Urgent.News

What's breaking now, across thousands of outlets.

Tech

US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide

Infecting devices from 2021 until the FBI stepped in

US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide

The FBI recently seized seven internet domains utilized by a Chinese security firm, Integrity Technology Group, in alleged hacking operations. These domains were linked to tools that Chinese-backed cyber operatives used to scan networks for weaknesses in critical infrastructure, including a power company in South Carolina.

The FBI, alongside agencies in the US, UK, Australia, Canada, Japan, New Zealand, and Spain, warned that these Chinese-linked attackers employ botnets, malware, and other intrusion techniques to target organizations globally and steal sensitive data, such as from US critical infrastructure networks. They exploit vulnerabilities using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers.

Post this activity, the US Cybersecurity and Infrastructure Security Agency (CISA) added five Common Vulnerabilities and Exposures (CVEs) to its Known Exploited Vulnerabilities Catalog. The court-authorized seizures are part of a series of US law-enforcement efforts to disrupt a Beijing-supported cybercrew known as Flax Typhoon, which allegedly used a Mirai-based botnet to infect devices, scan networks, and launch cyberattacks under the guise of Chinese government hackers.

Integrity Tech developed the botnet, a tool called Microscan for scanning vulnerabilities, and a post-compromise tool named FishHub, which allegedly stole sensitive data from infected networks. Allegations suggest Integrity Tech had contracts with the PRC government, linking Flax Typhoon to this private firm. Flax Typhoon reportedly conducted successful computer intrusions into universities in Taiwan and a US power company, as well as other organizations worldwide.

The FBI seized domains like c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net, which facilitated the FishHub malware's distribution and infected over 20 Taiwanese universities. Once the malware infiltrated victims' computers, it used the domains to retrieve additional malicious programs and exfiltrated data to an attacker-controlled server.

Despite the dismantling of a 260,000-device botnet in September 2024, ongoing warnings from private sector security researchers and governments suggest Chinese hackers continue targeting critical networks.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Thursday 8 October →