In a coordinated international action, the FBI announced the seizure of seven web domains linked to hacking tools allegedly operated by Integrity Technology Group, a Chinese security firm. The domains were used by a Beijing-backed cyber crew known as Flax Typhoon to target critical infrastructure globally.
A joint cybersecurity advisory was issued by government agencies from the US, UK, Australia, Canada, Japan, New Zealand, and Spain. The advisory warns that Chinese government-linked attackers, enabled by Integrity Tech, are using botnets and intrusion tools to compromise organizations worldwide and steal sensitive data.
"These actors exploit vulnerabilities by using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while establishing persistence through VPN software and exfiltrating emails and credentials using scripts," the security alert states.
Court documents allege Integrity Tech developed a vulnerability scanner called Microscan, a Mirai-based botnet, and a post-compromise tool named FishHub. The US Cybersecurity and Infrastructure Security Agency (CISA) has added five exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog based on the activity.
Victims cited in the documents include a university in Hsinchu, Taiwan (compromised March 2023), a university in Puli Township, Taiwan (breached August 2022), a South Carolina power company, a multi-national NGO, Japanese and Polish airports, and Taiwanese natural gas and power infrastructure companies.
Five of the seized domains were used to deliver the FishHub malware as recently as March, infecting approximately 20 Taiwanese universities. The malware gave attackers remote access to compromised networks, listing files, searching for specific documents, compressing them, and exfiltrating the selected files to an attacker-controlled server.
In September 2024, the FBI previously disrupted the group's 260,000-device botnet. This latest action underscores the ongoing international effort to counter state-sponsored cyber operations targeting critical infrastructure and allied nations.