The FBI, working with French cops, obtained nine warrants to remotely wipe PlugX malware from thousands of Windows-based computers that had been infected by Chinese government-backed criminals, according to newly unsealed court documents. The Feds had been tracking a crew called Mustang Panda, aka Twill Typhoon, for years, and claimed the Beijing-linked team had broken into “numerous government and private organizations” in the US, Europe, and Indo-Pacific region. “Significant foreign targets include European shipping companies in 2024, several European Governments from 2021 to 2023, worldwide Chinese dissident groups, and governments throughout the Indo-Pacific,” American prosecutors noted [PDF] in court filings. According to the Feds, the People’s Republic of China paid Mustang Panda to, among other computer intrusion services, provide malware including PlugX. The crew used a version of PlugX that allowed the miscreants to remotely access and control infected machines, steal files, and deploy additional malware. As detailed in the unsealed application for a search and seizure warrant to wipe the software from people's Microsoft Windows PCs: This variant of PlugX malware spreads through a computer’s USB port, infecting attached USB devices, and then potentially spreading to other Windows-based computers that the USB device is later plugged into. Once it has infected the victim computer, the malware remains on the machine (maintains persistence), in part by creating registry ...
FBI wipes Chinese PlugX malware from 4,200+ US Windows PCs
The Register
·Jessica Lyons
·Published Jan 14, 2025
·Updated
Affected Software
3 affected components
Microsoft Windows
Microsoft Windows
PlugX PlugX
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the FBI's collaboration with French authorities to remove PlugX malware from over 4,200 infected Windows PCs.
2
What security implications are discussed?
The article highlights the risk posed by Chinese government-backed cybercriminals exploiting vulnerabilities through the PlugX malware.
3
What products or software are affected?
The affected software includes Microsoft Windows operating systems and the PlugX malware itself.
4
Who is behind the PlugX malware attacks?
The attacks are attributed to a group known as Mustang Panda, which is linked to the Chinese government.
5
What actions did the FBI take against the malware?
The FBI obtained nine warrants to remotely wipe the PlugX malware from infected computers.