The mechanism seems to be a search warrant. The FBI applied for a warrant to "search" all compromised Exchange servers in the United States, and to "seize" the illicit malware on those servers by executing a specified series of commands.
A few excerpts from the above link:
"FBI personnel now seek authorization to search the compromised Microsoft Exchange Servers and uninstall the web shells on those servers". (6th page of the PDF)
"This warrant authorizes the United States to seize and copy from Microsoft Exchange Servers located in the United States the web shells identified in Attachment A, and to delete the web shells from those servers." (11th page)