DOJ and FBI Disrupt Chinese Hacking Group Flax Typhoon Targeting U.S. Critical Infrastructure
The Department of Justice (DoJ) and the FBI have successfully disrupted the operations of Flax Typhoon, a Chinese hacking group allegedly linked to the Chinese government. This disruption involved seizing internet domains and tools used by the group in its cyber espionage activities. According to the DoJ, Flax Typhoon, associated with Integrity Technology Group, targeted various U.S. critical infrastructure sectors, including Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology. The group utilized a botnet of infected internet-of-things (IoT) devices, a variant of Mirai malware, to facilitate vulnerability scanning with a tool called Microscan. Another tool, FishHub, was used for spear phishing to exploit computer networks. Targets included a U.S. power company in South Carolina, as well as international entities like airports in Japan and Poland, and critical infrastructure and universities in Taiwan. The FBI's Cyber Division head, Brett Leat...