FBI Seizes Flax Typhoon Hacking Tools Linked to Chinese Contractor
FBI and DOJ seize domains and disrupt hacking tools used by China-linked Flax Typhoon.
Summary
The FBI and US Department of Justice have seized seven domains and disrupted online platforms used by Flax Typhoon, a China-linked hacking group associated with Integrity Technology Group. The seized infrastructure supported vulnerability scanning and spear-phishing operations targeting US critical infrastructure. The tools, identified as "Microscan" and "FishHub," were used for scanning and infiltration, respectively. This action is part of a broader US effort to counter state-sponsored cyber operations.
Full text
Cyber Crime SecurityFBI Seizes Flax Typhoon Hacking Tools Linked to Chinese ContractorbyWaqasOctober 9, 20262 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening The FBI and DOJ seized domains and disrupted scanning and spear-phishing tools used by Flax Typhoon, a China-linked threat group tied to Integrity Technology Group. The FBI and US Justice Department have seized 7 domains and disrupted online platforms used by Flax Typhoon, a China-linked hacking group associated with Integrity Technology Group. According to the Justice Department, the seized infrastructure supported vulnerability scanning and spear-phishing activity used to target US critical infrastructure and foreign networks. The FBI said the platforms were used to scan, and in some cases infiltrate, critical infrastructure systems. The tools were identified as “Microscan” and “FishHub.” Microscan was used for vulnerability scanning, while FishHub supported spear-phishing operations, according to the Justice Department. Flax Typhoon has previously been linked to large-scale botnets, living-off-the-land techniques and hands-on exploitation. US authorities associate the group with the now-sanctioned Integrity Technology Group, a China-based company accused of supporting cyber activity for the People’s Republic of China. Flax Typhoon attack chain (Microsoft) In a press release, the Justice Department said the disruption targeted the group’s hacking tools, not just one set of servers. The action is part of a wider US effort to expose companies and contractors accused of helping Chinese state-linked cyber operations. The Justice Department identified the following domains as part of the seized infrastructure used to support the Flax Typhoon tools: C0CC.CC 98AICAI.COM 98AIBLOG.COM 98AICODE.COM LINKEDINNS.NET OUTLOOK3650.COM YOUTUBECARD.COM The FBI, CISA, NSA and international partners also issued a joint cybersecurity advisory (PDF) with technical details, indicators of compromise, tactics, techniques and mitigation guidance for network defenders. The seizure notice on the seized domains Previous Flax Typhoon Activity The latest DOJ action follows earlier warnings and enforcement activity involving Flax Typhoon and Integrity Technology Group. In 2023, Microsoft identified Flax Typhoon as a China-linked threat group conducting cyber espionage against government agencies, education, manufacturing, information technology and other sectors. Microsoft said the group relied heavily on living-off-the-land techniques, using legitimate Windows tools and remote access software to maintain access while reducing the chance of detection. The group has also been linked to the Raptor Train botnet, a large network of compromised internet-connected devices that US authorities disrupted in 2024. That botnet was associated with Flax Typhoon activity, but “Flax Typhoon” refers to the threat actor, while “Raptor Train” refers to the botnet infrastructure used in the campaign. Nevertheless, organizations in critical infrastructure sectors should review the advisory, check for listed indicators and look for signs of scanning, spear-phishing and botnet-linked activity associated with the group. Waqas I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism. View Posts ChinaCyber CrimeCybersecurityFlax TyphoonIntegrity Technology GroupPhishingVulnerability Scanner Leave a Reply Cancel reply View Comments (0) Related Posts Read More Malware Security New skimmer attack uses fake credit card form to steal data The unique aspect of this attack is that WebSockets is used instead of other methods such as HTML tags to extract the information needed. bySudais Asif Read More Cyber Crime US Man Jailed 8 Years for SIM Swapping and Apple Support Impersonation In addition to his prison sentence, Amir Hossein Golshan, the culprit, has been ordered to pay $1,218,526 in restitution to his victims. byWaqas Read More Security A Dangerous Vulnerability in Solar Panels can Cause Power Outage Willem Westerhof, a cybersecurity researcher at Dutch security firm ITsec, has identified a serious vulnerability in an essential… byWaqas Read More Security Critical “PixieFail” Flaws Expose Millions of Devices to Cyberattacks Quarkslab Discovers "PixieFail" Vulnerabilities: Critical Flaws in Open Source UEFI Code Require Immediate Patching. byDeeba Ahmed
Indicators of Compromise
- domain — C0CC.CC
- domain — 98AICAI.COM
- domain — 98AIBLOG.COM
- domain — 98AICODE.COM
- domain — LINKEDINNS.NET
- domain — OUTLOOK3650.COM
- domain — YOUTUBECARD.COM