US agencies seize Flax Typhoon domains as seven nations warn of data theft
- law enforcement agencies seized seven internet domains tied to state-sponsored Chinese cyber espionage operations, targeting infrastructure used to probe critical infrastructure globally.
- The coordinated takedown dismantles two primary platforms operated under the hacking cluster known as Flax Typhoon, also tracked by security researchers as Ethereal Panda and RedJuliett.
- The Department of Justice and the Federal Bureau of Investigation targeted the command-and-control mechanisms behind the threat group's reconnaissance and payload delivery systems.
U.S. law enforcement agencies seized seven internet domains tied to state-sponsored Chinese cyber espionage operations, targeting infrastructure used to probe critical infrastructure globally. The operation targeted digital tools operated by Beijing-based Integrity Technology Group, an entity identified by authorities as a contractor for the Chinese government, according to Justice Department records.
The coordinated takedown dismantles two primary platforms operated under the hacking cluster known as Flax Typhoon, also tracked by security researchers as Ethereal Panda and RedJuliett. The targeted domains include c0cc[.]cc, 98aiblog[.]com, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net.
Justice Department and FBI Target Flax Typhoon Infrastructure
The Department of Justice and the Federal Bureau of Investigation targeted the command-and-control mechanisms behind the threat group’s reconnaissance and payload delivery systems. The seized domains supported platforms designated as MicroScan and FishHub, which investigators linked directly to Integrity Technology Group. MicroScan functioned as an automated scanning tool that probed exposed computer systems for vulnerabilities, while FishHub facilitated malicious software delivery following targeted phishing attacks.
Federal officials stated that the seized infrastructure enabled remote access and unauthorized file theft across multiple international targets. Court documents revealed that the MicroScan platform examined networks belonging to a South Carolina power utility, airports in Japan and Poland, and Taiwanese energy operators. Investigators confirmed actual network intrusions at two Taiwanese universities, alongside FishHub-related activity impacting roughly 20 universities in Taiwan.
Global Security Agencies Issue Multi-Nation Warnings
Security authorities across seven countries issued a joint advisory detailing the threat group’s tactics. Agencies from the United States, United Kingdom, Australia, Canada, Japan, New Zealand, and Spain warned that state-backed actors combine automated vulnerability scanning with manual intrusions to harvest credentials and sensitive data. Target sectors span healthcare, manufacturing, government, and IT organizations globally.
The advisory notes that Integrity Technology Group utilized an extensive botnet built on compromised Internet of Things devices and small office routers to mask malicious reconnaissance. A database server discovered during previous investigations contained records of more than 1.2 million infected devices as of June 5, 2024, including over 385,000 unique victim devices in the United States. That botnet relied on a management application named Sparrow and utilized subdomains of w8510[.]com for command communications.
These state-sponsored hackers continue to aggressively target and access networks and systems throughout the world in an effort to identify and steal files and otherwise exploit victims' vulnerabilities.
U.S. Attorney Troy Rivetti for the Western District of Pennsylvania
Officials Recommend Patching and Authentication to Mitigate Risk
While the domain seizures disrupt active communication channels used by the tools, investigators noted that domain takedowns do not automatically remove existing malware from already compromised machines. Officials recommend prompt software patching, mandatory multifactor authentication, and disabling unused network services to mitigate risk. For consumer devices, regulatory bodies advise updating router firmware, replacing default passwords, and turning off unnecessary remote management features to prevent botnet enrolment.
