Full Report
The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon. To that end, the agencies seized several domains and blocked access to platforms that were used to scan, and in some cases infiltrate, U.S. critical infrastructure. The list of seized
Analysis Summary
# Incident Report: Disruption of Flax Typhoon Botnet and Infrastructure
## Executive Summary
The U.S. FBI and DoJ disrupted a significant cyber espionage infrastructure operated by the China-linked APT group Flax Typhoon (Integrity Technology Group). The operation involved the seizure of domains and tools, including a Mirai-based IoT botnet known as "Raptor Train" and vulnerability scanning platforms. These tools were used to target and infiltrate critical infrastructure, NGOs, and educational institutions globally.
## Incident Details
- **Discovery Date:** Documented activity as early as 2017; major enforcement actions in September 2024 and October 2026.
- **Incident Date:** Continuous operations from 2017 through late 2026.
- **Affected Organization:** Multiple entities, including U.S. power companies, airports (Japan/Poland), and Taiwanese universities.
- **Sector:** Critical Infrastructure, Energy, Aviation, Education, and NGOs.
- **Geography:** Global, with heavy concentration in the U.S. and Taiwan.
## Timeline of Events
### Initial Access
- **Date/Time:** Ongoing since 2017.
- **Vector:** Spear-phishing and exploitation of known vulnerabilities in web-facing applications.
- **Details:** The group used the "FishHub" tool for spear-phishing and "Microscan" to identify unpatched servers.
### Lateral Movement
- **Details:** Once initial access was gained via FishHub or exploited vulnerabilities, the group deployed follow-on payloads to establish remote access and navigate victim networks to locate sensitive files.
### Data Exfiltration/Impact
- **Details:** Unauthorized remote access was used to search for and exfiltrate specific files to C2 servers controlled by Integrity Technology Group.
### Detection & Response
- **Detection:** Collaborative intelligence effort involving CISA, FBI, and international partners (Five Eyes, Japan, Spain).
- **Response actions taken:** Court-authorized seizure of seven malicious domains and disruption of C2 servers. Previous takedown of the "Raptor Train" IoT botnet in September 2024.
## Attack Methodology
- **Initial Access:** Spear-phishing (FishHub) and vulnerability scanning (Microscan).
- **Persistence:** Mirai malware variants on IoT/SOHO devices; unauthorized remote access tools.
- **Defense Evasion:** Use of a massive botnet of legitimate SOHO/IoT devices to mask C2 traffic and scanning activity.
- **Discovery:** Large-scale reconnaissance using Microscan (1,300+ scripts) and open-source tools like NMAP and masscan.
- **Lateral Movement:** Remote access payloads and automated penetration testing scripts.
- **Exfiltration:** Bidirectional communication via C2 domains to move stolen data to actor-controlled servers.
- **Impact:** Exploitation of critical infrastructure and theft of proprietary/sensitive data.
## Impact Assessment
- **Financial:** Significant costs associated with incident response for 1.2 million+ infected devices.
- **Data Breach:** Compromise of files from U.S. power companies, NGOs, and academic institutions.
- **Operational:** Disruption of over 260,000 active botnet nodes; potential for disruptive actions against critical infrastructure.
- **Reputational:** Public exposure of Integrity Technology Group as a front for Chinese state-sponsored activity.
## Indicators of Compromise
### Network Indicators
- c0cc[.]cc
- 98aiblog[.]com
- 98aicai[.]com
- 98aicode[.]com
- outlook3650[.]com
- youtubecard[.]com
- linkedinns[.]net
- w8510[.]com (subdomains)
- 202.182.109[.]151 (Database server)
- 198.13.53[.]226 (Microscan host)
### Behavioral Indicators
- Large-scale scanning for vulnerabilities in Oracle WebLogic, Jenkins, Apache Struts, and WordPress.
- High-volume traffic originating from compromised SOHO routers and IoT devices (Mirai variants).
## Response Actions
- **Containment:** Domain seizures to break C2 communication.
- **Eradication:** Court-authorized technical disruption of the "Sparrow" management application.
- **Recovery:** Public attribution and joint international advisories to assist victims in patching scanned vulnerabilities.
## Lessons Learned
- **Contractor Proliferation:** The PRC increasingly relies on private "contractor" companies (like Integrity Tech) to provide scale for state-sponsored operations.
- **IoT Vulnerability:** SOHO and IoT devices remain a primary weak point, used to build massive proxy networks that hide state-sponsored activity.
- **Tool Convergence:** The group successfully blended custom tools (Microscan) with common open-source tools (NMAP, wpscan) to increase efficiency.
## Recommendations
- **Edge Device Security:** Regularly patch and update SOHO routers and IoT devices; replace devices that are End-of-Life (EoL).
- **Vulnerability Management:** Prioritize patching for the 1,300+ vulnerabilities targeted by Microscan, specifically Jenkins and Apache Struts.
- **Network Monitoring:** Implement behavior-based detection to identify anomalous traffic patterns from unexpected geographical locations or IoT devices.