US and Allies Disrupt Chinese State-Linked Hacking Campaign Targeting Global Infrastructure

FBI seizes seven domains; joint advisory details widespread data theft from power grids and universities

By LineZotpaper
Published
Read Time2 min
The FBI has seized seven web domains used by a Chinese state-backed hacking campaign as the US, UK, Australia and other allies jointly warned that Beijing-linked cyber operatives are targeting critical infrastructure globally to steal sensitive data.

In a coordinated international action, the FBI announced the seizure of seven web domains linked to hacking tools allegedly operated by Integrity Technology Group, a Chinese security firm. The domains were used by a Beijing-backed cyber crew known as Flax Typhoon to target critical infrastructure globally.

A joint cybersecurity advisory was issued by government agencies from the US, UK, Australia, Canada, Japan, New Zealand, and Spain. The advisory warns that Chinese government-linked attackers, enabled by Integrity Tech, are using botnets and intrusion tools to compromise organizations worldwide and steal sensitive data.

"These actors exploit vulnerabilities by using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while establishing persistence through VPN software and exfiltrating emails and credentials using scripts," the security alert states.

Court documents allege Integrity Tech developed a vulnerability scanner called Microscan, a Mirai-based botnet, and a post-compromise tool named FishHub. The US Cybersecurity and Infrastructure Security Agency (CISA) has added five exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog based on the activity.

Victims cited in the documents include a university in Hsinchu, Taiwan (compromised March 2023), a university in Puli Township, Taiwan (breached August 2022), a South Carolina power company, a multi-national NGO, Japanese and Polish airports, and Taiwanese natural gas and power infrastructure companies.

Five of the seized domains were used to deliver the FishHub malware as recently as March, infecting approximately 20 Taiwanese universities. The malware gave attackers remote access to compromised networks, listing files, searching for specific documents, compressing them, and exfiltrating the selected files to an attacker-controlled server.

In September 2024, the FBI previously disrupted the group's 260,000-device botnet. This latest action underscores the ongoing international effort to counter state-sponsored cyber operations targeting critical infrastructure and allied nations.

§

Analysis

Why This Matters

  • The campaign's targeting of power grids, airports, and universities highlights the vulnerability of essential services to state-sponsored cyber warfare.
  • The joint advisory reflects rare consensus among Western and Asian allies on the severity of Chinese state-linked cyber espionage.
  • The alleged use of a private security firm as a front for state operations blurs the line between commerce and conflict in cyberspace.

Background

Flax Typhoon is a state-sponsored hacking group tracked by Western intelligence agencies. It focuses on compromising infrastructure devices to build botnets for cyber espionage. The FBI first publicly identified the group and disrupted its 260,000-device botnet in September 2024. The current action expands disruption to the specific tools and domain infrastructure used in the campaign.

Key Perspectives

US and Allied Governments: Frame the action as a necessary defensive measure to protect critical national infrastructure and deter state-backed cyber crime. The seizure and public naming serve both operational and diplomatic purposes.

China: Beijing has historically rejected allegations of state-sponsored hacking. It typically frames such cybersecurity operations as defensive or attributes malicious activity to non-state actors.

Cybersecurity Researchers: The technical analysis confirms a highly capable threat actor focused on long-term persistence. While domain seizures disrupt operations, state actors often quickly adapt by moving to new infrastructure.

What to Watch

  • Potential indictments or sanctions against individuals linked to Integrity Technology Group.
  • The rebuilding of the Flax Typhoon infrastructure and emergence of replacement domains.
  • Diplomatic blowback at international cybercrime or security forums.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.

How we workSubscribe