DOJ and FBI Seize Flax Typhoon Hacking Tools as CISA NSA Issue Joint Advisory on Chinese Government-Linked Cyber Threats
The Justice Department and FBI announced court-authorized seizures of seven domains, unsealed in the Western District of Pennsylvania on Thursday, to deny access to the Microscan scanning tool and the FishHub spear phishing tool
The seizures remove two tools and seven domains but leave the contractor model intact, so Integrity Tech's operators can rebuild scanning and phishing infrastructure on new domains. The joint advisory shifts the burden to defenders, who must hunt the published indicators in Exchange servers, VPN appliances and exposed web applications. Microscan's 1,300-plus scripts cover common enterprise software, so unpatched OpenSSL, WebLogic, WordPress, Jenkins and Struts deployments stay exposed regardless. Targeting of a South Carolina utility and Japanese and Polish airports points to reconnaissance of operational technology beyond Taiwan, which CISA ties to pre-positioning for disruption. Reporting rests on one Justice Department release that trade press repeats. The action may be mainly signaling, since the tools are cheap to replace and operators may hold backup infrastructure.
7 sources
- Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools -
U.S. Department of Justice (Western District of Pennsylvania) - DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub -
CyberScoop - US seizes vulnerability scanning and spear phishing tools used by China-sponsored hackers -
ITPro - FBI Seized Vulnerability Scanning and Spear Phishing Tools Used by China-Linked Hackers -
Cyber Security News - US Disrupts Chinese State-Sponsored Hacking Tools -
SecurityWeek - FBI disrupts Chinese hacking tools used to breach critical infrastructure -
BleepingComputer - FBI disrupts Flax Typhoon hacking tools used in global cyberattacks -
Help Net Security