{"id":1381,"date":"2025-01-17T05:01:38","date_gmt":"2025-01-17T05:01:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/01\/17\/fbi-deletes-plugx-malware-from-thousands-of-computers-html\/"},"modified":"2025-01-17T05:01:38","modified_gmt":"2025-01-17T05:01:38","slug":"fbi-deletes-plugx-malware-from-thousands-of-computers-html","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/01\/17\/fbi-deletes-plugx-malware-from-thousands-of-computers-html\/","title":{"rendered":"FBI Deletes PlugX Malware from Thousands of Computers"},"content":{"rendered":"\n<div>FBI Deletes PlugX Malware from Thousands of Computers<\/div>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>According to a DOJ <a href=\"https:\/\/www.justice.gov\/opa\/pr\/justice-department-and-fbi-conduct-international-operation-delete-malware-used-china-backed\">press release<\/a>, the FBI was able to delete the Chinese-used PlugX malware from \u201capproximately 4,258 U.S.-based computers and networks.\u201d<\/p>\n<p><a href=\"https:\/\/gizmodo.com\/the-fbi-says-it-made-malware-delete-itself-from-americans-computers-2000550046\">Details<\/a>:<\/p>\n<blockquote>\n<p>To retrieve information from and send commands to the hacked machines, the malware connects to a command-and-control server that is operated by the hacking group. <a href=\"https:\/\/www.justice.gov\/opa\/media\/1384136\/dl\">According to the FBI<\/a>, at least 45,000 IP addresses in the US had back-and-forths with the command-and-control server since September 2023.<\/p>\n<p>It was that very server that allowed the FBI to finally kill this pesky bit of malicious software. First, they tapped the know-how of French intelligence agencies, which had <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/french-police-push-plugx-malware-self-destruct-payload-to-clean-pcs\/\">recently discovered a technique<\/a> for getting PlugX to self-destruct. Then, the FBI gained access to the hackers\u2019 command-and-control server and used it to request all the IP addresses of machines that were actively infected by PlugX. Then it sent a command via the server that causes PlugX to delete itself from its victims\u2019 computers.<\/p>\n<\/blockquote>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Bruce Schneier<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/www.schneier.com\/blog\/archives\/2025\/01\/fbi-deletes-plugx-malware-from-thousands-of-computers.html\">Go to bruce schneier<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>FBI Deletes PlugX Malware from Thousands of Computers According to a DOJ press release, the FBI was able to delete the Chinese-used PlugX malware from \u201capproximately 4,258 U.S.-based computers and networks.\u201d Details: To retrieve information from and send commands to the hacked machines, the malware connects to a command-and-control server that is operated by the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[57,573,258,1],"tags":[87],"class_list":["post-1381","post","type-post","status-publish","format-standard","hentry","category-bruce-schneier","category-fbi","category-malware","category-uncategorized","tag-bruce-schneier"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1381"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=1381"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1381\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=1381"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=1381"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=1381"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}