Back to FeedTechnology

U.S. Seizes Seven Domains in Flax Typhoon Disruption

U.S. authorities seized seven domains supporting Microscan and FishHub, tools allegedly used by Integrity Tech-linked actors to target critical infrastructure and other networks.

3 min read|Mefico News News Desk|
Aa
Seven disconnected network nodes protected inside a cybersecurity barrier in a modern data center
Representative image generated with artificial intelligence.

The U.S. Justice Department and FBI have seized seven internet domains used to operate two cyber tools that American authorities say were controlled by actors associated with China-based Integrity Technology Group. The court-authorized action, announced on 8 October, targeted a vulnerability-scanning platform called Microscan and a spear-phishing system called FishHub.

According to court documents unsealed in the Western District of Pennsylvania, the tools were used to scan and, in some cases, gain access to critical infrastructure and other networks in the United States and abroad. The Justice Department described the operators as “Flax Typhoon” actors linked to Integrity Technology Group, a company it says has contracts with the Chinese government. Those claims are allegations by U.S. authorities; Reuters reported that Integrity Tech did not respond to a request for comment, while the Chinese Embassy in Washington rejected the accusations and said China opposes hacking.

What the seized tools allegedly did

The Justice Department said Microscan was built for reconnaissance and vulnerability discovery. It was used through a botnet of compromised internet-of-things devices and through other infrastructure to test networks for weaknesses that clients could later exploit. Targets identified in the court material included a power company in South Carolina, a multinational non-governmental organization, airports in Japan and Poland, Taiwanese companies in the natural-gas and electricity sectors, and two Taiwanese universities.

FishHub allegedly supported the next stage of an intrusion. After a spear-phishing attack established an initial foothold, the system could download additional malware. U.S. authorities said that malware allowed remote access to victim networks or searched for selected files and transferred them to servers controlled by Integrity Tech. Approximately 20 Taiwanese universities were confirmed victims of FishHub activity, according to the Justice Department.

A separate multinational cybersecurity advisory described broader activity attributed to actors associated with Integrity Tech, including vulnerability scanning, password attacks against Microsoft 365 and Exchange accounts, and tools designed to collect email. Independent security publication The Hacker News reported that the advisory linked the activity to targets across Southeast Asia, Africa and North America. The advisory also warned network defenders about technical indicators that could be used to identify possible compromises.

Second public U.S. disruption action

The latest seizure follows a September 2024 operation against a botnet that U.S. authorities attributed to Integrity Tech. Reuters reported that the earlier botnet contained more than 250,000 compromised consumer devices worldwide. At the time, U.S. officials said the infrastructure supported reconnaissance and intelligence collection associated with the cluster widely tracked as Flax Typhoon.

The new action is narrower in one sense: it removes access to named domains and tools rather than announcing criminal convictions. Domain seizures can interrupt command systems, deny operators access to infrastructure and give investigators additional technical evidence. They do not, by themselves, establish every attribution claim in court. The public documents therefore matter both as a defensive warning and as the U.S. government’s account of how the infrastructure operated.

For organizations, the practical significance lies in the targeting pattern. Critical infrastructure, universities, government services, healthcare, technology providers and religious organizations were among the sectors named in official and independent reporting. Defenders are being urged to review indicators of compromise, close known vulnerabilities, monitor unusual authentication activity and strengthen protections around internet-facing services and email accounts.

The dispute also reflects continuing tensions between Washington and Beijing over cyber operations. U.S. agencies increasingly use domain seizures, sanctions and public technical advisories together to expose and disrupt alleged state-backed activity. China continues to deny the accusations and says the United States politicizes cybersecurity. No new criminal judgment against Integrity Tech was announced with the seizure; the immediate verified development is the court-authorized removal of seven domains supporting Microscan and FishHub.

Sources

This article was prepared with AI assistance and its sources were checked by the Mefico News News Desk.

Like/dislike buttons become active once you finish reading the article.