HomeSecurityUSA: FBI removes PlugX malware from thousands of computers

US: FBI removes PlugX malware from thousands of computers

The US Department of Justice announced that the FBI has deleted PlugX malware from more than 4,200 computers on networks across the country.

PlugX malware FBI

The malware, controlled by Chinese hackers Mustang Panda, infected thousands of systems using a variant that included a wormable component and allowed it to spread via USB flash drives.

According to court documents, the victims include: European shipping companies (2024), several European governments (from 2021 to 2023), global Chinese dissident groups , and governments across the Indo-Pacific (e.g. Taiwan, Hong Kong, Japan, South Korea, Mongolia, India, Myanmar, Indonesia, the Philippines, Thailand, Vietnam, and Pakistan).

See also: WP3.XYZ malware: Adds fraudulent administrators to 5,000+ WordPress sites

After infecting the victim computer, the malware remains on the machine (maintains persistence), creating registry keys that automatically run the PlugX application when the computer starts,” the Ministry says. “Owners of computers infected with PlugX malware are usually unaware of the infection.”

The removal of PlugX malware from computers in the US follows a global takedown operation led by French company Sekoia. The operation began in July 2024, when French police and Europol removed the malware from infected devices in France.

In August 2024, the Department of Justice and the FBI obtained the first of nine warrants in the Eastern District of Pennsylvania, authorizing the removal of PlugX malware from computers based in the United States,” the Justice Department said.

The last of these warrants expired on January 3, 2025, thus completing the U.S. portions of the business.“.

See also: Hackers exploit YouTube to distribute malware

The FBI sent the following commands to computers infected with the PlugX malware:

  • Deleting files created by the malware on the victim's computer
  • Delete PlugX registry keys used to automatically run the PlugX application at computer startup
  • Creating a temporary script file to delete the PlugX application after stopping it
  • Stop PlugX application
  • Run temporary file to delete PlugX application, delete directory created on victim computer, and delete temporary file from victim computer

The FBI is notifying computer owners who have been cleaned of the PlugX infection through their internet service providers.

US: FBI removes PlugX malware from thousands of computers

The PlugX malware has been used in attacks since at least 2008, with the aim of espionage. Many threat groups have used it to target government, defense, technology, and political organizations, primarily in Asia and later in the rest of the world.

Some security researchers believe that the malware's source code was leaked around 2015.This leak, combined with the tool's multiple updates, makes it difficult to attribute the new attacks to a specific group.

See also: What is Wallet Drainer malware and how to protect yourself?

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

PlugX malware has extensive capabilities, including collecting system information , uploading and downloading files, logging keystrokes, and executing commands.

The FBI's success in taking down the PlugX malware serves as a reminder that constant vigilance is essential in the ongoing fight against cybercrime .

In addition to government efforts, it is also important for individuals and businesses to prioritize cybersecurity. This includes regularly updating software and systems, using strong passwords, avoiding opening links and attachments from unknown senders, and backing up important data.

By working together, we can create a safer online environment. Let's continue to stay informed and take proactive measures to protect our digital world from cyber threats.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS