Urgent.News

What's breaking now, across thousands of outlets.

Tech

The FBI Has Seized Tools Used by Chinese Hackers for Cyber Operations, Officials Say

LOS ANGELES (AP) — The FBI has seized scanning and phishing tools used by a group of hackers that officials say is associated with the Chinese government and is believed responsible for disruptive cyber operations in the United States and abroad, including against the power industry, academia and critical infrastructure.

The FBI has seized scanning and phishing tools utilized by a hacker group believed to be linked to the Chinese government, officials revealed on Thursday. These tools, dubbed "Microscan" and "FishHub," were employed to scan, phish, and infiltrate targets encompassing U.S. and foreign critical infrastructure, academia, and power sectors, officials disclosed.

Microscan was utilized to specifically target a U.S. power company, Japanese and Polish airports, Taiwanese universities, a multinational NGO, and Taiwanese critical infrastructure firms. Meanwhile, FishHub facilitated phishing endeavors, granting hackers remote access to compromised networks, according to the FBI.

The recent operation has rendered these tools ineffective, deemed a setback for the hacking campaign according to FBI and Justice Department officials. Assistant Director Jason Bilnoski emphasized their objective to strip threat actors of their capabilities, targeting their infrastructure, finances, and tools. He labeled the hacking operation as "indiscriminate and reckless."

The tools were operated by a Chinese-based information security firm, Integrity Technology Group, which the FBI identifies as the true identity behind Flax Typhoon. The company holds contracts with the Chinese government, as per the FBI.

Earlier in September 2024, the FBI reported disrupting a vast botnet associated with Flax Typhoon, which had infected over 200,000 consumer devices including cameras, video recorders, and routers, to enable cybercrimes such as stealing sensitive data. FBI San Diego Supervisory Special Agent Brett Lally stated that the department would remain vigilant for any potential reestablishment of the company's infrastructure in China.

Written by urgent.news from The Japan News by The Yomiuri Shimbun's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at japannews.yomiuri.co.jp →

More in Tech

Edge-Agentic Commit Analyzer: A Zero-Dependency Local Guardrail

Edge-Agentic Commit Analyzer: A Zero-Dependency Local Guardrail Why "Daemonless and API-less"? The modern development environment is bloated with background services.

  • Zero-dependency, local guardrail tool
  • Analyzes code changes in developer commits
  • Emphasizes 100% local execution, speed, minimal footprint

Marketplace Agent Logs — Production API JSON Search for Incident Reconstruction

TL;DR: Optimize log management for reconstruction, not collection volume. A marketplace agent run should leave one correlated sequence of request, model, tool, retry, and outcome events, with elapsed…

  • Marketplace agents must log production data in JSON format.
  • Logs should include requestid, runid, stepid, and parentstepid.
  • Structured logs aid privacy-friendly incident reconstruction.

Hosted Application Logging: 5 Node.js Postgres SaaS API Rollback Decisions

TL;DR: Choose a hosted searchable log store with a small, vendor-neutral Node.js contract when manual review is acceptable.

  • Define rollback question with release, asset, trace, and outcome identifiers
  • Use trace ID for linking records, but not for silent cron failures
  • Implement minimal TypeScript application with JSON line logging to hosted service

More from Friday 9 October →