FBI Seizes Chinese Hacking Tools, Cites Disruption of Cyber Operations
The FBI announced the seizure of scanning and phishing tools linked to a Chinese government-associated hacking group known as Flax Typhoon, disrupting their cyber operations targeting critical infrastructure and other entities.
The FBI has seized scanning and phishing tools used by a group of hackers officials say is associated with the Chinese government and responsible for disruptive cyber operations in the United States and abroad. The seizure of the tools, announced Wednesday by the FBI and Justice Department, represents the latest law enforcement effort to address a broad-based hacking campaign known in the private sector as Flax Typhoon.
The tools, named “Microscan” and “FishHub,” were employed by the hackers to scan, phish, and compromise targets including U.S. and foreign critical infrastructure. Among the entities targeted were an unnamed U.S. power company, airports in Japan and Poland, universities in Taiwan, a multinational non-governmental organization, and Taiwanese critical infrastructure firms.
FBI and Justice Department officials stated that the operation has rendered the seized tools inoperable, marking a significant blow to the hacking group's capabilities. "We aim to remove the capability from the threat actors. We target their infrastructure, their money, and their tools," said FBI Cyber Division Deputy Assistant Director Jason Bilnoski, describing the hacking operation as “indiscriminate and reckless.”
The tools were reportedly operated by Integrity Technology Group, a China-based information security company that the FBI has identified as being closely associated with the Chinese government and the operational identity behind Flax Typhoon.
This action follows a previous disruption in September 2024, when the FBI announced it had dismantled a botnet linked to Flax Typhoon. That operation involved malicious software installed on over 200,000 consumer devices, including cameras, video recorders, and routers, to create a large network used for cybercrimes such as stealing sensitive information.
FBI San Diego Supervisory Special Agent Brett Lally indicated that the department would continue to monitor the company for efforts to rebuild its infrastructure, stating, “It’ll be interesting to see what this round of disruption actions have in terms of their ability to operate as a company in China.”