FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions
FBI and DOJ seized seven domains disrupting Flax Typhoon's Microscan and FishHub tools used to scan and infiltrate U.S. critical infrastructure.
The FBI and DOJ seized seven domains disrupting tools run by China-linked Flax Typhoon (Integrity Technology Group), used to scan and infiltrate U.S. critical infrastructure. Court documents describe a Mirai-variant IoT botnet (Raptor Train) managed by the Sparrow application, with a database of more than 1.2 million infected devices and roughly 260,000 actively infected (about 126,000 U.S.) as of June 2024. Microscan offered 1,300+ penetration-testing scripts, while FishHub enabled spear-phishing intrusions; confirmed victims include a South Carolina power company, Japanese and Polish airports, Taiwanese gas/power firms, and 20 Taiwanese universities. A seven-nation joint advisory details TTPs including Python/Go utilities, XSS credential harvesting, SoftEther VPN persistence, and EBurst brute-forcing of Microsoft 365; the State Department also offered $10 million for Silk Typhoon suspect Zhang Yu.
- Seven domains seized, disrupting Microscan vulnerability scanner and FishHub phishing tool.
- Botnet database listed 1.2M+ infected devices; ~126,000 U.S. devices actively infected (June 2024).
- Joint advisory from US, UK, Australia, Canada, Japan, New Zealand, and Spain details TTPs.
- Victims include U.S. power company, Japanese and Polish airports, and 20 Taiwanese universities.
- $10 million reward offered for Zhang Yu tied to Silk Typhoon Exchange attacks.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | 98aiblog.com | cture. The list of seized domains is as follows - c0cc[.]cc 98aiblog[.]com 98aicai[.]com 98aicode[.]com outlook3650[.]com youtubecar |
| domain | 98aicai.com | of seized domains is as follows - c0cc[.]cc 98aiblog[.]com 98aicai[.]com 98aicode[.]com outlook3650[.]com youtubecard[.]com linked |
| domain | 98aicode.com | ains is as follows - c0cc[.]cc 98aiblog[.]com 98aicai[.]com 98aicode[.]com outlook3650[.]com youtubecard[.]com linkedinns[.]net Flax |
| domain | c0cc.cc | infrastructure. The list of seized domains is as follows - c0cc[.]cc 98aiblog[.]com 98aicai[.]com 98aicode[.]com outlook3650[. |
| domain | linkedinns.net | ai[.]com 98aicode[.]com outlook3650[.]com youtubecard[.]com linkedinns[.]net Flax Typhoon , also tracked as Ethereal Panda and RedJuli |
| domain | outlook3650.com | ows - c0cc[.]cc 98aiblog[.]com 98aicai[.]com 98aicode[.]com outlook3650[.]com youtubecard[.]com linkedinns[.]net Flax Typhoon , also tr |
| domain |
Full article861 words · extracted from thehackernews.com · click to collapse
The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon.
To that end, the agencies seized several domains and blocked access to platforms that were used to scan, and in some cases infiltrate, U.S. critical infrastructure. The list of seized domains is as follows -
- c0cc[.]cc
- 98aiblog[.]com
- 98aicai[.]com
- 98aicode[.]com
- outlook3650[.]com
- youtubecard[.]com
- linkedinns[.]net
Flax Typhoon, also tracked as Ethereal Panda and RedJuliett, is associated with Integrity Technology Group, a Beijing-based company that contracts with the Chinese government. It was previously attributed to a botnet called Raptor Train that comprised thousands of compromised small office/home office (SOHO) and IoT devices. It was taken down following a U.S. court-authorized operation in September 2024.
"These state-sponsored hackers continue to aggressively target and access networks and systems throughout the world in an effort to identify and steal files and otherwise exploit victims' vulnerabilities," said U.S. Attorney Troy Rivetti for the Western District of Pennsylvania.
Court documents allege that Integrity Tech created and operated an IoT botnet that leveraged a variant of the Mirai malware. According to the FBI, the botnet is said to have used a number of domains, including subdomains of w8510[.]com, for command-and-control (C2), enabling bidirectional communications between the operators and devices in the botnet. The botnet itself was controlled and managed by an application named Sparrow.
A database server hosted on the server ("202.182.109[.]151") contained records for more than 1.2 million infected devices as of June 5, 2024, including over 385,000 unique U.S. victim devices. In all, more than 260,000 devices, including approximately 126,000 U.S. devices, were actively infected as of June 5, 2024.
The botnet made use of a tool called Microscan to facilitate reconnaissance and computer vulnerability scanning, allowing the threat actors to identify targets of interest. The Python-based web tool, originally hosted on "198.13.53[.]226," was accessible via the domain "c0cc[.]cc" as recently as September 9, 2026, according to an FBI affidavit. The tool is believed to have been put to use as early as 2017.
MicroScan features over 1,300 penetration testing scripts to scan websites for specific vulnerabilities, including OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts. The scanner is complemented by open-source tooling like BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe, and wpscan that are used to find vulnerabilities in networks and web-based applications.
Some of the targeted companies include a U.S. power company based in South Carolina, a multi-national Non-Governmental Organization, Japanese and Polish airports, Taiwanese critical infrastructure companies in the natural gas and power sectors, and two Taiwanese universities.
A second Integrity Tech tool is FishHub, which allegedly enabled the exploitation of computer networks through spear-phishing attacks and the deployment of follow-on payloads. Confirmed victims of FishHub-related activity include 20 Taiwanese universities.
"This malware provided Integrity Tech's clients with unauthorized remote access to the victim network or searched for specific files and sent them to servers controlled by Integrity Tech," the DoJ said.
"Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure," said Assistant Director Brett Leatherman of the FBI's Cyber Division.
"The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure."
In tandem, a joint advisory issued by cybersecurity and intelligence agencies from the U.S., the U.K., Australia, Canada, Japan, New Zealand, and Spain has called out the for-profit company for enabling malicious cyber actors to target organizations worldwide by acquiring or building cyber tools for use and sale and compromising networks.
Since at least mid-January 2021, the threat actors have been observed breaking into victim networks and cloud-based services using Python- and Go-based command line utilities, while also relying on cross-site scripting (XSS) attacks to conduct user credential harvesting.
Besides installing SoftEther VPN software clients on victim devices for persistence, the threat actors have been found to use EBurst, an open-source Python-based brute-force tool, to target accounts in Microsoft 365 Cloud environments, and gain unauthorized access to mailbox data using a command-line utility known as office-cli.
"Malicious cyber actors, enabled by Integrity Tech, are uniquely using AI tools, such as automated scanning, alongside large-scale botnets and manual exploitation techniques to compromise and steal confidential data from companies around the world, including critical sectors," the U.K. National Cyber Security Centre (NCSC) said.
The development comes as the U.S. State Department announced rewards of up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the U.S. in connection with the 2021 Microsoft Exchange Server attacks.
The activity is tracked under the moniker Silk Typhoon (formerly Hafnium). In April 2026, co-defendant Xu Zewei was extradited to the U.S. from Italy to face charges related to allegedly stealing COVID-19 research from U.S.-based universities, immunologists, and virologists.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.