DevelopingSecurity

FBI seizes seven domains used by Flax Typhoon hacking tools

Brievox summary

The FBI seized seven domains used to operate MicroScan and FishHub, tools linked to Flax Typhoon and used to target critical infrastructure and other organizations. One account says the activity affected US and foreign targets; another describes worldwide breaches.

Image: BleepingComputer

Why it matters

Operators of critical infrastructure should assess whether their systems were targeted by MicroScan or FishHub and follow their incident-response procedures.

What we know

Confirmed by several sources

Reported by one source

  • The tools were used by Flax Typhoon and other advanced persistent threat groups. — SecurityWeek

Open questions

  • The extent of the devices affected by the campaign remains unclear. — The Register

Coverage 4 publishers

  1. BleepingComputerFirst report

    FBI disrupts Chinese hacking tools used to breach critical infrastructure

    The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide.

  2. The Register

    US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide

    Infecting devices from 2021 until the FBI stepped in

  3. SecurityWeek

    US Disrupts Chinese State-Sponsored Hacking Tools

    Flax Typhoon and other APTs used MicroScan and FishHub to scan and hack US and foreign critical infrastructure.

  4. Help Net Security

    FBI disrupts Flax Typhoon hacking tools used in global cyberattacks

    The FBI seized seven domains used to operate Microscan and FishHub, two hacking tools linked to Chinese state-sponsored hackers known as Flax Typhoon that were used to target critical infrastructure and other organizations in the US and…

Earliest report first. Articles stay on their publishers’ sites; each link opens the original.