#PlugX
The U.S. Department of Justice announced today that the FBI has deleted Chinese #PlugX malware from over 4,200 computers in networks across the United States. #Malware #MustangPanda #CyberSecurity www.bleepingcomputer.com/news/securit...
FBI wipes Chinese PlugX malware from over 4,000 US computers
​The U.S. Department of Justice announced today that the FBI has deleted Chinese PlugX malware from over 4,200 computers in networks across the United States.
www.bleepingcomputer.com
January 15, 2025 at 12:29 AM
FBI wipes Chinese PlugX malware from thousands of Windows PCs in America
FBI wipes Chinese PlugX malware from thousands of Windows PCs in America
Hey, Xi: Zài jiàn! The FBI, working with French cops, obtained nine warrants to remotely wipe PlugX malware from thousands of Windows-based computers that had been infected by Chinese government-backed criminals, according to newly unsealed court…
dlvr.it
January 14, 2025 at 7:45 PM
The US says the FBI hacked ~4.2K devices in the US to delete PlugX, malware used by China-backed hackers since 2014, after obtaining warrants in August 2024 (Carly Page/TechCrunch)

Main Link | Techmeme Permalink
January 14, 2025 at 6:36 PM
The DOJ worked with French authorities and Sekoia.io to remove PlugX malware from thousands of devices around the world

therecord.media/doj-deletes-...
DOJ deletes China-linked PlugX malware off more than 4,200 US computers
U.S law enforcement accused the People’s Republic of China of paying hackers that are part of a well-known group called Mustang Panda to deploy the PlugX malware — which allows them to “infect, contro...
therecord.media
January 14, 2025 at 8:08 PM
French police push PlugX #malware self-destruct #payload to clean PCs

"The French #police and #Europol are pushing out a "disinfection solution" that automatically removes the PlugX malware from infected devices in France." 😑
www.bleepingcomputer.com/news/securit...
French police push PlugX malware self-destruct payload to clean PCs
The French police and Europol are pushing out a "disinfection solution" that automatically removes the PlugX malware from infected devices in France.
www.bleepingcomputer.com
July 26, 2024 at 7:29 PM
if plugx is your game, open dir with live payloads
103.43.18[.]71:88 #apt #malware
files archived here for homegamers github.com/StrikeReady-...
November 16, 2024 at 3:58 PM
Oh good, thanks to government surveillance, spying and direct tampering with civilian computers we are now safe from government surveillance, spying and direct tampering with civilian computers

techcrunch.com/2025/01/14/d...
DOJ confirms FBI operation that mass-deleted Chinese malware from thousands of US computers | TechCrunch
The FBI says it was authorized to mass-remove “PlugX” malware from more than 4,000 compromised machines in the United States
techcrunch.com
January 14, 2025 at 6:55 PM
The funniest thing about Herr PlugX saying that – indeed, *anyone* who says that – is that, were he to find himself in dire straits and denied the empathy he evidently thinks so little of, he would become positively indignant. Nothing but a hypocritical piece of shit who mistakes wealth for quality.
March 9, 2025 at 11:54 AM
The FBI, working with French cops, obtained nine warrants to remotely wipe PlugX malware from thousands of Windows-based computers that had been infected by Chinese government-backed criminals, according to newly unsealed court documents.
FBI wipes Chinese PlugX malware from 4,200+ US Windows PCs
Hey, Xi: Zài jiàn!
www.theregister.com
January 14, 2025 at 8:54 PM
PlugX C2: doorforum[.]com
November 25, 2025 at 6:57 PM
China-linked hackers targeted #Qatar using fake war news to spread PlugX backdoors and launch cyber-espionage attacks on military and energy sectors.

hackread.com/china-hacker...

