DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub
DOJ and FBI seized Flax Typhoon tools Microscan and FishHub tied to China's Integrity Technology Group.
The U.S. Justice Department and FBI said they seized domains for Microscan, a vulnerability scanner, and FishHub, a spearphishing tool, allegedly run by China-based Integrity Technology Group for Flax Typhoon. A Western District of Pennsylvania court authorized the seizures. FBI, CISA, and NSA warned the actors scan for flaws, use cross-site scripting and password spraying against Microsoft Exchange, persist through VPN software, and steal email and credentials, including from U.S. critical infrastructure. Officials said a Mirai-variant IoT botnet supported Microscan, with targets including a South Carolina power company, airports in Japan and Poland, and universities in Taiwan.
- DOJ and FBI seized Microscan and FishHub domains linked to Integrity Technology Group.
- FBI, CISA, and NSA described scanning, XSS, password spraying, and VPN persistence.
- A Mirai-variant IoT botnet reportedly supported Microscan against infrastructure and universities.
- FishHub delivers malware after spearphishing, with Taiwanese university victims.
Full article606 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The seizures of the tools, allegedly operated by the Chinese firm Integrity Tech, accompanied a warning from the FBI, CISA and NSA.
The Justice Department and FBI announced that they had seized two hacking tools connected to the Chinese government-linked group Flax Typhoon and a China-based company that the U.S. government has repeatedly taken action against, including with a new multi-agency advisory Thursday.
The domain name seizures were meant to deny hackers access to the vulnerability scanning tool Microscan and the spearphishing tool FishHub created by the Chinese firm Integrity Technology Group, which the United States sanctioned last year. The U.S. government in 2024 also made the company the focus of a takedown operation, saying it was behind a massive botnet.
Authorities were granted the court-authorized seizures in the Western District of Pennsylvania, the FBI and DOJ announced Thursday in unsealing documents in the case.
U.S. agencies paired the announcement of the seizures with an advisory from the FBI, Cybersecurity and Infrastructure Security Agency and National Security Agency.
“Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide, including U.S. critical infrastructure sectors,” the advisory reads. “These actors exploit vulnerabilities by using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while establishing persistence through VPN software and exfiltrating emails and credentials using scripts.”
Similar to previous allegations, law enforcement said Integrity Tech leaned on a Mirai-variant botnet of internet-of-things devices, in this case to facilitate Microscan.
Microscan targets have included a South Carolina power company, airports in Japan and Poland, critical infrastructure companies and universities in Taiwan and others, according to the FBI and DOJ. Victims of FishHub, which downloads malware on their networks after gaining access through spearphishing, include Taiwanese universities.
“Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing,” said Chris Butera, acting executive assistant director for cybersecurity at CISA.
“Under the FBI Cyber Strategy, we pursue both the actors who threaten critical infrastructure and the enterprises that support them,” said Brett Leatherman, head of the FBI’s Cyber Division. “Integrity Technology Group, a China-based company with ties to the Chinese government, is one of those enterprises, acquiring or developing cyber tools and hosting infrastructure for actors targeting networks worldwide.”
Latest Podcasts
Government
Major rules for federal contractors handling sensitive data are nearing the finish line
FBI, French authorities seize deepfake CSAM-for-sale websites
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
Former NSA chief Nakasone says agency overhaul is ‘probably needed’
Technology
Threats
PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
Citrix discloses third actively exploited NetScaler zero-day in less than a week
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
WaterISAC reckons with range of threats after summer of cyberattacks
Policy
Wiretapping change sparks big privacy fight in the Golden State
Here’s how experts think CISA should tell agencies to protect OT
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
Supreme Court permits states to use SAVE database for citizenship checks