DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


The Justice Department and FBI announced that they had seized two hacking tools connected to the Chinese government-linked group Flax Typhoon and a China-based company that the U.S. government has repeatedly taken action against, including with a new multi-agency advisory Thursday.

The domain name seizures were meant to deny hackers access to the vulnerability scanning tool Microscan and the spearphishing tool FishHub created by the Chinese firm Integrity Technology Group, which the United States sanctioned last year. The U.S. government in 2024 also made the company the focus of a takedown operation, saying it was behind a massive botnet.

Authorities were granted the court-authorized seizures in the Western District of Pennsylvania, the FBI and DOJ announced Thursday in unsealing documents in the case.

U.S. agencies paired the announcement of the seizures with an advisory from the FBI, Cybersecurity and Infrastructure Security Agency and National Security Agency.

“Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide, including U.S. critical infrastructure sectors,” the advisory reads. “These actors exploit vulnerabilities by using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while establishing persistence through VPN software and exfiltrating emails and credentials using scripts.”

Similar to previous allegations, law enforcement said Integrity Tech leaned on a Mirai-variant botnet of internet-of-things devices, in this case to facilitate Microscan.

Microscan targets have included a South Carolina power company, airports in Japan and Poland, critical infrastructure companies and universities in Taiwan and others, according to the FBI and DOJ. Victims of FishHub, which downloads malware on their networks after gaining access through spearphishing, include Taiwanese universities.

“Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing,” said Chris Butera, acting executive assistant director for cybersecurity at CISA. 

“Under the FBI Cyber Strategy, we pursue both the actors who threaten critical infrastructure and the enterprises that support them,” said Brett Leatherman, head of the FBI’s Cyber Division. “Integrity Technology Group, a China-based company with ties to the Chinese government, is one of those enterprises, acquiring or developing cyber tools and hosting infrastructure for actors targeting networks worldwide.”


Written by Tim Starks

Tim Starks is senior reporter at CyberScoop. His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly. An Evansville, Ind. native, he’s covered cybersecurity since 2003. Email Tim here: tim.starks@cyberscoop.com.



Click Here For The Original Source.

——————————————————–

..........

.

.