FBI seizes seven domains tied to China-linked Flax Typhoon hacking tools
The FBI and US Justice Department seized seven domains linked to Microscan, a vulnerability-scanning tool, and FishHub, a spear-phishing tool allegedly operated by China-based Integrity Technology Group. US court documents say the tools were used to scan networks and, in some cases, access systems including a South Carolina power company, airports in Japan and Poland, and Taiwanese universities and infrastructure.
Bottom line — The seizure is the second publicly announced US disruption of Integrity Tech’s infrastructure since 2024.
Go deeper 5
-
The FBI and partner agencies in the UK, Australia, Canada, Japan, New Zealand and Spain issued a joint advisory on the alleged activity.
-
Court documents allege Microscan used a Mirai-variant botnet of infected internet-connected devices to scan networks for vulnerabilities.
-
Authorities say FishHub-related activity affected about 20 Taiwanese universities.
-
The FBI advisory describes attackers using password spraying, VPN software and scripts to steal credentials and emails.
-
Reuters reported that the 2024 disruption involved more than 250,000 compromised consumer devices; other reports put the figure above 200,000 or 260,000.