The DOJ has disclosed that a multi-month law enforcement operation allowed the FBI to delete PRC-associated PlugX malware from over 4,250 infected computers:
The Justice Department and FBI today announced a multi-month law enforcement operation that, alongside international partners, deleted “PlugX” malware from thousands of infected computers worldwide. As described in court documents unsealed in the Eastern District of Pennsylvania, a group of hackers sponsored by the People’s Republic of China (PRC), known to the private sector as “Mustang Panda” and “Twill Typhoon,” used a version of PlugX malware to infect, control, and steal information from victim computers.
According to court documents, the PRC government paid the Mustang Panda group to, among other computer intrusion services, develop this specific version of PlugX. Since at least 2014, Mustang Panda hackers then infiltrated thousands of computer systems in campaigns targeting U.S. victims, as well as European and Asian governments and businesses, and Chinese dissident groups. Despite previous cybersecurity reports, owners of computers still infected with PlugX are typically unaware of the infection. The court-authorized operation announced today remediated U.S.-based computers infected with Mustang Panda’s version of PlugX.
Roger Grimes, Data-Driven Defense Evangelist at KnowBe4 had the following comment on this news:
“It’s always a good day when the good guys get a win! As simple as it seems for anyone to go in and proactively remove malware, it really isn’t easy to do. First, you’ve got to make sure you can do it legally. That often takes lawyers and legal review, and in most cases, lawyers with experience in global cybercriminals and laws. It takes someone in law enforcement who cares enough to push it. They’ve got to make a case and get it approved by senior management. Then, the removal process has to be tested.”
“In this case, the FBI relied upon the bot’s own removal instructions, but it isn’t always this easy. Historically, there have been instances of less mature and capable but well-meaning defenders who have less elegantly removed malware and caused more problems than the malware did. The solution has to be tested and retested. Then, it has to be globally coordinated to happen as quickly as it can before the attackers know something is up and implement defenses.”
“The overall process is more difficult than it first sounds. There’s a reason why proactive removal isn’t that common. With that said, it does seem like we are seeing just a bit more of these proactive removal projects than we used to see. Of course, expect to see the hackers respond by making it harder for unauthorized removal schemes to take place. It’s a business, and the bad guys see the good guys as adversaries and will respond accordingly. The bad guys won’t sit back and stay defeated. They will respond. They will make it harder for future efforts to be as successful. But for today, let’s celebrate the win!”
Wins seem to be hard to come by these days. Thus I will take this one. But realistically what needs to happen is prevention and detection means need to be better so that actions like these are the exception.
Chinese hacking platform takedown exposes an ORB network hiding in your routers
Posted in Commentary with tags DoJ, FBI on August 27, 2026 by itnerdThe DOJ and FBI just disrupted QTFY, a Chinese state-linked hacking platform built around QScan, which scanned the internet for vulnerable IoT and SOHO devices, and QTRouter, which enrolled those devices into an obfuscation mesh to hide attacker traffic. Authorities seized the domains hard-coded into the malware, making the tooling inoperable across every operation that relied on it, not just one campaign. The FBI also flagged business ties between the company behind QTFY and groups like Salt Typhoon and i-Soon.
Josh Picolet, VP of Detection & Analysis, Team Cymru had this to say:
“QTFY is a useful case study in how state-linked contracting networks actually operate. The detail worth noting is what QScan was built to do. It scanned the internet, likely in a very targeted manner, for vulnerable IoT/SOHO devices and enrolled them into QTRouter, the layer that hid the actual operations behind a mesh of compromised hardware. That is the operating model of an ORB network, an operational relay box mesh assembled from hijacked edge devices, and it is exactly the type infrastructure ecosystem we have been tracking at Team Cymru for years. QTFY is one network in a much larger pattern. Turning routers, IoT gear, and SOHO devices into an obfuscation layer for attacker traffic is not a one-off tactic bolted onto a single contractor. It is how China’s freelance hacking and contracting market has learned to work, and the business ties noted here to Salt Typhoon and i-Soon are the visible edge of a quartermaster model that resells capability and access across many customers.
That model is also why the takedown landed the way it did. The domains were hard-coded into the malware for communication and authentication, so seizing that infrastructure made the tooling inoperable across every operation depending on it, not just one intrusion. Detection built around a single campaign’s indicators would never have surfaced a platform built to be shared across operators. What exposes infrastructure like this is the ability to detect the shared obfuscation layer underneath the operations, recognizing the mesh as a repeatable tradecraft pattern rather than a scatter of unrelated victims.
Defenders should not expect this one to fade. The quartermaster model and the compromise of edge devices for obfuscation will be fought for years to come. We track a large number of these ORB mesh networks, and the modus operandi across them is remarkably consistent. That is why we tag and track every model of router, IoT, and SOHO device we can observe, so these networks can be detected early and customers get a real risk level on the IPs involved. Organizations in defense, telecom, and critical infrastructure should be asking whether their own detection reaches that layer, well past the perimeter.”
Disruptions like this are good. But what will really solve the issue is going after the people behind these schemes and bringing them to justice. That way the profitability gets taken out of activities like these.
Leave a comment »