logo

FBI Deletes PlugX Malware From Computers Infected by China Group

ID: 9b70b8e4-89cc-57b2-bc17-39c90a6c47b3

STIX ID: report--9b70b8e4-89cc-57b2-bc17-39c90a6c47b3

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2025-01-15

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

The FBI, working with French law enforcement and a private vendor, deleted a PlugX RAT variant from more than 4,200 infected U.S. computers after an investigation determined Mustang Panda (Twill Typhoon), allegedly contracted by the Chinese government, had used the malware since September 2023 to persist, spread (notably via USB devices), and exfiltrate data; investigators observed roughly 45,000 U.S. IP addresses contacting the malware’s C2 and leveraged the variant’s native self-delete and location-reporting functions to remediate targeted systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.