Full Report
The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide. [...]
Analysis Summary
# Incident Report: FBI Seizure of Flax Typhoon Hacking Infrastructure
## Executive Summary
The FBI, in coordination with international partners, disrupted the operations of the Chinese state-sponsored threat group "Flax Typhoon" (attributed to Integrity Technology Group) by seizing seven operational domains. The group utilized custom vulnerability scanning and spear-phishing platforms (MicroScan and FishHub) to breach critical infrastructure, government agencies, and educational institutions worldwide. The disruption targets the group's ability to maintain persistence and exfiltrate data from compromised networks.
## Incident Details
- **Discovery Date:** Investigation active through September 2026; Joint advisory issued October 8, 2026.
- **Incident Date:** Ongoing activity documented since at least August 2022.
- **Affected Organization:** Multiple (including U.S. government agencies, Japanese/Polish airports, Taiwanese power/gas companies).
- **Sector:** Critical Infrastructure (Energy, Transportation, Government, Healthcare, IT, Education).
- **Geography:** Worldwide (U.S., Taiwan, Japan, Poland, and others).
## Timeline of Events
### Initial Access
- **Date/Time:** Documented instances in August 2022, March 2023, and through 2026.
- **Vector:** Exploitation of known vulnerabilities and spear-phishing.
- **Details:** Use of the "MicroScan" platform and Mirai-based botnets to identify weaknesses, followed by exploitation of CVEs (e.g., Shellshock, Pulse Secure VPN, GitLab RCE).
### Lateral Movement
- Attackers utilized **SoftEther VPN** for maintained access and **EBurst** for password-spraying against Microsoft Exchange servers to gain broader network presence.
### Data Exfiltration/Impact
- **FishHub** platform used to search for, collect, and exfiltrate data. Evidence of stolen data from over 20 organizations was found on a single linked server.
### Detection & Response
- **Detection:** Identified through FBI investigation into Integrity Tech’s infrastructure and botnet activities.
- **Response:** Court-authorized seizure of seven domains; issuance of a multi-agency joint cybersecurity advisory.
## Attack Methodology
- **Initial Access:** Exploitation of CVE-2014-6278, CVE-2019-11510, CVE-2021-22205, etc.; Spear-phishing via FishHub.
- **Persistence:** Installation of SoftEther VPN; use of compromised consumer device botnets.
- **Privilege Escalation:** Not explicitly detailed, but implied through Active Directory credential collection.
- **Defense Evasion:** Use of legitimate-looking domains (e.g., outlook3650[.]com) and decentralized botnet infrastructure.
- **Credential Access:** Password-spraying (EBurst) and Active Directory credential harvesting.
- **Discovery:** Vulnerability scanning via MicroScan; MicroScan utilized Mirai botnets for distributed scanning.
- **Lateral Movement:** VPN-based tunneling and Exchange server exploitation.
- **Collection:** Automated file searching via FishHub; custom web apps for browsing stolen emails.
- **Exfiltration:** Data sent to Integrity Tech-controlled servers via FishHub.
- **Impact:** Unauthorized access and data theft from critical infrastructure providers.
## Impact Assessment
- **Financial:** Costs associated with incident response for dozens of global organizations.
- **Data Breach:** Sensitive files and emails stolen from 20+ organizations, including 6 universities.
- **Operational:** Potential disruption to energy and transportation sectors (extent of disruption not fully disclosed).
- **Reputational:** Public attribution of Integrity Technology Group as a Chinese state contractor.
## Indicators of Compromise
### Network Indicators
- c0cc[.]cc (MicroScan)
- 98aicai[.]com
- 98aicode[.]com
- outlook3650[.]com
- youtubecard[.]com
- linkedinns[.]net
- 98aiblog[.]com (SoftEther VPN)
### File/Behavioral Indicators
- Presence of **SoftEther VPN** software in unauthorized contexts.
- Use of **MicroScan** and **FishHub** custom toolsets.
- **EBurst** activity against Microsoft Exchange.
## Response Actions
- **Containment:** Domain seizures by the FBI effectively "sinkholed" the command-and-control (C2) traffic.
- **Eradication:** Global advisory issued to help organizations identify and remove the Mirai-based malware and FishHub components.
- **Recovery:** Ongoing patching and credential resets for affected critical infrastructure entities.
## Lessons Learned
- **Contractor Proliferation:** State actors increasingly rely on private companies (Integrity Tech) to build and manage offensive infrastructure, complicating attribution and defense.
- **Zombie Vulnerabilities:** Attackers continue to successfully exploit very old vulnerabilities (e.g., Shellshock from 2014) in critical environments.
- **Botnet Synergy:** The integration of Mirai-style botnets with sophisticated state-sponsored scanning platforms allows for unprecedented scale in target identification.
## Recommendations
- **Patch Management:** Prioritize patching of edge-facing services, specifically focusing on the CVEs listed (Pulse Secure, GitLab, Apache Struts).
- **Service Hardening:** Disable unnecessary exposed services and implement strict geo-blocking where applicable.
- **Identity Security:** Enforce Multifactor Authentication (MFA) across all remote access points and email services.
- **Network Monitoring:** Monitor for unauthorized VPN software (SoftEther) and anomalous scanning activity originating from within the network.