US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwidenew
FBI seized seven Flax Typhoon-linked domains as seven governments warned of PRC data theft.
The FBI seized seven domains linked to tools from Chinese firm Integrity Technology Group that Flax Typhoon allegedly used to scan and intrude on networks, including a South Carolina power company. Agencies in the US, UK, Australia, Canada, Japan, New Zealand, and Spain warned that PRC-linked actors use botnets, malware, vulnerability scanning, cross-site scripting, and password spraying against Microsoft Exchange to steal data. CISA added CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, and CVE-2023-22894 to the KEV catalog. Court filings say Microscan and FishHub supported intrusions at Taiwanese universities and scans of airports and critical infrastructure.