The U.S. Department of Justice and FBI said a court-authorized international operation deleted a PlugX malware variant from about 4,258 U.S.-based computers and networks infected by the China-backed group Mustang Panda (also known as Twill Typhoon). Authorities said the malware had been used since at least 2014 against U.S. victims as well as governments, businesses, and dissident groups in Europe and Asia. The disruption was carried out with French law enforcement and Sekoia.io, and the FBI used validated malware-deletion commands under nine warrants obtained in the Eastern District of Pennsylvania before notifying affected owners through internet service providers.
PlugX has long been tied to Chinese cyber-espionage tradecraft, including DLL sideloading, in-memory loading, and remote access capabilities that support persistent access to victim systems. Prior reporting linked Mustang Panda to spear-phishing campaigns against the Hong Kong Catholic Church using archive files and decoy documents to install PlugX, while independent malware analysis showed older PlugX variants remained active with sideloaded components, compressed payloads, and command-and-control infrastructure. The takedown highlights a sustained espionage ecosystem built around PlugX and the continued operational use of the malware across politically sensitive targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The last of the nine warrants expired on Jan. 3, 2025, ending the U.S. portion of the international operation. By then, authorities had deleted PlugX from about 4,258 U.S.-based computers and networks.
In August 2024, the Justice Department and FBI obtained the first of nine warrants in the Eastern District of Pennsylvania authorizing deletion of the Mustang Panda PlugX variant from U.S.-based computers.
PassiveDNS first observed the PlugX command-and-control domain xiguamomomo[.]com, which was later analyzed as part of a PlugX sample using DLL sideloading and reflective loading.
A China-linked spear-phishing campaign targeting members of the Hong Kong Catholic Church began in May, using Vatican- and Catholic-themed lure documents and DLL side-loading to deliver PlugX. Arkbird attributed the samples to Mustang Panda, while Mandiant said the activity was consistent with Chinese state-backed espionage.
Court documents cited by the Justice Department say the PRC-sponsored group Mustang Panda, also known as Twill Typhoon, had used this PlugX variant to infiltrate thousands of systems targeting U.S. victims, European and Asian governments, businesses, and Chinese dissident groups since at least 2014.
The Justice Department and FBI announced a court-authorized, multi-month international operation led with French law enforcement and Sekoia.io to remove a Mustang Panda PlugX variant from thousands of infected computers. The FBI also said it was notifying affected U.S. owners through internet service providers.
Mandiant published analysis of SNOWYDRIVE, SOGU, FROZENHILL, and ZIPZAG, describing removable-media propagation, persistence, and command capabilities. The report also released YARA and YARA-L hunting rules plus file and network indicators of compromise.
A public analysis detailed a PlugX sample delivered by a dropper that extracted WinHelp32.exe, rscom.dll, and rscom.dll.dat, then used DLL sideloading, in-memory decompression, and svchost.exe injection. The decoded configuration exposed command-and-control infrastructure including xiguamomomo[.]com and related IP addresses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
pyaeheinnkyaw.com
Open sourcejustice.gov
Open sourcecloud.google.com
Open sourcecyberandramen.net
Open sourcezdnet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.