The FBI has seized tools used by Chinese hackers for cyber operations, officials say
Advertisement
Read this article for free:
or
Already have an account? Log in here »
To continue reading, please subscribe:
Digital Subscription
One year of digital access for only $205*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.
To continue reading, please subscribe:
Add Free Press access to your Brandon Sun subscription for only an additional
$1 for the first 4 weeks*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.
Read unlimited articles for free today:
or
Already have an account? Log in here »
LOS ANGELES (AP) — The FBI has seized scanning and phishing tools used by a group of hackers that officials say is associated with the Chinese government and is believed responsible for disruptive cyber operations in the United States and abroad, including against the power industry, academia and critical infrastructure.
The seizure of the tools, announced Thursday by the FBI and Justice Department, represents the latest law enforcement effort in recent years to go after a broad-based hacking campaign known to the private sector as Flax Typhoon.
The tools at issue, called “Microscan” and “FishHub,” were used by the hackers to scan, phish and hack targets that included U.S. and foreign critical infrastructure, officials said. Microscan was used to target, among other entities, an unnamed power company in the U.S., Japanese and Polish airports, Taiwanese universities, a multinational, nongovernmental organization and Taiwanese critical infrastructure companies. And “FishHub” facilitated phishing activity that gave hackers remote access to victim networks, the FBI said.
The latest operation has rendered the tools inoperable in what FBI and Justice Department officials said was a blow to the hacking operation.
“We aim to remove the capability from the threat actors. We target their infrastructure, their money, and their tools,” FBI Cyber Division Deputy Assistant Director Jason Bilnoski said in an interview with The Associated Press, calling the hacking operation “indiscriminate and reckless.”
The tools were operated by a Chinese-based information security company called Integrity Technology Group, which the FBI says has contracts with the Chinese government. The company is regarded by the FBI as the true identity of Flax Typhoon.
In September 2024, the FBI announced that it had disrupted a massive botnet associated with Flax Typhoon that installed malicious software on more than 200,000 consumer devices, including cameras, video recorders and home and office routers, to create a massive botnet. The botnet, or network of infected computers, was used to facilitate cyber crimes, such as the theft of sensitive information from victims’ networks.
FBI San Diego Supervisory Special Agent Brett Lally said that the department would continue to monitor for ways that the company might rebuild its infrastructure.
“It’ll be interesting to see what this round of disruption actions have in terms of their ability to operate as a company in China,” Lally said.
____
Tucker reported from Washington.