FBI removes Chinese PlugX malware from US computers

OVERKILL

$100 Site Donor 2021
Joined
Apr 28, 2008
Messages
61,491
Location
Ontario, Canada
https://www.bleepingcomputer.com/ne...e-plugx-malware-from-over-4-000-us-computers/

The U.S. Department of Justice announced today that the FBI has deleted Chinese PlugX malware from over 4,200 computers in networks across the United States.

The malware, controlled by the Chinese cyber espionage group Mustang Panda (also tracked as Twill Typhoon), infected thousands of systems using a PlugX variant with a wormable component that allowed it to spread through USB flash drives.

According to court documents, the list of victims targeted using this malware includes "European shipping companies in 2024, several European Governments from 2021 to 2023, worldwide Chinese dissident groups, and governments throughout the Indo-Pacific (e.g., Taiwan, Hong Kong, Japan, South Korea, Mongolia, India, Myanmar, Indonesia, Philippines, Thailand, Vietnam, and Pakistan)."

*SNIP*

"In August 2024, the Justice Department and FBI obtained the first of nine warrants in the Eastern District of Pennsylvania authorizing the deletion of PlugX from U.S.-based computers," the Justice Department said today.

"The last of these warrants expired on Jan. 3, 2025, thereby concluding the U.S. portions of the operation. In total, this court-authorized operation deleted PlugX malware from approximately 4,258 U.S.-based computers and networks."

The command sent to infected computers by the FBI told the PlugX malware:


  1. Delete the files created by the PlugX malware on the victim's computer,
  2. Delete the PlugX registry keys used to automatically run the PlugX application when the victim computer is started,
  3. Create a temporary script file to delete the PlugX application after it is stopped,
  4. Stop the PlugX application and
  5. Run the temporary file to delete the PlugX application, delete the directory created on the victim computer by the PlugX malware to store the PlugX files, and delete the temporary file from the victim computer.
The FBI is now notifying the owners of U.S.-based computers that have been cleaned of the PlugX infection through their internet service providers and says the action didn't collect information from or impact the disinfected devices in any way.

Cybersecurity firm Sekoia previously discovered a botnet of devices infected with the same PlugX variant, taking control of its command and control (C2) server at 45.142.166[.]112 in April 2024. Sekoia said that, over six months, the botnet's C2 server received up to 100,000 pings from infected hosts daily and had 2,500,000 unique connections from 170 countries.

PlugX has been used in attacks since at least 2008, mainly in cyber espionage and remote access operations by groups linked to the Chinese Ministry of State Security. Multiple threat groups have used it to target government, defense, technology, and political organizations, primarily in Asia and later expanding to the rest of the world.




A bit wild that the "disinfection" involves directing the malware to delete itself... :unsure:


Wild that this software has been around since at least 2008, that's some crazy staying power (though it has received updates).
 
In modern times who on earth uses usb flash drives and what business out there allows them to be read or mounted to their computers.
I use them all the time to install fresh copies of Windows, wipe hard drives...etc. Lots of personal use cases. Now, in a business environment, nobody should be using them with the exception of very specific conditions (like updating the firmware on an X-Ray machine for example).
 
@Pablo 🤣
Yeah, I started a rant on TIKTOK and how Gen Z doesnt care about China owning their hearts and soles, including the fact that Gen Z has made TikTok's search engine a major source of information and yet China doesnt even allow it in their country. They get the censored verision. China is winning the war is my feeling, now we have pop tarts relying on the information fed to them through TikToK
I do believe still in the end we win, im just not so sure with the pop tarts anymore. They are spoon fed, lack a sense of critical thinking.

But I deleted it all and I am disappointed at midnight tonight, Monday it will be allowed to start up again.

End of short rant *LOL*
 
@Pablo 🤣
Yeah, I started a rant on TIKTOK and how Gen Z doesnt care about China owning their hearts and soles, including the fact that Gen Z has made TikTok's search engine a major source of information and yet China doesnt even allow it in their country. They get the censored verision. China is winning the war is my feeling, now we have pop tarts relying on the information fed to them through TikToK
I do believe still in the end we win, im just not so sure with the pop tarts anymore. They are spoon fed, lack a sense of critical thinking.

But I deleted it all and I am disappointed at midnight tonight, Monday it will be allowed to start up again.

End of short rant *LOL*
You mean bottom of their Nike’s or soul ?
 
@Pablo 🤣
Yeah, I started a rant on TIKTOK and how Gen Z doesnt care about China owning their hearts and soles, including the fact that Gen Z has made TikTok's search engine a major source of information and yet China doesnt even allow it in their country. They get the censored verision. China is winning the war is my feeling, now we have pop tarts relying on the information fed to them through TikToK
I do believe still in the end we win, im just not so sure with the pop tarts anymore. They are spoon fed, lack a sense of critical thinking.

But I deleted it all and I am disappointed at midnight tonight, Monday it will be allowed to start up again.

End of short rant *LOL*
Great rant. Frankly.
 
@Pablo 🤣
Yeah, I started a rant on TIKTOK and how Gen Z doesnt care about China owning their hearts and soles, including the fact that Gen Z has made TikTok's search engine a major source of information and yet China doesnt even allow it in their country. They get the censored verision. China is winning the war is my feeling, now we have pop tarts relying on the information fed to them through TikToK
I do believe still in the end we win, im just not so sure with the pop tarts anymore. They are spoon fed, lack a sense of critical thinking.

But I deleted it all and I am disappointed at midnight tonight, Monday it will be allowed to start up again.

End of short rant *LOL*

Boomers and GenX already gave them our industries and money. Might as well continue the trend.

Most younger folks that I work with, straight out of college don't care for TikTok anymore; it was more of a phase.
 
Boomers and GenX already gave them our industries and money. Might as well continue the trend.

Most younger folks that I work with, straight out of college don't care for TikTok anymore; it was more of a phase.
I dont disagree. My feeling is that it is a perfect way for China to educate our youth in middle school and high school since they use its search engine. (I didnt even know it had one)
https://backlinko.com/tiktok-users
 
Last edited:
  • Wow
Reactions: Pew
there needs to be a phone that has the utility you need and cut out all the garbage. a music service, maps, chat gpt, rideshare, weather, etc. cut all the rest of the bs and that would solve a lot of this bs.
 
there needs to be a phone that has the utility you need and cut out all the garbage. a music service, maps, chat gpt, rideshare, weather, etc. cut all the rest of the bs and that would solve a lot of this bs.

Yes there's a few "dumb phones" out on the market. Nokia makes one. They're not really sold at the big three stores but they're out there.
 
Yes there's a few "dumb phones" out on the market. Nokia makes one. They're not really sold at the big three stores but they're out there.
they don't have the utility of the smartphone though. I'm talking about the perfect product that gives you utility of a smart phone with none of the downsides.
 
they don't have the utility of the smartphone though. I'm talking about the perfect product that gives you utility of a smart phone with none of the downsides.
I think all smart phones can be set by parents to not allow apps to be downloaded unless the parent approves it. But no one bothers.
 
  • Like
Reactions: Pew
they don't have the utility of the smartphone though. I'm talking about the perfect product that gives you utility of a smart phone with none of the downsides.
That was arguably Blackberry, and now look at them, lol.
 
  • Like
Reactions: Y_K
Back
Top Bottom