Ethical Hacking News
The FBI has disrupted the Flax Typhoon tools used in critical infrastructure intrusions, seizing 7 domains and taking down a botnet that compromised thousands of devices. The operation highlights the involvement of Chinese state-sponsored hackers in cyber espionage and raises concerns about the use of AI-powered tools in malicious cyber attacks.
The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) disrupted a China-linked advanced persistent threat group known as Flax Typhoon. Flax Typhoon was linked to a botnet called Raptor Train, which compromised thousands of SOHO and IoT devices. The botnet was controlled by an application named Sparrow, and used a tool called Microscan for reconnaissance and computer vulnerability scanning. Flax Typhoon used a tool called FishHub for spear-phishing attacks and exploiting computer networks. The group is believed to be state-sponsored and has been targeting networks and systems worldwide to identify and steal files. The U.S. is taking action against companies that enable malicious cyber activity, including those that acquire or build cyber tools for use and sale. Rewards have been offered for information leading to the identification or location of Zhang Yu, a Chinese national charged in connection with the 2021 Microsoft Exchange Server attacks.
The recent operation by the U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) has resulted in the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon. Flax Typhoon was also tracked as Ethereal Panda and RedJuliett, and it was previously associated with a botnet called Raptor Train, which comprised thousands of compromised small office/home office (SOHO) and IoT devices.
In September 2024, the Raptor Train botnet was taken down following a U.S. court-authorized operation. However, Flax Typhoon continued to operate and was found to have been linked to Integrity Technology Group, a Beijing-based company that contracts with the Chinese government. This connection highlights the involvement of the Chinese government in the operation of the botnet.
According to the DoJ, Flax Typhoon used various domains, including subdomains of w8510.com, for command-and-control (C2), enabling bidirectional communications between the operators and devices in the botnet. The botnet itself was controlled and managed by an application named Sparrow.
The FBI alleges that Flax Typhoon used a tool called Microscan to facilitate reconnaissance and computer vulnerability scanning, allowing the threat actors to identify targets of interest. Microscan features over 1,300 penetration testing scripts to scan websites for specific vulnerabilities, including OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts.
The botnet made use of a tool called FishHub, which allegedly enabled the exploitation of computer networks through spear-phishing attacks and the deployment of follow-on payloads. Confirmed victims of FishHub-related activity include 20 Taiwanese universities.
The U.S. Attorney Troy Rivetti for the Western District of Pennsylvania stated that Flax Typhoon is a state-sponsored hacking group that continues to aggressively target and access networks and systems throughout the world in an effort to identify and steal files and otherwise exploit victims' vulnerabilities.
Assistant Director Brett Leatherman of the FBI's Cyber Division stated that Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure.
The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, the U.S. makes it harder for the PRC to target American networks and infrastructure.
A joint advisory issued by cybersecurity and intelligence agencies from the U.S., the U.K., Australia, Canada, Japan, New Zealand, and Spain has called out the for-profit company for enabling malicious cyber actors to target organizations worldwide by acquiring or building cyber tools for use and sale and compromising networks.
The threat actors have been observed breaking into victim networks and cloud-based services using Python- and Go-based command line utilities, while also relying on cross-site scripting (XSS) attacks to conduct user credential harvesting.
Besides installing SoftEther VPN software clients on victim devices for persistence, the threat actors have been found to use EBurst, an open-source Python-based brute-force tool, to target accounts in Microsoft 365 Cloud environments, and gain unauthorized access to mailbox data using a command-line utility known as office-cli.
The development comes as the U.S. State Department announced rewards of up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the U.S. in connection with the 2021 Microsoft Exchange Server attacks.
The activity is tracked under the moniker Silk Typhoon (formerly Hafnium). In April 2026, co-defendant Xu Zewei was extradited to the U.S. from Italy to face charges related to allegedly stealing COVID-19 research from U.S.-based universities, immunologists, and virologists.
Related Information:
https://www.ethicalhackingnews.com/articles/FBI-Cracks-Down-on-Chinese-State-Sponsored-Hackers-Flax-Typhoon-Tools-Disrupted-and-Malicious-Domains-Seized-ehn.shtml
https://thehackernews.com/2026/10/fbi-seizes-7-domains-disrupts-flax.html
https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/
https://deepstrike.io/blog/flax-typhoon
https://www.bitsight.com/underground/threat-actors/flax-typhoon
Published: Fri Oct 9 02:44:01 2026 by llama3.2 3B Q4_K_M