The FBI announced that it has seized seven web domains linked to hacking tools allegedly operated by a Chinese security firm called Integrity Technology Group and used by Beijing-backed cyber operatives to scan a South Carolina power company’s network and other critical infrastructure systems for vulnerabilities. In a subsequent advisory, the FBI and other government agencies in the US, UK, Australia, Canada, Japan, New Zealand, and Spain warned that Chinese government-linked attackers, enabled by Integrity Tech, are using botnets, malware, and other intrusion tools to target organizations worldwide and steal sensitive data, including from US critical infrastructure networks. “These actors exploit vulnerabilities by using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while establishing persistence through VPN software and exfiltrating emails and credentials using scripts,” according to the security alert. Based on this activity, the US Cybersecurity and Infrastructure Security Agency (CISA) has added five CVEs to its Known Exploited Vulnerabilities Catalog: CVE-2015-3306 CVE-2015-5477 CVE-2016-3081 CVE-2021-3199 CVE-2023-22894 The court-authorized seizures are the latest in a long series of US law-enforcement attempts to disrupt a Beijing-backed cybercrew called Flax Typhoon and shut down its botnet. From 2021 until its disruption, Flax Typhoon allegedly used a version of this Mirai-based botnet to infect internet-connected devices with malware, scan networks for vulnerabilities, and launch additional cyberattacks, all while hiding the PRC government hackers’ true IP addresses and physical location. The feds allege Integrity Tech developed the botnet and a vulnerability scanner called Microscan, and operated a post-compromise tool called FishHub. The latter allegedly downloaded additional malware to the phishing victims’ networks and stole sensitive data. Court documents, unsealed on Thursday, allege Integrity Tech has contracts with the PRC government, and the feds have long linked Flax Typhoon to the private firm. “Flax Typhoon actors conducted successful computer intrusions against multiple victim entities which had been scanned using the Microscan tool,” according to the court documents. Victims include a university in Hsinchu, Taiwan, that Flax Typhoon compromised in March 2023, and a second university in Puli Township, Taiwan breached in August 2022. “On or about April 26, 2022, and on or about December 29, 2022, Flax Typhoon actors also used the Microscan tool to scan for vulnerabilities on the networks of a U.S. power company based in South Carolina, a multi-national Non-Governmental Organization, Japanese and Polish airports, and at least two Taiwanese critical infrastructure companies in the natural gas and power sectors,” the documents allege. Integrity Tech accessed Microscan through one of the seized domains, c0cc[.]cc. Meanwhile, five of the seized domains, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net, delivered the FishHub malware as recently as March, and infected about 20 Taiwanese universities. “Based on my training and experience I believe the tool was named FishHub because it facilitated phishing activity,” FBI special agent Adam James said in a seizure warrant affidavit. After FishHub downloaded a file onto victims’ computers, that file used the five domains to retrieve additional malicious programs and code. The malware created a file listing, searched for specific files, compressed documents, and then exfiltrated the selected files to an attacker-controlled server. This gave Flax Typhoon remote access to compromised networks. In September 2024, the FBI said Integrity Tech and Flax Typhoon tore down their 260,000-device botnet after the FBI and its international pals went after them. As recently as this year, however, both private sector security researchers and Western governments warned that Chinese hackers continue to turn compromised routers and IoT devices into botnets and break into critical networks. In February, operational technology (OT) security provider Dragos said China’s state-sponsored spies haven’t let up on their attempts to compromise America’s critical infrastructure, and this includes a group whose activity overlaps with Flax Typhoon. This group focuses on gaining long-term access to OT engineering workstations and exfiltrating operational files, and it targets manufacturing, defense, automotive, electric power, oil and gas, and government organizations across the US, Europe, and the Asia-Pacific region. In April, a 10-country joint advisory warned that basically every Chinese “Typhoon” group is using botnets “strategically, and at scale.” Some of these covert networks are built and maintained by Chinese infosec companies including Integrity Tech, which also controlled and managed the so-called Raptor Train network, the alert said. In late August, the FBI said that it had disrupted a different botnet and seized domains associated with two platforms that Chinese government-backed operatives allegedly used to target NASA, the US Senate, the Department of Energy, and several other government agencies and critical networks. The DOJ subsequently clarified that not all the named organizations had been compromised.®
US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide

