FBI and allies seize domains behind China's Flax Typhoon hacking tools
TLDR
- The US Justice Department and FBI, backed by a six-country coalition, seized seven domains supporting "MicroScan" and "FishHub," hacking tools built and operated by Beijing-based Integrity Technology Group under contract to China's Ministry of State Security.13
- MicroScan scanned for vulnerabilities at a South Carolina power company, Japanese and Polish airports, and Taiwanese gas and electricity firms, and was used to breach two Taiwanese universities in 2022 and 2023.12
- FishHub ran spear-phishing campaigns and confirmed data theft from roughly 20 Taiwanese universities.1
- The FBI, CISA, NSA and partner agencies in Australia, Japan, the UK, Spain, New Zealand and Canada published a joint 58-page advisory on Integrity Tech's toolset, which also includes an Exchange password-spraying tool called EBurst.3
Court documents unsealed in the Western District of Pennsylvania describe Integrity Tech building and running a Mirai-variant botnet of internet-connected devices to power MicroScan, a reconnaissance platform used to scan victim networks for vulnerabilities that its clients could later exploit.1 MicroScan was accessed through one of the seized domains, c0cc.cc, and BleepingComputer reports it is a Python-based scanner with more than 1,300 penetration-testing scripts targeting widely used software including Oracle WebLogic.2 Its scanning targets included a South Carolina power company, a multinational non-governmental organisation, airports in Japan and Poland, Taiwanese natural gas and power companies, and two Taiwanese universities whose networks were scanned in August 2022 and March 2023 before being breached.12
FishHub, the second tool, facilitated spear-phishing attacks that delivered further malware once a network was compromised, giving Integrity Tech's clients remote access or letting them search for and exfiltrate specific files to Integrity Tech-controlled servers.1 Confirmed FishHub victims included approximately 20 Taiwanese universities.1 Law enforcement seized five domains used to deliver the FishHub malware (98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com and linkedinns.net) plus a seventh domain, 98aiblog.com, tied to the SoftEther VPN software used to maintain persistent access to victim networks.2
"Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure," said FBI Cyber Division Assistant Director Brett Leatherman. "The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure."13 US Attorney Troy Rivetti called the action the department's "second disruption of Integrity Tech's massive operations in as many years."1
Alongside the seizures, the FBI, CISA and NSA published a joint 58-page advisory with Australia, Japan, the UK, Spain, New Zealand and Canada detailing Integrity Tech's broader toolset, including EBurst, used for password spraying against Microsoft Exchange accounts, and tools for accessing emails, calendars and contacts.3 The agencies said they recovered an archived email database the actors used to target victim organisations, with observed victims including government bodies, law enforcement agencies, healthcare systems and religious institutions in Southeast Asia, and that in some instances the actors restricted access to exfiltrated data to IP addresses based in Xiamen, China.3 CISA's acting executive assistant director for cybersecurity, Chris Butera, said Chinese government hackers "continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing."3 The UK National Cyber Security Centre's director of operations, Paul Chichester, said the "breadth of sectors that have been targeted across the globe demonstrate the extent of the threat."3 The activity overlaps with operations also tracked as Flax Typhoon, Ethereal Panda and Red Juliett, though agencies caution not all of it is necessarily linked to Integrity Tech.2
Why it matters: rather than sanctioning or indicting an elusive state-backed hacking crew directly, the US and five allied governments went after the commercial contractor supplying its tools, a disruption strategy that aims to raise costs for the whole ecosystem of companies that rent capability to Chinese state hackers.
Sources
- Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers (U.S. Department of Justice)
- FBI disrupts Chinese hacking tools used to breach critical infrastructure (BleepingComputer)
- International coalition seizes tools used by cyber firm behind Flax Typhoon (The Record)