Back to Feed
Nation-stateOct 9, 2026

FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions

FBI seizes 7 domains, disrupting Flax Typhoon tools used in critical infrastructure intrusions.

Summary

The FBI and Department of Justice have disrupted tools used by China-linked APT group Flax Typhoon, seizing seven domains and blocking access to platforms used for scanning and infiltrating U.S. critical infrastructure. Flax Typhoon, also known as Ethereal Panda and RedJuliett, is linked to Beijing-based Integrity Technology Group, which allegedly developed an IoT botnet using a Mirai variant and tools like Microscan for vulnerability scanning and FishHub for spear-phishing.

Full text

FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions Ravie LakshmananOct 09, 2026Cyber Espionage / Botnet The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon. To that end, the agencies seized several domains and blocked access to platforms that were used to scan, and in some cases infiltrate, U.S. critical infrastructure. The list of seized domains is as follows - c0cc[.]cc 98aiblog[.]com 98aicai[.]com 98aicode[.]com outlook3650[.]com youtubecard[.]com linkedinns[.]net Flax Typhoon, also tracked as Ethereal Panda and RedJuliett, is associated with Integrity Technology Group, a Beijing-based company that contracts with the Chinese government. It was previously attributed to a botnet called Raptor Train that comprised thousands of compromised small office/home office (SOHO) and IoT devices. It was taken down following a U.S. court-authorized operation in September 2024. "These state-sponsored hackers continue to aggressively target and access networks and systems throughout the world in an effort to identify and steal files and otherwise exploit victims' vulnerabilities," said U.S. Attorney Troy Rivetti for the Western District of Pennsylvania. Court documents allege that Integrity Tech created and operated an IoT botnet that leveraged a variant of the Mirai malware. According to the FBI, the botnet is said to have used a number of domains, including subdomains of w8510[.]com, for command-and-control (C2), enabling bidirectional communications between the operators and devices in the botnet. The botnet itself was controlled and managed by an application named Sparrow. A database server hosted on the server ("202.182.109[.]151") contained records for more than 1.2 million infected devices as of June 5, 2024, including over 385,000 unique U.S. victim devices. In all, more than 260,000 devices, including approximately 126,000 U.S. devices, were actively infected as of June 5, 2024. The botnet made use of a tool called Microscan to facilitate reconnaissance and computer vulnerability scanning, allowing the threat actors to identify targets of interest. The Python-based web tool, originally hosted on "198.13.53[.]226," was accessible via the domain "c0cc[.]cc" as recently as September 9, 2026, according to an FBI affidavit. The tool is believed to have been put to use as early as 2017. MicroScan features over 1,300 penetration testing scripts to scan websites for specific vulnerabilities, including OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts. The scanner is complemented by open-source tooling like BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe, and wpscan that are used to find vulnerabilities in networks and web-based applications. Some of the targeted companies include a U.S. power company based in South Carolina, a multi-national Non-Governmental Organization, Japanese and Polish airports, Taiwanese critical infrastructure companies in the natural gas and power sectors, and two Taiwanese universities. A second Integrity Tech tool is FishHub, which allegedly enabled the exploitation of computer networks through spear-phishing attacks and the deployment of follow-on payloads. Confirmed victims of FishHub-related activity include 20 Taiwanese universities. "This malware provided Integrity Tech's clients with unauthorized remote access to the victim network or searched for specific files and sent them to servers controlled by Integrity Tech," the DoJ said. "Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure," said Assistant Director Brett Leatherman of the FBI's Cyber Division. "The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure." In tandem, a joint advisory issued by cybersecurity and intelligence agencies from the U.S., the U.K., Australia, Canada, Japan, New Zealand, and Spain has called out the for-profit company for enabling malicious cyber actors to target organizations worldwide by acquiring or building cyber tools for use and sale and compromising networks. Since at least mid-January 2021, the threat actors have been observed breaking into victim networks and cloud-based services using Python- and Go-based command line utilities, while also relying on cross-site scripting (XSS) attacks to conduct user credential harvesting. Besides installing SoftEther VPN software clients on victim devices for persistence, the threat actors have been found to use EBurst, an open-source Python-based brute-force tool, to target accounts in Microsoft 365 Cloud environments, and gain unauthorized access to mailbox data using a command-line utility known as office-cli. "Malicious cyber actors, enabled by Integrity Tech, are uniquely using AI tools, such as automated scanning, alongside large-scale botnets and manual exploitation techniques to compromise and steal confidential data from companies around the world, including critical sectors," the U.K. National Cyber Security Centre (NCSC) said. The development comes as the U.S. State Department announced rewards of up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the U.S. in connection with the 2021 Microsoft Exchange Server attacks. The activity is tracked under the moniker Silk Typhoon (formerly Hafnium). In April 2026, co-defendant Xu Zewei was extradited to the U.S. from Italy to face charges related to allegedly stealing COVID-19 research from U.S.-based universities, immunologists, and virologists. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  botnet, Cloud security, critical infrastructure, cyber espionage, law enforcement, Malware, Nation-State, Phishing ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Roo

Indicators of Compromise

  • domain — c0cc[.]cc
  • domain — 98aiblog[.]com
  • domain — 98aicai[.]com
  • domain — 98aicode[.]com
  • domain — outlook3650[.]com
  • domain — youtubecard[.]com
  • domain — linkedinns[.]net
  • domain — w8510[.]com
  • ip — 202.182.109[.]151
  • ip — 198.13.53[.]226

Entities

Flax Typhoon (threat_actor)Ethereal Panda (threat_actor)RedJuliett (threat_actor)Integrity Technology Group (vendor)