Microscan, FishHub takedown hits Flax Typhoon tools

U.S. authorities have seized the domains behind the Microscan and FishHub hacking platforms, a move aimed at disrupting Chinese government-linked operations known as Flax Typhoon that have targeted power grids, airports and universities worldwide.[1][2][4]

In court documents unsealed in the Western District of Pennsylvania, the Justice Department and FBI said they obtained authorization to take control of seven domains used to host and deliver the Microscan vulnerability scanning tool and the FishHub spearphishing platform.[1][4] Officials said the tools had been used to scan and, in some cases, hack U.S. and foreign critical infrastructure networks, including victims in the power sector and academia.[1][2][11]

The seizures focus on infrastructure operated by Integrity Technology Group, a People’s Republic of China-based information security company that U.S. officials say is closely associated with the Chinese government and is effectively the true identity of Flax Typhoon.[1][2][8] A prior multi-agency assessment described how PRC-linked actors working with Integrity Tech built a large botnet of compromised routers, firewalls, network-attached storage and internet-of-things devices positioned for malicious activity.[13][14] According to the newly unsealed filings, Integrity Tech used a Mirai-variant IoT botnet to power Microscan’s large-scale scanning of victim environments.[4][5]

Microscan itself is described as a Python-based web application containing more than 1,300 penetration-testing scripts designed to probe websites and services for specific vulnerabilities.[4][10] Investigators say Integrity Tech developed Microscan to conduct reconnaissance—via both the botnet and other infrastructure—of victim networks for weaknesses that its clients would later exploit.[4][1] Identified targets include a South Carolina power company, non-governmental organizations, airports in Japan and Poland, Taiwanese critical infrastructure firms and universities, among others.[1][5][8]

FishHub, a second Integrity Tech tool, was allegedly used to facilitate spearphishing campaigns that delivered malware to targeted networks.[4][6] Once attackers obtained an initial foothold, FishHub would download additional malicious software that granted unauthorized remote access or searched for specific files and sent them back to servers controlled by Integrity Tech.[4][6] Authorities say Taiwanese universities were among the victims of these FishHub-enabled operations.[1][5][8]

Federal agencies paired the takedown with a new advisory warning that Chinese government-linked actors enabled by Integrity Tech combine automated scanning tools, large botnets and hands-on exploitation techniques to steal sensitive data from organizations worldwide, including U.S. critical infrastructure sectors.[3][13] The guidance notes that these actors exploit vulnerabilities using scanning tools, cross-site scripting attacks and password spraying against Microsoft Exchange servers, then establish persistence through VPN software and exfiltrate emails and credentials using scripts.[3][13]

Officials characterize the Microscan and FishHub domain seizures as a significant blow to Flax Typhoon, but caution that the broader tactics and tooling will continue to threaten vulnerable organizations.[2][4] Critical infrastructure operators, universities and other high-value targets are urged to patch commonly exploited internet-facing services, harden and monitor Exchange servers, enforce strong authentication on VPNs, and secure routers and IoT devices to avoid being absorbed into covert botnets like the one attributed to Integrity Tech.[13][14] The advisory further encourages network defenders to review the latest technical guidance, update detection rules for Microscan- and FishHub-style activity patterns, and report suspected compromises promptly to law enforcement and national cyber defense authorities.[1][13]

References

  1. Justice Department and FBI Seize Vulnerability Scanning …
  2. The FBI has seized tools used by Chinese hackers for …
  3. DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub
  4. Justice Department and FBI Seize Vulnerability Scanning …
  5. U.S. Seizes China‑Linked Hacking Tools ‘Microscan’ and ‘ …
  6. US seizes hacking tools linked to China
  7. 美FBI查扣中國駭客「亞麻颱風」工具 台灣大專院校與關鍵基礎設施曾遭鎖定
  8. FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
  9. AP News Summary at 1:04 p.m. EDT
  10. People’s Republic of China-Linked Actors Compromise …
  11. Defending Against China-Nexus Covert Networks of Compromised …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply