FBI Deletes PlugX Malware From Computers Infected by China Group
ID: 9b70b8e4-89cc-57b2-bc17-39c90a6c47b3
STIX ID: report--9b70b8e4-89cc-57b2-bc17-39c90a6c47b3
Feed Name: Security Boulevard
The FBI, working with French law enforcement and a private vendor, deleted a PlugX RAT variant from more than 4,200 infected U.S. computers after an investigation determined Mustang Panda (Twill Typhoon), allegedly contracted by the Chinese government, had used the malware since September 2023 to persist, spread (notably via USB devices), and exfiltrate data; investigators observed roughly 45,000 U.S. IP addresses contacting the malware’s C2 and leveraged the variant’s native self-delete and location-reporting functions to remediate targeted systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
