Quick Read Summary
- The FBI and US Justice Department say they seized two tools used in cyber operations attributed to a group linked by US officials to the Chinese government.
- The tools, Microscan and FishHub, were used to scan targets and support phishing that could give attackers remote access to networks.
- Targets identified by officials included a US power company, airports in Japan and Poland, Taiwanese universities and infrastructure firms.
The FBI and US Justice Department say they have disabled two tools used in cyber operations attributed to a group known in the private sector as Flax Typhoon. The operation, announced on Thursday, targeted Microscan and FishHub, which officials said were used to identify vulnerable systems and gain access to networks.
Microscan was used to scan targets, including an unnamed US power company, airports in Japan and Poland, Taiwanese universities, a multinational organisation and Taiwanese critical-infrastructure companies. FishHub supported phishing activity that could give attackers remote access to victims’ systems, according to the FBI.
FBI Cyber Division Deputy Assistant Director Jason Bilnoski told the Associated Press that the agency aims to remove capabilities from threat actors by targeting their infrastructure, money and tools. Officials said the seizure rendered the tools inoperable.
The FBI says the tools were operated by Integrity Technology Group, a China-based information-security company that it says has contracts with the Chinese government. US authorities identify the company as the organisation behind Flax Typhoon. Those claims represent the US government’s attribution and should be distinguished from a final judicial finding.
The Chinese government has previously rejected allegations of state-backed hacking. The available report describes the US operation and its findings, but it does not provide an independent assessment from the company accused of operating the tools.
The latest action follows a 2024 FBI operation against a botnet associated with the same group. Authorities said that network had infected more than 200,000 consumer devices, including cameras, video recorders and home or office routers. A botnet can allow operators to use large numbers of compromised devices to conceal activity, scan targets or support further attacks.
Disrupting infrastructure can raise the cost of an operation and force attackers to rebuild their systems. It does not necessarily remove every compromised device or prevent the group from developing replacement tools. FBI officials said they would continue monitoring for efforts to rebuild the infrastructure.
Critical-infrastructure operators should not assume that a law-enforcement seizure means their networks are safe. The case shows the importance of keeping routers and other internet-connected equipment updated, removing default credentials, limiting remote access and monitoring unusual outbound connections.
The tools named by authorities
Phishing remains an important route into organisations because a single compromised account can give an attacker a foothold that is harder to detect than an external scan. Multifactor authentication, strong access controls and tested incident-response plans can reduce the damage if credentials are stolen.
The operation shows a shift toward disrupting the services and tools that support cyber campaigns, rather than focusing only on individual intrusions. Whether that approach produces a lasting reduction in activity will depend on how quickly the operators can replace the seized infrastructure and how effectively potential victims close the weaknesses being exploited.
Cyber investigations often focus on individual victims, but the services used to coordinate an operation can connect many targets. Taking control of command infrastructure or disabling a tool can disrupt several activities at once and provide investigators with information about how an operation was organised. It can also warn potential victims that a campaign has been identified.
Such operations are rarely a permanent solution on their own. Operators can move to new hosting providers, change domains, modify software or recruit other intermediaries. The lasting effect depends on whether defenders use the disruption to close exposed services and whether law enforcement can keep pace with replacement infrastructure.
Attribution is a process rather than a label. Investigators compare technical indicators with earlier campaigns, examine how tools are deployed and look for links between infrastructure, operators and organisations. Some evidence may be withheld publicly to protect sources or ongoing operations, but the public should still distinguish a government's assessment from a judicial finding.
The allegations in this case are directed at a group and a company that US authorities say is connected to the Chinese government. The report does not establish that every employee of the company was involved, nor does it provide a complete independent review of the evidence. Those limits are important when describing responsibility.
Operators of power systems, airports and other essential services should maintain an inventory of internet-facing equipment and remove devices that no longer receive security updates. Remote access should be limited to necessary users, protected with multifactor authentication and monitored for unusual logins. Network segmentation can reduce the chance that a compromised device becomes a path into more sensitive systems.
Organisations should also rehearse how they will respond if a supplier or law-enforcement agency identifies their systems as targets. A tested plan for isolating equipment, preserving logs and restoring service can be more useful than a policy document that has never been exercised.