Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > FBI Seizes Seven Domains Supporting Flax Typhoon Scanning and Phishing Operations
FBI Seizes Seven Domains Supporting Flax Typhoon Scanning and Phishing Operations
Read Time:3 Minute, 8 Second

The FBI and U.S. Department of Justice have seized seven domains associated with two hacking platforms allegedly operated by China-based Integrity Technology Group. The court-authorized action targets Microscan and FishHub, tools that investigators say supported large-scale vulnerability discovery, spear phishing, malware delivery, data theft, and persistent access.

Court documents unsealed in the Western District of Pennsylvania connect the operation to Flax Typhoon, a threat group widely tracked by security researchers. U.S. authorities allege that Integrity Technology Group holds Chinese government contracts and supplied capabilities used to identify and compromise targets. The October 8 disruption removes important access points, but it does not automatically evict attackers from previously breached networks.

Compromised Devices Powered Large-Scale Scanning

Investigators say Integrity Tech used a Mirai variant to assemble a botnet of internet-connected equipment. That network and other infrastructure supported Microscan, a Python-based web application containing more than 1,300 penetration-testing scripts. Operators could centrally scan websites and services for weaknesses affecting products such as Oracle WebLogic, WordPress, Jenkins, Apache Struts, OpenSSL, and Juniper ScreenOS.

Authorities traced Microscan activity back to at least 2017. Named scanning targets included a South Carolina power company, airports in Japan and Poland, energy providers in Taiwan, a multinational non-governmental organization, and Taiwanese universities. A scan identifies possible entry points; it should not be confused with proof that every listed organization was successfully breached.

The seized domain c0cc[.]cc provided access to Microscan. Taking it away is intended to interrupt the operators’ workflow and deprive customers of a central interface for managing findings. The action follows a September 2024 disruption of an Integrity Tech botnet containing more than 200,000 routers, cameras, recorders, and network-attached storage devices worldwide.

FishHub Enabled Phishing and Follow-On Access

FishHub served a different phase of operations. Prosecutors allege it supported targeted phishing and the delivery of additional malware after an initial foothold. That follow-on code could grant remote access or search for particular files and transfer them to infrastructure controlled by Integrity Tech.

Approximately 20 Taiwanese universities were confirmed as FishHub victims, according to the government account. Five seized domains—98aicai[.]com, 98aicode[.]com, linkedinns[.]net, outlook3650[.]com, and youtubecard[.]com—supported malware delivery. Another domain, 98aiblog[.]com, was associated with SoftEther VPN software used to maintain unauthorized remote connections.

The broader advisory describes password spraying against Microsoft Exchange interfaces, automated email theft, and VPN-based persistence. Those observations provide context for Integrity Tech-linked activity, though defenders should not assume every technique was a feature of FishHub itself.

Domain Seizure Is a Starting Point for Defenders

Infrastructure disruption can impose costs and generate valuable intelligence, but compromised organizations may still contain malware, stolen accounts, scheduled tasks, VPN tools, or alternate access paths. Security teams should use the newly published indicators to review historical DNS, proxy, firewall, identity, email, and endpoint telemetry.

  • Patch internet-facing applications and network devices, prioritizing known exploited weaknesses.
  • Disable unnecessary services and restrict administrative interfaces to trusted management networks.
  • Require phishing-resistant multifactor authentication where possible and investigate password-spraying patterns.
  • Search for unexpected SoftEther or other remote-access installations and unusual outbound transfers.
  • Preserve logs and isolate affected hosts before removing access if compromise is suspected.

Matches should be investigated in context because domain or IP contact alone may not establish an intrusion. Conversely, a clean check against the seized domains cannot rule out alternate infrastructure. Organizations with relevant exposure should trace activity from the earliest suspicious event, identify every affected identity and system, and rotate credentials only from trusted devices. They should also revisit older alerts that may have been closed as routine scanning. The seizures make a mature operation harder to run; defenders must complete the job inside their own environments.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on FBI Seizes Seven Domains Supporting Flax Typhoon Scanning and Phishing Operations, use the discussion on Forum.

>> forum community

Comments

Leave a Reply