International coalition seizes tools used by cyber firm behind Flax Typhoon
A US-led coalition seized Flax Typhoon tools Microscan and FishHub operated by China's Integrity Tech.
US and allied cyber agencies announced seizures of websites supporting Microscan and FishHub, tools built by Beijing-based Integrity Technology for China-linked activity associated with Flax Typhoon. Officials said the company, hired by China's Ministry of State Security, supported vulnerability scanning and intrusions against universities, government, telecommunications, media, and critical infrastructure. A 58-page advisory says Microscan has scanned for vulnerabilities since 2017, FishHub enabled phishing and malware delivery, and EBurst password-sprayed Microsoft Exchange accounts to steal email. The FBI previously disrupted the group's Mirai-based botnet of more than 260,000 devices in September 2024.
- The Justice Department seized sites supporting Integrity Tech tools Microscan and FishHub.
- Allies published a 58-page advisory covering six years of Flax Typhoon activity.
- Microscan scanned critical infrastructure; FishHub aided phishing and post-breach malware delivery.
- EBurst password-sprayed Microsoft Exchange accounts, and actors stole victim email.
- The FBI disrupted the group's Mirai botnet of more than 260,000 devices in 2024.
Full article859 words · extracted from therecord.media · click to collapse
Cybersecurity agencies in several countries partnered to take down tools used by state-backed hackers in China to attack critical infrastructure organizations. The actions targeted Integrity Tech, a prominent Chinese cybersecurity company hired by the People’s Republic of China’s (PRC) Ministry of State Security to assist in attacks on universities, government agencies, telecommunications providers and media organizations globally. “Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure,” FBI Assistant Director Brett Leatherman said Thursday. “The PRC relies on contractors and enabling companies to expand the reach and scale of its malicious cyber activity.” The Justice Department seized multiple websites underpinning two powerful hacking tools known as “Microscan” and “FishHub.” U.S. officials published a 58-page advisory on the tools and others that Chinese actors have used over the last six years as part of a long-running campaign known as Flax Typhoon. Beijing-based Integrity Tech uses an array of automated scanning tools, botnets and hands-on-keyboard techniques to steal sensitive data from organizations. Court documents and advisories explained that Integrity Tech built Microscan to conduct reconnaissance for vulnerabilities that could be exploited by Chinese hackers. Victims of the scanning tool include a South Carolina power company, Japanese and Polish airports, Taiwanese critical infrastructure companies in the natural gas and power sectors and more. MicroScan has been used since 2017 for penetration testing scripts written to scan websites for specific vulnerabilities. FishHub was another tool Integrity Tech created to expedite the process of conducting phishing attacks. It allowed hackers to download malware onto a victim’s network after it had been breached. The remote access offered by FishHub was used specifically against about 20 universities in Taiwan, authorities said. The technical advisory was borne from multiple incident response investigations conducted by the FBI on organizations that had been attacked by Integrity Tech or other Chinese groups that used their tools. The Cybersecurity and Infrastructure Security Agency (CISA) and The National Security Agency (NSA) said the company typically targeted edge devices that are not closely monitored because they allowed the hackers to maintain long-term, secret access to an organization. CISA’s acting executive assistant director for cybersecurity, Chris Butera, said Chinese government hackers “continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing.” The countries that contributed to the advisory include Australia, Japan, the U.K., Spain, New Zealand and Canada. Paul Chichester, director of operations at the U.K.’s National Cyber Security Centre, said the “breadth of sectors that have been targeted across the globe demonstrate the extent of the threat.” Integrity Tech is a key cog in China’s web of hacking campaigns — acquiring, selling or hosting tools used by several groups to steal sensitive data and more. Some tools, like EBurst, are used to target compromised email accounts on Microsoft Exchange servers using multiple interfaces for password spraying and password guessing. Others are designed to access emails, calendars and contact. “The FBI recovered an archived email database the threat actors used to target email accounts of victim organizations. The threat actors collect account credentials and exfiltrate victim email data from on-premise systems and cloud-based services,” the agencies said. “Observed victims of email data theft included government organizations, law enforcement agencies, healthcare systems, and religious institutions located in Southeast Asia. In some instances, the threat actors restricted access to the exfiltrated data to only IP addresses from Xiamen, China.” U.S. agencies have repeatedly targeted Integrity Tech with sanctions and takedown efforts over the last three years as concern has grown over its involvement in the Flax Typhoon attacks, which were initially identified publicly by researchers from Microsoft in 2023. In September 2024, the DOJ disrupted Integrity Tech’s Mirai-based botnet, which consisted of more than 260,000 consumer devices. The FBI used a court authorization to remove the malware from infected devices and take control of Flax Typhoon’s internet infrastructure. The group mainly targeted government agencies and education, critical manufacturing and information technology organizations in Taiwan, but Microsoft said it also saw victims across Southeast Asia, North America and Africa. Then-FBI Director Christopher Wray said at the time that Flax Typhoon became adept at infecting internet of things (IoT) hardware like “cameras, video recorders and storage devices — using the breaches to target “everyone from corporations and media organizations to universities and government agencies.” Integrity Technology is best known in China for developing the country’s cyber ranges — powerful training tools that simulate real-world platforms, networks and other digital systems. The company has touted its extensive government funding in the past and experts from the Natto Thoughts research team said the company was founded in 2010 by Cai Jingjing — a legendary hacker in China. ‘Breadth of sectors’
Known entity
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.