Skip to main content

FBI to ‘remove’ this nasty malware that’s affected 2.5 million PCs

An individual surrounded by several computers typing on a laptop.
Digital Trends

A malware originating from China has now been contained after the FBI gained a court order to have the harmful code deleted from thousands of Windows PCs.

Recommended Videos

The agency has successfully put an end to the reign of the PlugX malware in the U.S., which has affected over 2.5 million devices globally by infiltrating infected USB drives, PCMag noted.

Working with the FBI, the Justice Department has confirmed that it has been granted court sanction to remove the malware from nearly 4,260 computers and networks in the U.S. as of Tuesday. With the resolution announced, the FBI is set to notify owners of infected machines via their internet service providers.

This is just one instance of federal departments getting control of a serious cybersecurity risk. However, its resolution notes the importance of ongoing cybersecurity research. The Justice Department detailed that the actors behind the attack are a private group of Chinese state-sponsored hackers called “Mustang Panda” that developed a unique version of PlugX malware for the ongoing mission.

PlugX first surfaced in 2008 when it was used as a backdoor vulnerability for bad actors to secretly control Windows machines. By 2020, the malware had been updated to allow it to infiltrate USB drives as well as connected PCs. This is described as a “wormable” malware that can transfer between computers via infected peripherals.

French cybersecurity vendor Sekoia observed that Mustang Panda eventually lacked the resources to support the number of machines it had infected with the PlugX malware and ultimately abandoned the project.

Similarly, antivirus provider Sophos observed several PlugX infections originating from a single IP address source. In September 2023,  collaborating with Sekoia, the cybersecurity vendor paid just $7 to gain access to the IP address and the infected machines. Further research uncovered a self-delete command within the PlugX code.

In July 2024, law enforcement in France allowed the self-deleting mechanism to be used to remedy the infected machines. Since then, 22 other countries have also followed suit.

While it is not clear how the U.S. entities plan to remove the malware from domestic PCs, the FBI testified in an affidavit that it has tested this self-delete command, confirming that it only removes the malware and does not affect any other device functions or transfer any other unwarranted code.

Fionna Agomuoh
Fionna Agomuoh is a Computing Writer at Digital Trends. She covers a range of topics in the computing space, including…
This could be the last laptop you ever need to buy
Framework laptop

Framework might not be a name you've heard of but it could soon be far more common as the company is about to release its modular laptop that could last you a lifetime.

Alright, any laptop laasting that long is a stretch, but the idea is that this will last you far longer than the usual update cycle.

Read more
Alienware gaming PC with RTX 5080 is $400 off
Alienware Area 51 gaming PC.

If your plan is to spend a huge amount of cash on a gaming PC deals so you'll end with an extremely powerful machine, you may want to set your sights on Dell's offer for the Alienware Area 51. This configuration of the gaming desktop with the Nvidia GeForce RTX 5080 graphics card usually sells for $5,050, but it's currently down to $4,650 following a $400 discount. The savings aren't that huge compared to the price, but you might as well take advantage of it if you're interested in this gaming PC, so hurry!

Why you should buy the Alienware Area 51 gaming PC

Read more
Walmart slashed the price of this mini gaming PC to $330
The GMKtec Nucbox M5 Plus gaming PC on a white background.

What if we told you that you can get a dependable gaming PC for an affordable price, and it also won't take up a lot of space on your desk? We're not kidding -- check out the GMKtec Nucbox M5 Plus, which is on sale from Walmart with a $72 discount that further lowers its price from $400 to only $328. You'll need to act fast though, as we're not sure how much longer stocks will last for this mini gaming PC.

Why you should buy the GMKtec Nucbox M5 Plus gaming PC

Read more