VMTech
Discuss a project →

FBI and DoJ seize seven Flax Typhoon domains used to scan critical infrastructure

FBI and DoJ seize seven Flax Typhoon domains used to scan critical infrastructure

The U.S. Federal Bureau of Investigation and Department of Justice have seized seven domains associated with malicious tooling used by the China-linked threat group Flax Typhoon. The action targeted platforms used to scan, and in some cases infiltrate, U.S. critical infrastructure. The seized domains are c0cc[.]cc, 98aiblog[.]com, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com and linkedinns[.]net.

Flax Typhoon is also tracked as Ethereal Panda and RedJuliett. U.S. authorities associate the activity with Integrity Technology Group, a Beijing-based company that contracts with the Chinese government. The FBI and DoJ said the company provided capabilities used for widespread vulnerability scanning and intrusions against U.S. and foreign critical infrastructure.

Domains supported reconnaissance and access operations

Court documents allege that Integrity Technology Group created and operated an IoT botnet using a Mirai variant. The botnet used domains, including subdomains of w8510[.]com, for command-and-control communications and was managed by an application called Sparrow. It was connected to Raptor Train, a botnet of compromised SOHO and IoT devices disrupted through a U.S. court-authorized operation in September 2024.

A database server at 202.182.109[.]151 contained records for more than 1.2 million infected devices on June 5, 2024, including more than 385,000 unique U.S. victim devices. More than 260,000 devices were actively infected at that point, approximately 126,000 of them in the United States.

The seized c0cc[.]cc domain made the Python-based MicroScan web tool available as recently as September 9, 2026, the FBI said. MicroScan, believed to have been in use since at least 2017, includes more than 1,300 penetration-testing scripts targeting vulnerabilities in products and technologies including OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins and Apache Struts.

Scanning was paired with phishing and cloud-account targeting

MicroScan was used alongside open-source tools such as BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe and wpscan. The activity targeted organizations including a South Carolina power company, a multinational non-governmental organization, airports in Japan and Poland, Taiwanese natural-gas and power-sector firms, and two Taiwanese universities.

Authorities also identified FishHub, an Integrity Technology Group tool alleged to support spear-phishing and the deployment of follow-on payloads. The DoJ said FishHub enabled unauthorized remote access or searched victim networks for specific files and sent them to Integrity Technology Group-controlled servers. Confirmed FishHub-related victims included 20 Taiwanese universities.

A joint advisory from agencies in the U.S., U.K., Australia, Canada, Japan, New Zealand and Spain said the company enabled malicious actors by acquiring or developing tools for use and sale and by compromising networks. Since at least mid-January 2021, the actors have used Python- and Go-based command-line utilities, cross-site scripting attacks to harvest credentials, SoftEther VPN clients for persistence, EBurst against Microsoft 365 accounts, and office-cli to access mailbox data.

What organisations should take from the disruption

The domain seizures disrupt identified infrastructure, but the reported techniques span internet-facing systems, cloud services, user credentials and unmanaged connected devices. Organisations operating critical services should maintain an inventory of exposed assets and SOHO or IoT devices, investigate suspicious scanning and account activity, and ensure that Microsoft 365 identities, mailboxes and externally accessible applications receive focused monitoring and remediation.

#cybersecurity#criticalinfrastructure#threatintelligence#cloudsecurity
Open analytics
On the site 1 views
min read 4 09.10.2026
Instagram

FBI and DoJ seize seven Flax Typhoon domains used to scan critical infrastructure

Open the post on Instagram ↗