US seizes vulnerability scanning and spear phishing tools used by China-sponsored hackers
Integrity Technology Group enabled vulnerability scanning and intrusions targeting US and foreign critical infrastructure
The US Justice Department and FBI have seized the domains of a company linked to the Flax Typhoon cyber crime group, disrupting access to two hacking tools.
The tools, Microscan and FishHub, were used to scan and compromise critical infrastructure systems and other networks in the US and around the world.
Integrity Technology Group, a China-based company with contracts with the Chinese government, is believed to be behind the activity, which has been linked with campaigns known as Flax Typhoon, Ethereal Panda and Red Juliett, amongst others.
The threat actors use a unique combination of large-scale botnets, VPN infrastructure, living off the land (LOTL) techniques, and repositories of computer network exploitation (CNE) tools.
“Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting US and foreign critical infrastructure,” said assistant director Brett Leatherman of the FBI’s Cyber Division.
“The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure.”
According to US officials, Integrity Tech developed Microscan to conduct reconnaissance, via the botnet and otherwise, of victim computer networks for vulnerabilities that its clients would later exploit.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
A Python-based web application, Microscan contains over 1,300 penetration testing scripts written to scan websites for specific vulnerabilities. The threat actors used these scripts to target services including OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts.
Targets included a US power company based in South Carolina, a multi-national NGO, Japanese and Polish airports, Taiwanese critical infrastructure companies in the natural gas and power sectors, and two Taiwanese universities.
Spear phishing campaign targeted corporate networks
Meanwhile, a second tool, FishHub, is believed to have played a part in the exploitation of computer networks through spear phishing.
After an initial network compromise, FishHub downloaded additional malware to the victim network, giving Integrity Tech’s clients unauthorized remote access. It also searched for specific files and sent them to servers controlled by the group. Confirmed victims included around 20 Taiwanese universities.
"The extensive malicious cyber activities, and services by Integrity Tech, that have been exposed today should be extremely concerning for all network defenders," said Paul Chichester, director of Operations at the UK's National Cyber Security Centre (NCSC).
"The breadth of sectors that have been targeted across the globe demonstrate the extent of the threat and all organizations should take note of this warning."
Last year, the UK government sanctioned Integrity Tech, alongside another China-based information security company, known as i-Soon, for their part in malicious cyber activity.
“These state-sponsored hackers continue to aggressively target and access networks and systems throughout the world in an effort to identify and steal files and otherwise exploit victims’ vulnerabilities,” said attorney Troy Rivetti for the Western District of Pennsylvania.
“These seizures, our second disruption of Integrity Tech’s massive operations in as many years, send another clear message to cybercriminals from the PRC and elsewhere of the department’s dedication to defending and maintaining cybersecurity in the United States and abroad.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Acer Aspire Go reviewReviews The cheapest-ever Aspire Go 15 is a usable and functional budget laptop with surprisingly good battery life
-
What UK tech can learn from a decentralized governmentPodcast RSM head of technology industry, Ben Bilsland, talks to ITPro about the state of the UK's startup ecosystem
-
Accenture contractor removed over blunder in lead up to FBI breachNews The contractor is believed to have failed to apply a security patch that would have secured Oracle PeopleSoft
-
Security experts sound alarm over 'expanded' China-linked botnet used to target US critical infrastructure and military assetsNews The China-linked botnet highlights risk of leaving routers and IoT devices unpatched
-
A ‘perfect storm’: NCSC chief issues warning over quantum threats, nation-state hackers, and the dangers of global ‘hacktivism’News NCSC CEO Richard Horne says nation-state attacks, AI and the looming quantum threat require stronger global collaboration
-
Stryker hackers struck by FBI in domain seizure campaignNews The domain seizures come hot on the heels of Handala's devastating attack on the medical tech firm
-
Thousands of Asus routers are being used to fuel a massive cyber crime spreeNews Black Lotus Labs has spotted a massive botnet of Asus routers built by malware that uses a common peer networking tool
-
Cloudflare warns state-backed hackers are ‘weaponizing legitimate enterprise ecosystems’ as ‘living off the land’ attacks surgeNews Chinese, North Korean, and Russian-backed threat groups now favor longer-term compromises over brute force attacks
-
Europol hails triple takedown with Rhadamanthys, VenomRAT, and Elysium sting operationsNews The Rhadamanthys infostealer operation is one of the latest victims of Europol's Operation Endgame, with more than a thousand servers taken down
-
Seized database helps Europol snare botnet customers in ‘Operation Endgame’ follow-up stingNews Europol has detained several people believed to be involved in a botnet operation as part of a follow-up to a major takedown last year.