• News/
  • https://www.theregister.com/2025/01/14/fbi_french_cops_boot_chinas/

FBI wipes Chinese PlugX malware from 4,200+ US Windows PCs

The Register
·
Jessica Lyons
·
Published Jan 14, 2025
·
Updated

The FBI, working with French cops, obtained nine warrants to remotely wipe PlugX malware from thousands of Windows-based computers that had been infected by Chinese government-backed criminals, according to newly unsealed court documents. The Feds had been tracking a crew called Mustang Panda, aka Twill Typhoon, for years, and claimed the Beijing-linked team had broken into “numerous government and private organizations” in the US, Europe, and Indo-Pacific region. “Significant foreign targets include European shipping companies in 2024, several European Governments from 2021 to 2023, worldwide Chinese dissident groups, and governments throughout the Indo-Pacific,” American prosecutors noted [PDF] in court filings. According to the Feds, the People’s Republic of China paid Mustang Panda to, among other computer intrusion services, provide malware including PlugX. The crew used a version of PlugX that allowed the miscreants to remotely access and control infected machines, steal files, and deploy additional malware. As detailed in the unsealed application for a search and seizure warrant to wipe the software from people's Microsoft Windows PCs: This variant of PlugX malware spreads through a computer’s USB port, infecting attached USB devices, and then potentially spreading to other Windows-based computers that the USB device is later plugged into. Once it has infected the victim computer, the malware remains on the machine (maintains persistence), in part by creating registry ...

Read full article

Affected Software

3 affected components
Microsoft Windows
Microsoft Windows
PlugX PlugX
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the FBI's collaboration with French authorities to remove PlugX malware from over 4,200 infected Windows PCs.

2

What security implications are discussed?

The article highlights the risk posed by Chinese government-backed cybercriminals exploiting vulnerabilities through the PlugX malware.

3

What products or software are affected?

The affected software includes Microsoft Windows operating systems and the PlugX malware itself.

4

Who is behind the PlugX malware attacks?

The attacks are attributed to a group known as Mustang Panda, which is linked to the Chinese government.

5

What actions did the FBI take against the malware?

The FBI obtained nine warrants to remotely wipe the PlugX malware from infected computers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203