FBI Seizes Flax Typhoon Domains, Cripples PRC Tools

The U.S. Department of Justice and the FBI have seized seven internet domains tied to two Chinese-developed hacking platforms used in intrusions against U.S. and foreign critical infrastructure networks.[1][2] The court-authorized operation is designed to deny threat actors access to “Microscan” and “FishHub,” bespoke vulnerability scanning and spear-phishing tools linked to the China-backed Flax Typhoon group and Beijing contractor Integrity Technology Group.[1][2][10]

According to charging documents and public statements, one seized domain, c0cc[.]cc, was used to access the Microscan platform, which allowed operators to identify exploitable weaknesses across critical infrastructure and enterprise environments.[1][2] Five other domains—98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net—served as delivery infrastructure for FishHub malware used in targeted spear-phishing campaigns and post-compromise operations.[2][3][12] A seventh domain, 98aiblog[.]com, was tied to SoftEther VPN installations on victim systems, giving attackers durable remote access into compromised networks.[2][12]

Flax Typhoon—also tracked by researchers as Ethereal Panda and RedJuliett—is described by officials as a Chinese government-sponsored hacking group operating a Mirai-based botnet and custom toolchain through Integrity Technology Group.[5][6][13] Integrity Technology, a Beijing-based firm with government contracts, had already drawn U.S. sanctions over its role in supporting state-aligned cyber operations before this latest seizure action.[10][15] Investigators say the company developed Microscan and FishHub, then offered them as turnkey services to PRC-linked operators for reconnaissance, intrusion, and data theft campaigns.[1][6][10]

Law enforcement and intelligence reporting tie the seized infrastructure to activity against a South Carolina power company and other critical infrastructure targets, where attackers used Microscan to scan operational networks for exploitable weaknesses.[1][6] FishHub-linked domains were also used to deliver malware to roughly 20 Taiwanese universities, illustrating that the same toolset was being repurposed against both U.S. and foreign organizations.[6][12] The FBI has also linked the broader Flax Typhoon botnet to compromises of internet-connected storage devices, cameras, and DVRs, which were abused as launchpads for further intrusions and data theft.[13]

Despite the scale of the operation, Justice Department filings and public advisories do not cite specific CVE identifiers for vulnerabilities exploited by Microscan or FishHub, underscoring that much of the activity leveraged systemic weaknesses in exposed services and poorly secured IoT gear rather than single high-profile bugs.[1][6] Earlier government reporting on the Flax Typhoon botnet noted that attackers relied heavily on default credentials, weak passwords, and outdated firmware on internet-facing devices to gain footholds before pivoting deeper into victim environments.[9][13] That pattern suggests the seized domains were part of a broader ecosystem of opportunistic scanning and exploitation rather than a campaign centered on one newly disclosed flaw.[6][13]

In its announcement, the Justice Department stressed that the disruption is temporary and urged network defenders to treat the takedown as an opportunity to harden systems against future iterations of the same tooling.[1][10] Agencies and private-sector security teams are being advised to hunt for historical connections to the seven seized domains, identify any use of Microscan or FishHub within their environments, and remove unauthorized remote-access software such as SoftEther VPN where found.[8][12] Officials also point to a recent multi-agency advisory on Integrity Technology and PRC-linked cyber activity, urging organizations in energy, higher education, and other critical sectors to tighten monitoring of internet-exposed devices, enforce strong authentication, and prioritize patching of services frequently targeted by state-backed scanning operations.[10][14]

References

  1. Justice Department and FBI Seize Vulnerability Scanning …
  2. FBI disrupts Chinese hacking tools used to breach critical infrastructure
  3. FBI Seizes Domains Used in Flax Typhoon Attacks
  4. thehackernews.com · search · labelbotnet — Latest News, Reports & Analysis | The Hacker News
  5. US disrupts Chinese hacking tools as 7 govts warn of PRC …
  6. FBI Seizes Flax Typhoon Domains: Exchange and Active Directory Checks for Windows Admins
  7. Court-Authorized Operation Disrupts Worldwide Botnet …
  8. DOJ, FBI seize Flax Typhoon-linked hacking tools …
  9. FBI Seized Vulnerability Scanning and Spear Phishing Tools Used by China-Linked Hackers
  10. FBI Director Announces Chinese Botnet Disruption, Exposes Flax Typhoon Hacker Group’s True Identity at Aspen Cyber Summit | Federal Bureau of Investigation
  11. flax typhoon
  12. FBI Seizes Flax Typhoon Hacking Tools Linked to Chinese Contractor

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply