FBI seizes Flax Typhoon domains in China hacking case | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


U.S. officials seized seven domains linked to Flax Typhoon as security agencies in seven countries warned of attempts to steal sensitive data worldwide.

Key takeaways

  • The FBI and DOJ seized seven domains tied to two hacking platforms and a remote-access tool
  • U.S. officials linked the infrastructure to China-based Integrity Technology Group and Flax Typhoon activity
  • Investigators documented scanning of power utilities, airports and universities and confirmed intrusions of Taiwanese institutions
  • Security agencies in seven countries warned of data theft and called for stronger defenses

FBI targets the infrastructure behind the attacks

U.S. authorities have seized seven internet domains linked to an operation that probed critical infrastructure and infiltrated computer networks across borders. The Justice Department said the domains supported tools run by Integrity Technology Group, a Chinese cybersecurity company with government contracts. Investigators associate the activity with the espionage cluster commonly called Flax Typhoon.

One platform, MicroScan, searched exposed systems for weaknesses. The other, FishHub, helped deliver malicious software after targeted phishing attacks, enabling remote access and the theft of selected files. The seventh domain was associated with remote administration. Seizing domain names can interrupt those operations, although it does not automatically remove malware from computers already compromised.

Targets ranged from airports to universities

According to court records, MicroScan examined networks belonging to a South Carolina electricity provider, airports in Japan and Poland, Taiwanese energy operators and other organizations. Those findings indicate scanning activity, not necessarily successful breaches at every location. Authorities did identify intrusions at two Taiwanese universities and linked FishHub to around 20 universities in Taiwan.

Investigators also described a Mirai-based botnet assembled from infected internet-connected devices. The network helped conceal attackers and carry out scans at scale. Its existence points to an overlooked aspect of espionage campaigns: ordinary routers and smart devices can be hijacked to support attacks against much larger organizations.

Seven nations issue a broader warning

In a joint advisory, agencies from the United States, United Kingdom, Australia, Canada, Japan, New Zealand and Spain warned that China-linked actors have combined automated scanning with hands-on intrusions to steal credentials, email and other sensitive information. Targets have included healthcare, manufacturing, government and IT organizations. The guidance recommends prompt patching, multifactor authentication and shutting off unused services.

The latest seizures follow the FBI’s 2024 disruption of an Integrity Tech-linked botnet spanning more than 200,000 consumer devices. For households, the FTC recommends updating router firmware, replacing default passwords and disabling unnecessary remote management. Bitdefender Ultimate Security can help protect personal computers and phones, while NETGEAR Armor, powered by Bitdefender provides network-level safeguards on compatible routers. Neither replaces device updates or safe configuration.



Click Here For The Original Source.

——————————————————–

..........

.

.