Hermes Vector

Tech

FBI Seizes Cyber Tools Used by Chinese Hacker Group Flax Typhoon

The FBI and Justice Department seized scanning and phishing tools used by a group associated with the Chinese government. The operation targeted tools linked to disruptive cyber activities against critical infrastructure.

By Hermes-Vector AI Desk

Also in: Español · Português · Français · Deutsch · हिन्दी

Checked against 4 sourcesbnnbloomberg.caFortunebozemandailychronicle.comottumwacourier.com
Illustration for: FBI Seizes Cyber Tools Used by Chinese Hacker Group Flax Typhoon

In brief

  • The FBI seized scanning and phishing tools named Microscan and FishHub used by a group associated with the Chinese government.
  • The tools were operated by Integrity Technology Group, which the FBI identifies as the true identity of the Flax Typhoon hacking campaign.
  • Targets included a U.S. power company, Japanese and Polish airports, and Taiwanese universities and critical infrastructure companies.
  • This follows a September 2024 disruption of a Flax Typhoon botnet that infected more than 200,000 consumer devices.

FBI Seizes Cyber Tools Used by Chinese Hacker Group Flax Typhoon

The FBI has seized scanning and phishing tools utilized by a hacking group that officials say is associated with the Chinese government and responsible for disruptive cyber operations in the United States and abroad. The seizure, announced by the FBI and Justice Department, targets a broad-based hacking campaign known to the private sector as Flax Typhoon.

Tools Rendered Inoperable

The tools seized, identified as “Microscan” and “FishHub,” were used by hackers to scan, phish, and hack targets including U.S. and foreign critical infrastructure. According to officials, Microscan was used to target an unnamed power company in the U.S., Japanese and Polish airports, Taiwanese universities, a multinational non-governmental organization, and Taiwanese critical infrastructure companies. The FBI stated that “FishHub” facilitated phishing activity that granted hackers remote access to victim networks.

The operation has rendered these tools inoperable. FBI Cyber Division Deputy Assistant Director Jason Bilnoski described the hacking operation as “indiscriminate and reckless.”

“We aim to remove the capability from the threat actors. We target their infrastructure, their money, and their tools,” Bilnoski said in an interview with The Associated Press.

Link to Integrity Technology Group

Officials identified the tools as being operated by a Chinese-based information security company called Integrity Technology Group. The FBI says the company has contracts with the Chinese government and is regarded as the true identity of Flax Typhoon.

This action follows previous law enforcement efforts against the group. In September 2024, the FBI announced it had disrupted a massive botnet associated with Flax Typhoon. That botnet installed malicious software on more than 200,000 consumer devices, including cameras, video recorders, and home and office routers. The network of infected computers was used to facilitate cyber crimes, such as the theft of sensitive information from victims’ networks.

Ongoing Monitoring

FBI San Diego Supervisory Special Agent Brett Lally stated that the department would continue to monitor for ways the company might rebuild its infrastructure.

“It’ll be interesting to see what this round of disruption actions have in terms of their ability to operate as a company in China,” Lally said.

Why it matters

The seizure represents the latest law enforcement effort in recent years to disrupt the Flax Typhoon hacking campaign. By rendering the specific tools used for scanning and phishing inoperable, officials aim to hinder the group's ability to conduct cyber operations against critical sectors such as the power industry, academia, and infrastructure.


Sources

This article was drafted with AI assistance and checked against the sources above. Company claims are reported as claims. Cover image is AI-generated.

Questions readers ask

What tools did the FBI seize from the Flax Typhoon hacking group?
The FBI seized scanning and phishing tools identified as Microscan and FishHub, which were used to target critical infrastructure and facilitate remote access to victim networks.
Who is responsible for operating the Flax Typhoon hacking group?
Officials identified the tools as being operated by Integrity Technology Group, a Chinese-based information security company that has contracts with the Chinese government.
What targets were affected by the Microscan tool?
Microscan was used to target an unnamed U.S. power company, Japanese and Polish airports, Taiwanese universities, a multinational non-governmental organization, and Taiwanese critical infrastructure companies.
What previous disruption did the FBI announce regarding Flax Typhoon?
In September 2024, the FBI announced it had disrupted a massive botnet associated with Flax Typhoon that installed malicious software on more than 200,000 consumer devices.
Why does this seizure matter for critical sectors?
The seizure aims to hinder the group's ability to conduct cyber operations against critical sectors such as the power industry, academia, and infrastructure by rendering their specific scanning and phishing tools inoperable.

The day's checked news, by email

One short email a day with the top stories. Free, and you can unsubscribe in one click.

Advertisement

Comments

Tech

Microsoft Releases Windows 11 2026 Update, Version 26H2

Microsoft began rolling out Windows 11 version 26H2 on September 29 as a small enablement package that resets the support clock for PCs that install it.

Checked against 6 sourcesghacks.netpureinfotech.comwindowslatest.com+3 more