By SAFIYAH RIDDLE and ERIC TUCKER
LOS ANGELES (AP) — The FBI has seized scanning and phishing tools used by a group of hackers that officials say is associated with the Chinese government and responsible for disruptive cyber operations in the United States and abroad, including against the power industry, academia and critical infrastructure.
The seizure of the tools, announced Wednesday by the FBI and Justice Department, represents the latest law enforcement effort in recent years to go after a broad-based hacking campaign known to the private sector as Flax Typhoon.
The tools at issue, called “Microscan” and “FishHub,” were used by the hackers to scan, phish and hack targets that included U.S. and foreign critical infrastructure. The tools were used to target, among other entities, an unnamed power company in the U.S., Japanese and Polish airports, Taiwanese universities, a multinational, nongovernmental organization and Taiwanese critical infrastructure companies.
The latest operation has rendered the tools inoperable in what FBI and Justice Department officials said was a blow to the hacking operation.
“We aim to remove the capability from the threat actors. We target their infrastructure, their money, and their tools,” FBI Cyber Division Deputy Assistant Director Jason Bilnoski told The Associated Press, calling the hacking operation “indiscriminate and reckless.”
The tools were operated by a Chinese-based information security company called Integrity Technology Group, which the FBI has said is closely associated with the Chinese government and is the actual identity of Flax Typhoon.
In September 2024, the FBI announced that it had disrupted a botnet associated with Flax Typhoon that installed malicious software on more than 200,000 consumer devices, including cameras, video recorders and home and office routers, to create a massive botnet — a network of infected computers. The botnet was used to facilitate cyber crimes, such as the theft of sensitive information from victims’ networks.
FBI San Diego Supervisory Special Agent Brett Lally said that the department would continue to monitor for ways that the company might rebuild its infrastructure.
“It’ll be interesting to see what this round of disruption actions have in terms of their ability to operate as a company in China,” Lally said.
Tucker reported from Washington.
Click Here For The Original Source.
