Why it matters
Operators of US critical infrastructure should review exposure to the scanning and intrusion activity linked to Flax Typhoon and apply their established incident-response procedures.
What we know
Confirmed by several sources
- Authorities in the United States and other countries disrupted digital tools and infrastructure associated with Flax Typhoon. — The Hacker News, The Record
- The tools were used for widespread vulnerability scanning and, in some cases, intrusions affecting critical infrastructure. — The Hacker News, The Record
Reported by one source
- The FBI and Justice Department seized several domains. — The Hacker News
- The infrastructure was operated by Beijing-based Integrity Tech. — The Record
Coverage 2 publishers
The RecordFirst report
International coalition seizes tools used by cyber firm behind Flax Typhoon
The U.S. and other nations took down digital tools and infrastructure by Beijing-based Integrity Tech that allowed "widespread vulnerability scanning and, in some cases, intrusions" as part of the Flax Typhoon campaign.
-
FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions
The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon. To that end, the agencies seized…
Earliest report first. Articles stay on their publishers’ sites; each link opens the original.
