TECH

US seizes domains used by China-linked hackers
The U.S. Department of Justice and the FBI announced the seizure of seven domains associated with China-linked hackers in an operation aimed at disrupting tools used to identify vulnerabilities and attack critical infrastructure. Authorities attribute the activity to Integrity Technology Group, a Chinese company linked to the cyber-espionage group Flax Typhoon.
The intervention, announced on October 8, targeted two software tools named Microscan and FishHub. According to U.S. authorities, the systems enabled the identification of vulnerable networks, the exploitation of security flaws, and unauthorized access to organizations in the United States and other countries.
Microscan and FishHub enabled network identification and attacks...According to the Department of Justice statement, the Microscan tool was used to scan computer networks and identify vulnerabilities that could subsequently be exploited.
Identified targets included a South Carolina electric utility, airports in Japan and Poland, Taiwanese companies in the natural gas and electricity sectors, and universities.
The second tool, FishHub, served a different function. Court documents indicate it facilitated spear-phishing attacks—a technique using targeted messages to trick victims into taking actions that compromise system security.
Following an initial intrusion, FishHub could download additional malicious software, enabling unauthorized remote access to networks or the collection of specific files.
Authorities identified approximately 20 Taiwanese universities among the victims of this activity.
The domain seizure aims to deprive the operators of access to the infrastructure needed to use these tools. The operation may hinder the continuation of the identified campaigns, although it does not mean that all compromised systems have been recovered. Second operation against the Flax Typhoon group
This marks the second public technical intervention by U.S. authorities against infrastructure attributed to Integrity Technology Group.
In September 2024, the Department of Justice announced the dismantling of a botnet comprising over 200,000 compromised devices distributed across the United States and other countries.
The network included routers, video surveillance cameras, digital recorders, and internet-connected storage devices. The infected equipment could be used to carry out malicious operations and mask the origin of the attackers' activities.
At the time, the FBI linked Integrity Technology Group to Flax Typhoon, a group identified by the cybersecurity industry and regarded by U.S. authorities as part of Chinese state-linked cyber-espionage operations.
The new intervention demonstrates that, despite the 2024 operation, authorities have continued to identify tools and infrastructure used by operators associated with the company.
According to Reuters, the FBI believes Integrity Technology Group performs cyber-reconnaissance and intelligence-gathering functions for Chinese security agencies.
The agency notes that the Chinese Embassy in Washington did not immediately respond to a request for comment on the operation. Beijing has repeatedly denied accusations of involvement in cyberattacks.
The link between the company, the seized tools, and the cyber-espionage operations stems from investigations and court documents filed by U.S. authorities. Attributing responsibility to the parties involved does not, in itself, constitute a judicial conviction.
Alongside the domain seizures, the FBI and partner entities issued a cybersecurity alert containing technical indicators associated with Integrity Technology Group's activities. The goal is to help organizations identify potential intrusions and protect their networks against similar attacks.
To that end, the agencies seized several domains and blocked access to platforms that were used to scan, and in some cases infiltrate, U.S. critical infrastructure. The list of seized domains is as follows -
c0cc[.]cc
98aiblog[.]com
98aicai[.]com
98aicode[.]com
outlook3650[.]com
youtubecard[.]com
linkedinns[.]net
Flax Typhoon, also tracked as Ethereal Panda and RedJuliett, is associated with Integrity Technology Group, a Beijing-based company that contracts with the Chinese government. It was previously attributed to a botnet called Raptor Train that comprised thousands of compromised small office/home office (SOHO) and IoT devices. It was taken down following a U.S. court-authorized operation in September 2024.
"These state-sponsored hackers continue to aggressively target and access networks and systems throughout the world in an effort to identify and steal files and otherwise exploit victims' vulnerabilities," said U.S. Attorney Troy Rivetti for the Western District of Pennsylvania.
Court documents allege that Integrity Tech created and operated an IoT botnet that leveraged a variant of the Mirai malware. According to the FBI, the botnet is said to have used a number of domains, including subdomains of w8510[.]com, for command-and-control (C2), enabling bidirectional communications between the operators and devices in the botnet. The botnet itself was controlled and managed by an application named Sparrow.
A database server hosted on the server ("202.182.109[.]151") contained records for more than 1.2 million infected devices as of June 5, 2024, including over 385,000 unique U.S. victim devices. In all, more than 260,000 devices, including approximately 126,000 U.S. devices, were actively infected as of June 5, 2024.
The botnet made use of a tool called Microscan to facilitate reconnaissance and computer vulnerability scanning, allowing the threat actors to identify targets of interest. The Python-based web tool, originally hosted on "198.13.53[.]226," was accessible via the domain "c0cc[.]cc" as recently as September 9, 2026, according to an FBI affidavit. The tool is believed to have been put to use as early as 2017.
MicroScan features over 1,300 penetration testing scripts to scan websites for specific vulnerabilities, including OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts. The scanner is complemented by open-source tooling like BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe, and wpscan that are used to find vulnerabilities in networks and web-based applications.
Some of the targeted companies include a U.S. power company based in South Carolina, a multi-national Non-Governmental Organization, Japanese and Polish airports, Taiwanese critical infrastructure companies in the natural gas and power sectors, and two Taiwanese universities.
A second Integrity Tech tool is FishHub, which allegedly enabled the exploitation of computer networks through spear-phishing attacks and the deployment of follow-on payloads. Confirmed victims of FishHub-related activity include 20 Taiwanese universities.
"This malware provided Integrity Tech's clients with unauthorized remote access to the victim network or searched for specific files and sent them to servers controlled by Integrity Tech," the DoJ said.
"Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure," said Assistant Director Brett Leatherman of the FBI's Cyber Division.
"The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure."
In tandem, a joint advisory issued by cybersecurity and intelligence agencies from the U.S., the U.K., Australia, Canada, Japan, New Zealand, and Spain has called out the for-profit company for enabling malicious cyber actors to target organizations worldwide by acquiring or building cyber tools for use and sale and compromising networks.
Since at least mid-January 2021, the threat actors have been observed breaking into victim networks and cloud-based services using Python- and Go-based command line utilities, while also relying on cross-site scripting (XSS) attacks to conduct user credential harvesting.
Besides installing SoftEther VPN software clients on victim devices for persistence, the threat actors have been found to use EBurst, an open-source Python-based brute-force tool, to target accounts in Microsoft 365 Cloud environments, and gain unauthorized access to mailbox data using a command-line utility known as office-cli.
"Malicious cyber actors, enabled by Integrity Tech, are uniquely using AI tools, such as automated scanning, alongside large-scale botnets and manual exploitation techniques to compromise and steal confidential data from companies around the world, including critical sectors," the U.K. National Cyber Security Centre (NCSC) said.
The development comes as the U.S. State Department announced rewards of up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the U.S. in connection with the 2021 Microsoft Exchange Server attacks.
The activity is tracked under the moniker Silk Typhoon (formerly Hafnium). In April 2026, co-defendant Xu Zewei was extradited to the U.S. from Italy to face charges related to allegedly stealing COVID-19 research from U.S.-based universities, immunologists, and virologists.
mundophone
No comments:
Post a Comment