Federal Agencies Seize China-Based Hacking Tools | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Federal agents seize tools linked to cyberattacks on global networks.


The U.S. Department of Justice (DOJ) and the FBI have seized two computer hacking tools allegedly used by China-linked cyber actors to search for weaknesses in computer networks and gain unauthorized access to systems in the U.S. and other countries. The seize targeted technology connected to Integrity Technology Group, a China-based company with contracts with the Chinese government. Federal officials said the tools, known as Microscan and FishHub, were used by individuals associated with the group identified as Flax Typhoon. Court records unsealed in Pennsylvania describe how the tools helped identify vulnerable computer systems and, in some cases, break into networks. The court-authorized seizures were carried out to prevent those behind the activity from continuing to use the tools and related internet domains.

Microscan was designed to search computer networks for security gaps that could later be used to gain access. According to court records, Integrity Technology Group used a network of internet-connected devices infected with a type of malicious software known as Mirai. This network, called a botnet, allowed the operators to carry out large-scale scans of computer systems. The scans helped to identify possible entry points into networks belonging to businesses, schools, airports and other groups, in order to seize harmful tools.

Reported targets included a power company based in South Carolina, an international nonprofit organization, airports in Japan and Poland, energy companies in Taiwan, and two Taiwanese universities. Investigators said Microscan was accessed through a domain seized during the operation. The findings suggest that the scanning activity reached organizations in several countries and included systems tied to essential services.

Photo by cottonbro studio from Pexels

The second tool, FishHub, was linked to attacks that used targeted email messages to trick people into opening harmful links or files. This method, known as spear phishing, often involves messages designed to appear relevant or trustworthy to a specific person or organization. Once attackers gained an initial foothold in a network, FishHub allegedly helped install additional malicious software. That software could give the attackers remote access to affected systems without permission. It could also search for certain files and send them to servers controlled by Integrity Technology Group. Investigators identified about 20 Taiwanese universities as confirmed victims of FishHub activity. Five internet domains connected to the tool were seized as part of the federal operation.

Officials said the action was intended to make it harder for China-linked groups to reach American networks and systems abroad. They also accused companies working with the Chinese government of helping expand the reach of cyber operations. The allegations described in court records concern activity tied to Integrity Technology Group and its alleged role in supporting the hacking efforts. In September 2024, federal authorities announced a court-approved operation targeting a Mirai-based botnet linked to Integrity Technology Group. That network included more than 200,000 consumer devices in the United States and other parts of the world.

The case reflects continued efforts by American authorities to disrupt cyber operations that threaten government systems, businesses, schools and services relied upon by the public. Investigators are working to identify the people and systems involved while helping network defenders recognize signs of possible attacks.

Sources:

Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers

FBI Seizes Domains Used in Flax Typhoon Attacks

Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers



Click Here For The Original Source.

——————————————————–

..........

.

.