: 64f3bb4a-35c0-51d2-ac67-1e1fe4a6129b

STIX ID: report--64f3bb4a-35c0-51d2-ac67-1e1fe4a6129b

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2025-01-16

Date Updated: 2026-04-28

...
...

The FBI, working with international partners, seized control of a PlugX command-and-control IP, sinkholed the botnet, and remotely deleted the PlugX remote-access Trojan from thousands of infected Windows systems worldwide after attributing a version of the malware to PRC-backed actors. The report highlights PlugX's long-running development, its use to spy and install further malware (including activity by a group called "Velvet Ant" that abused compromised F5 BIG-IP appliances), and that affected users were notified via ISPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.