In a massive crackdown on global cyber threats, the United States has seized seven internet domains connected to a widespread Chinese hacking operation. In a statement issued on Thursday, the US Justice Department revealed that these domains were being used by hackers to aggressively scan and breach critical infrastructure systems in the US and across the world.
The hacking operation has been traced back to individuals working with a Chinese IT firm known as Integrity Technology Group.
Who is behind the attacks?
The FBI has directly linked Integrity Technology Group to a notorious state-sponsored hacking collective nicknamed “Flax Typhoon.” According to previous statements by then-FBI Director Christopher Wray, the tech company has been carrying out extensive intelligence collection and reconnaissance operations for Beijing’s security agencies.
Not the first crackdown
Thursday’s domain seizure marks the US government’s second public effort to dismantle Integrity Tech’s dangerous cyber infrastructure. Back in September 2024, the Justice Department successfully disrupted a massive “botnet” run by the very same group.
That network had hijacked more than 250,000 consumer devices worldwide, including everyday gadgets like home Wi-Fi routers and smart cameras, using Mirai malware to launch automated cyberattacks.
How the hackers broke in
The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) released a detailed advisory on how Flax Typhoon managed to infiltrate targeted networks:
Automated Scouting: The group used large-scale botnets and automated tools to constantly hunt for weak spots in enterprise networks.
Targeting Microsoft Exchange: Hackers frequently went after Microsoft Exchange servers, using password-guessing and malicious scripts to break through the front door.
Silent Data Theft: Once inside, the hackers planted scripts to steal sensitive emails and user passwords. They relied heavily on VPN software to blend in and stay hidden within the victim’s network for extended periods.
What happens next?
By seizing these seven internet domains, US officials have essentially severed the main communication lines the hackers used to control their cyber tools. The FBI is now actively investigating the broader network in coordination with global partners, including the National Police Agency of Japan.
The Chinese Embassy in Washington did not immediately respond to requests for comment after business hours on Thursday. However, Beijing routinely denies any involvement in state-sponsored hacking operations.
How to protect your networks
For IT administrators and companies wanting to safeguard their digital borders, CISA recommends three fundamental security steps:
Turn on MFA: Always enforce Multi-Factor Authentication across all digital services and remote access points.
Close Unused Doors: Disable any internet ports, automatic configurations, or file-sharing protocols that your business does not actively need.
Update Everything: Apply the latest software security patches immediately to block hackers from injecting malicious code into your systems.
– Ends
Click Here For The Original Source.
