Voz media US Voz.us

Washington dismantles China-linked cyberespionage network that targeted critical infrastructure

The FBI and the Department of Justice seized seven domains used by the Flax Typhoon hacker group to infiltrate computer networks in the U.S. and other countries. Among their targets were electric utilities, airports and universities.

The Shinyhunters website on the dark web, where the hacker group claims to have hacked the FBI (Illustration)

The Shinyhunters website on the dark web, where the hacker group claims to have hacked the FBI (Illustration)ANP via AFP

Diane Hernández
Published by

The FBI and the Department of Justice announced on Thursday an operation against cyberespionage infrastructure linked to the Chinese regime, which led to the takedown of two tools used to identify computer vulnerabilities, steal information, and illegally access the networks of public and private organizations.

According to a DOJ report, authorities seized seven domains associated with Microscan and FishHub, two platforms operated by hackers linked to Flax Typhoon, a group that, according to U.S. investigators, operates through the Chinese company Integrity Technology Group.

The company, based in China and holding contracts with the government in Beijing, is alleged to have developed tools to facilitate operations involving reconnaissance, system penetration and the extraction of confidential information.

Among the identified targets are an electric utility in South Carolina, airports in Japan and Poland, energy companies in Taiwan, Taiwanese universities, and an international NGO.

How the Chinese hackers operated

According to the federal investigation, Microscan made it possible to detect security vulnerabilities in computer networks that could later be exploited by attackers. To do this, the company used a network of internet-connected devices infected with a variant of the Mirai malware.

FishHub facilitated spear phishing attacks, a form of fraud involving messages targeted at specific victims. Once systems were compromised, the tool could install additional software to enable unauthorized remote access or to locate and extract files.

Authorities confirmed that approximately 20 universities in Taiwan were among the victims of activities related to FishHub.

Washington warns Beijing

Deputy Attorney General for National Security John A. Eisenberg stated that the United States will not allow China or its proxies to act with impunity against U.S. interests in cyberspace.

Brett Leatherman, deputy director of the FBI's Cyber Division, warned that Beijing relies on contractors to expand the reach of its cyber operations.

According to the official, dismantling these platforms aims to hinder new attacks against American networks and infrastructure.

Curbing cyberespionage operations

The operation represents the second public strike against the infrastructure of Integrity Technology Group. In September 2024, U.S. authorities had already dismantled a network of more than 200,000 infected devices—including home and commercial equipment—used to facilitate malicious cyber activities.
​
​The new intervention is part of Washington's efforts to contain cyberespionage operations attributed to actors sponsored by the Chinese regime, especially those targeting sectors critical to national security.
​
​According to the AP, U.S. authorities believe the seizure represents a significant disruption to the group's capabilities, though they remain vigilant against the possibility that it could rebuild its infrastructure.
tracking