Why it matters
Operators of critical infrastructure should assess whether their systems were targeted by MicroScan or FishHub and follow their incident-response procedures.
What we know
Confirmed by several sources
- The FBI seized seven domains used to operate MicroScan and FishHub, tools linked to Flax Typhoon. — Help Net Security, BleepingComputer
- The tools were used to scan for and attack critical infrastructure and other organizations. — Help Net Security, SecurityWeek, BleepingComputer
- The tools targeted organizations in the United States and abroad. — Help Net Security, SecurityWeek, BleepingComputer
Reported by one source
- The tools were used by Flax Typhoon and other advanced persistent threat groups. — SecurityWeek
Open questions
- The extent of the devices affected by the campaign remains unclear. — The Register
Coverage 4 publishers
BleepingComputerFirst report
FBI disrupts Chinese hacking tools used to breach critical infrastructure
The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide.
-
US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide
Infecting devices from 2021 until the FBI stepped in
-
US Disrupts Chinese State-Sponsored Hacking Tools
Flax Typhoon and other APTs used MicroScan and FishHub to scan and hack US and foreign critical infrastructure.
-
FBI disrupts Flax Typhoon hacking tools used in global cyberattacks
The FBI seized seven domains used to operate Microscan and FishHub, two hacking tools linked to Chinese state-sponsored hackers known as Flax Typhoon that were used to target critical infrastructure and other organizations in the US and…
Earliest report first. Articles stay on their publishers’ sites; each link opens the original.
