Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

US Disrupts Chinese Hacking Tools as Global Governments Unite to Counter PRC Spy Activities


The US has disrupted a complex network of hacking tools allegedly operated by a Chinese security firm called Integrity Technology Group, as governments around the world warn of the activities of Chinese government-linked attackers. The FBI and other government agencies have issued a joint advisory, urging organizations to take immediate action to protect themselves from these types of attacks. The disruptions highlight the ongoing threat posed by Chinese hacking activities to organizations worldwide and underscore the importance of robust cybersecurity measures.

  • The US has disrupted a complex network of hacking tools allegedly operated by Chinese security firm Integrity Technology Group.
  • Governments around the world have warned of the activities of Chinese government-linked attackers, who are using botnets, malware, and other tools to target organizations worldwide.
  • The FBI and other government agencies have issued a joint advisory, warning of the risks posed by these attacks and urging organizations to take immediate action to protect themselves.
  • The US has added five CVEs to its Known Exploited Vulnerabilities Catalog, including vulnerabilities that were previously exploited by the attackers.
  • The disruption of Integrity Tech's hacking tools is the latest in a long series of US law-enforcement attempts to disrupt a Beijing-backed cybercrew called Flax Typhoon and shut down its botnet.
  • The Flax Typhoon actors conducted successful computer intrusions against multiple victim entities, including universities in Taiwan.
  • The FBI has also disrupted a different botnet and seized domains associated with Chinese government-backed operatives targeting NASA and other government agencies.
  • The disruptions highlight the ongoing threat posed by Chinese hacking activities to organizations worldwide and underscore the importance of robust cybersecurity measures.



  • The world of cybersecurity has been abuzz with the recent news that the United States has disrupted a complex network of hacking tools allegedly operated by a Chinese security firm called Integrity Technology Group. This development has been met with alarm by governments around the world, who have been warning of the activities of Chinese government-linked attackers, enabled by Integrity Tech, who are using botnets, malware, and other intrusion tools to target organizations worldwide and steal sensitive data.

    The FBI and other government agencies in the US, UK, Australia, Canada, Japan, New Zealand, and Spain have issued a joint advisory, warning of the risks posed by these attacks and urging organizations to take immediate action to protect themselves. The advisory highlights the tactics used by these attackers, including the use of scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, as well as the use of VPN software and scripts to establish persistence and exfiltrate sensitive data.

    The US has also added five CVEs to its Known Exploited Vulnerabilities Catalog, including CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, and CVE-2023-22894. These vulnerabilities were previously identified as being exploited by the attackers, and the US is now urging organizations to take action to patch these vulnerabilities and prevent further exploitation.

    The disruption of Integrity Tech's hacking tools is the latest in a long series of US law-enforcement attempts to disrupt a Beijing-backed cybercrew called Flax Typhoon and shut down its botnet. Flax Typhoon allegedly used a version of this Mirai-based botnet to infect internet-connected devices with malware, scan networks for vulnerabilities, and launch additional cyberattacks, all while hiding the PRC government hackers' true IP addresses and physical location.

    The feds allege that Integrity Tech developed the botnet and a vulnerability scanner called Microscan, and operated a post-compromise tool called FishHub. FishHub allegedly downloaded additional malware to the phishing victims' networks and stole sensitive data. Court documents, unsealed on Thursday, allege that Integrity Tech has contracts with the PRC government, and the feds have long linked Flax Typhoon to the private firm.

    The Flax Typhoon actors conducted successful computer intrusions against multiple victim entities, which had been scanned using the Microscan tool. Victims include a university in Hsinchu, Taiwan, that Flax Typhoon compromised in March 2023, and a second university in Puli Township, Taiwan, breached in August 2022.

    The FBI has also disrupted a different botnet and seized domains associated with two platforms that Chinese government-backed operatives allegedly used to target NASA, the US Senate, the Department of Energy, and several other government agencies and critical networks.

    The disruption of these hacking tools and the subsequent warnings from governments around the world highlight the ongoing threat posed by Chinese government-linked attackers to organizations worldwide. It also underscores the importance of robust cybersecurity measures and the need for organizations to take proactive steps to protect themselves from these types of attacks.

    In addition to the disruptions of Flax Typhoon and Integrity Tech, the US has also seen other recent developments in the fight against Chinese hacking activities. Nvidia, for example, has announced that it has found $1 billion under its couch to help secure American scientific computing dominance. The company is also preparing to fortify its arsenal with at least seven AI-optimized supers.

    Furthermore, the US has taken steps to disrupt other Chinese hacking activities, including the seizure of domains associated with two platforms that Chinese government-backed operatives allegedly used to target NASA, the US Senate, the Department of Energy, and several other government agencies and critical networks.

    The disruptions of Flax Typhoon and Integrity Tech, along with other recent developments in the fight against Chinese hacking activities, highlight the ongoing threat posed by these activities to organizations worldwide. It also underscores the importance of robust cybersecurity measures and the need for organizations to take proactive steps to protect themselves from these types of attacks.

    In conclusion, the recent disruptions of Flax Typhoon and Integrity Tech, along with other recent developments in the fight against Chinese hacking activities, highlight the ongoing threat posed by these activities to organizations worldwide. It is essential for organizations to take proactive steps to protect themselves from these types of attacks, including patching vulnerabilities, implementing robust cybersecurity measures, and staying informed about the latest threats and trends in the cybersecurity landscape.

    The US has disrupted a complex network of hacking tools allegedly operated by a Chinese security firm called Integrity Technology Group, as governments around the world warn of the activities of Chinese government-linked attackers. The FBI and other government agencies have issued a joint advisory, urging organizations to take immediate action to protect themselves from these types of attacks. The disruptions highlight the ongoing threat posed by Chinese hacking activities to organizations worldwide and underscore the importance of robust cybersecurity measures.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/US-Disrupts-Chinese-Hacking-Tools-as-Global-Governments-Unite-to-Counter-PRC-Spy-Activities-ehn.shtml

  • https://www.theregister.com/security/2026/10/08/us-disrupts-chinese-hacking-tools-as-7-govts-warn-of-prc-spies-stealing-sensitive-data-worldwide/5302107


  • Published: Thu Oct 8 17:11:11 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us