International Coalition Seizes Hacking Tools Linked to Chinese Contractor Behind Flax Typhoon
Cybersecurity agencies from several countries have worked together to disrupt tools used by state-backed hackers in China. The action targeted Integrity Tech, a Beijing-based cybersecurity company that authorities say was hired by China's Ministry of State Security to assist in attacks on universities, government agencies, telecommunications providers and media organisations worldwide. The US Justice Department seized multiple websites that supported two tools known as "Microscan" and "FishHub".
According to court documents and advisories, Microscan was built to scan for weaknesses that Chinese hackers could then exploit. Reported victims include a South Carolina power company, airports in Japan and Poland, and Taiwanese natural gas and power companies. FishHub was designed to speed up phishing attacks and let attackers place malware on a network after it had been breached. It was used against about 20 universities in Taiwan, authorities said.
US officials also published a 58-page advisory covering these and other tools used over the last six years as part of a long-running campaign known as Flax Typhoon. It draws on FBI incident response investigations into organisations hit by Integrity Tech or other Chinese groups using its tools. FBI Assistant Director Brett Leatherman said the PRC relies on contractors and enabling companies to expand the reach and scale of its malicious cyber activity.