PlugX malware deleted from thousands of systems by FBI
ID: 64f3bb4a-35c0-51d2-ac67-1e1fe4a6129b
STIX ID: report--64f3bb4a-35c0-51d2-ac67-1e1fe4a6129b
Feed Name: Malwarebytes Blog
The FBI, working with international partners, seized control of a PlugX command-and-control IP, sinkholed the botnet, and remotely deleted the PlugX remote-access Trojan from thousands of infected Windows systems worldwide after attributing a version of the malware to PRC-backed actors. The report highlights PlugX's long-running development, its use to spy and install further malware (including activity by a group called "Velvet Ant" that abused compromised F5 BIG-IP appliances), and that affected users were notified via ISPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