#CyberSecurity #China #PlugX #CyberAttack #Malware
China-Linked Hackers Hit Qatar with Backdoor Disguised as War News
China-linked hackers targeted Qatar using fake war news lures to spread PlugX backdoor malware and spy on military and energy sectors.
hackread.com
March 10, 2026 at 5:40 PM
NEW pod alert! We discuss French threat-intel company Sekoia creating a portal to handle “sovereign disinfections” of PlugX malware, CISA leadership taking a 'secure-by-design' victory lap, and another Fortinet zero-day!

securityconversations.com/episode/insi...
Inside the PlugX malware removal operation, CISA takes victory lap and another Fortinet 0day - Security Conversations
Three Buddy Problem – Episode 30: We discuss French threat-intel Sekoia creating a portal to handle “sovereign disinfections” of the PlugX malware, CISA leadership taking […]
securityconversations.com
January 17, 2025 at 9:26 PM
FBI wipes Chinese PlugX malware from over 4,000 US computers
FBI wipes Chinese PlugX malware from over 4,000 US computers
​The U.S. Department of Justice announced today that the FBI has deleted Chinese PlugX malware from over 4,200 computers in networks across the United States.
www.bleepingcomputer.com
January 14, 2025 at 4:49 PM
A look back at #PlugX #worm “sovereign disinfection” campaign
PlugX worm disinfection campaign feedbacks
Discover how we successfully disinfected thousands of computers infected with the PlugX worm using two remote disinfection methods.
blog.sekoia.io
January 9, 2025 at 3:05 PM
if USG wanted to impress me, they would’ve hit PlugX, ShadowPad, and KeyPlug all at once.
January 14, 2025 at 8:03 PM
DOJ confirms FBI operation that mass-deleted Chinese malware from thousands of US computers
DOJ confirms FBI operation that mass-deleted Chinese malware from thousands of US computers
The FBI says it was authorized to mass-remove “PlugX” malware from more than 4,000 compromised machines in the United States © 2024 TechCrunch. All rights reserved. For personal use only.
tcrn.ch
January 14, 2025 at 4:39 PM
#US and #international law enforcement agencies have removed the #PlugX #malware from thousands of computers #worldwide in a coordinated campaign to blunt the effectiveness of one of the most infamous pieces of malware used by #malicious #cyber actors. cyberscoop.com/plugx-malwar...
Law enforcement action deletes PlugX malware from thousands of machines
U.S. and international law enforcement agencies have removed the PlugX malware from thousands of computers worldwide.
cyberscoop.com
January 14, 2025 at 5:34 PM
Fake Claude sites are infecting users with PlugX malware that gives attackers access to your system.

Here’s how the attack works (and why it’s so effective).
Fake Claude site installs malware that gives attackers access to your computer
We found a convincing fake site that installs a trojanized Claude app while quietly deploying PlugX malware.
www.malwarebytes.com
April 13, 2026 at 11:38 PM
​The U.S. Department of Justice announced today that the FBI has deleted Chinese PlugX malware from over 4,200 computers in networks across the United States.
FBI wipes Chinese PlugX malware from over 4,000 US computers
​The U.S. Department of Justice announced today that the FBI has deleted Chinese PlugX malware from over 4,200 computers in networks across the United States.
www.bleepingcomputer.com
January 14, 2025 at 4:26 PM
Fake Claude Website Distributes PlugX RAT www.securityweek.com/fake-claude-...
Fake Claude Website Distributes PlugX RAT
The malware mimics the legitimate Anthropic installation, relies on DLL sideloading, and cleans up after itself.
www.securityweek.com
April 14, 2026 at 5:12 AM
Symantec & Trend Micro have found Chinese APT malware in ransomware attacks across 15 countries

The tools are versions of PlugX and Shadowpad, typical Chinese APT backdoors

Ransomware payloads included RA World and a new strain

www.trendmicro.com/en_us/resear...

www.security.com/threat-intel...
China-linked Espionage Tools Used in Ransomware Attacks
Espionage actor may be moonlighting as RA World attacker.
www.security.com
February 20, 2025 at 12:33 PM
International team (France, USA, others) used active operations to remove PlugX malware from thousands computers around the world. L’opération de cyber-désinfection. www.tribunal-de-paris.justice.fr/sites/defaul... www.justice.gov/opa/media/13...
January 16, 2025 at 6:32 PM