FBI Seizes Chinese Hacker Tools in Major Cyber Operation

The FBI and US Justice Department seized Microscan and FishHub, hacking tools linked to China-associated Flax Typhoon, used to target power companies, airports, universities and critical infrastructure.
Pelumi Ilesanmi
Pelumi Ilesanmi • Global • 10 hours ago • 2 minute read •
Key Points
• The FBI and Justice Department seized sophisticated scanning and phishing tools from a Chinese government-linked hacking group known as Flax Typhoon.
• The seized tools, "Microscan" and "FishHub," were used to infiltrate critical sectors including power, academia, and infrastructure across the U.S. and internationally.
• This operation has rendered the hacking tools inoperable, marking a significant setback for the group's cyber operations and building on previous disruptions.
FBI Seizes Chinese Hacker Tools in Major Cyber Operation

The Federal Bureau of Investigation (FBI) and the Justice Department have successfully seized sophisticated scanning and phishing tools linked to a hacking group, known to the private sector as Flax Typhoon, which officials assert is associated with the Chinese government.

This operation, announced recently, targets a group responsible for widespread and disruptive cyber activities across the United States and internationally, impacting crucial sectors such as the power industry, academia, and various forms of critical infrastructure.

The seized tools, specifically named “Microscan” and “FishHub,” were instrumental in the hackers' operations to scan, phish, and infiltrate numerous targets.

These included, but were not limited to, an undisclosed power company within the U.S., airports in Japan and Poland, several universities in Taiwan, a multinational non-governmental organization, and other Taiwanese critical infrastructure companies.

The FBI and Justice Department officials confirmed that this latest action has effectively rendered these tools inoperable, marking a significant setback for the hacking operation.

Jason Bilnoski, Deputy Assistant Director of the FBI's Cyber Division, highlighted the strategic intent behind such operations, stating, “We aim to remove the capability from the threat actors. We target their infrastructure, their money, and their tools.”

He further characterized the hacking campaign as “indiscriminate and reckless.” The tools were operated by Integrity Technology Group, an information security company based in China, which the FBI has identified as being closely linked to the Chinese government and as the true identity behind the Flax Typhoon group.

This seizure builds upon previous law enforcement efforts against Flax Typhoon.

In September 2024, the FBI announced the disruption of a botnet associated with the group. This botnet had infected over 200,000 consumer devices, including cameras, video recorders, and home and office routers, to establish a vast network of compromised computers.

This extensive botnet was then utilized to facilitate cyber crimes, predominantly the theft of sensitive information from victim networks.

Looking ahead, FBI San Diego Supervisory Special Agent, Brett Lally, indicated that the department would maintain vigilance, monitoring for any attempts by Integrity Technology Group to rebuild its cyber infrastructure.

Lally expressed curiosity regarding the long-term impact of these disruption actions on the company's ability to continue operating within China.

Loading...