Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Popular AI leaderboard Arena nearly doubles valuation to $3.1B valuation in 10 months

    October 9, 2026

    Microsoft: Outdated Windows devices will stop receiving security updates

    October 9, 2026

    France Proposes Stablecoin Swap Tax and Crypto Exit Tax

    October 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Popular AI leaderboard Arena nearly doubles valuation to $3.1B valuation in 10 months
    • Microsoft: Outdated Windows devices will stop receiving security updates
    • France Proposes Stablecoin Swap Tax and Crypto Exit Tax
    • Maricopa County’s Housing Hub Is a Dead End for Homeless Families — ProPublica
    • Why vote count spikes are a normal part of elections
    • Three Saudis killed in Riyadh airport attack claimed by Houthis | Saudi Arabia
    • Thieves in Italy steal 30,000 wine bottles worth €5m, reports say
    • Fired OpenAI researchers say they were let go for ‘prioritising safety’
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 9, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon.

    To that end, the agencies seized several domains and blocked access to platforms that were used to scan, and in some cases infiltrate, U.S. critical infrastructure. The list of seized domains is as follows –

    • c0cc[.]cc
    • 98aiblog[.]com
    • 98aicai[.]com
    • 98aicode[.]com
    • outlook3650[.]com
    • youtubecard[.]com
    • linkedinns[.]net

    Flax Typhoon, also tracked as Ethereal Panda and RedJuliett, is associated with Integrity Technology Group, a Beijing-based company that contracts with the Chinese government. It was previously attributed to a botnet called Raptor Train that comprised thousands of compromised small office/home office (SOHO) and IoT devices. It was taken down following a U.S. court-authorized operation in September 2024.

    “These state-sponsored hackers continue to aggressively target and access networks and systems throughout the world in an effort to identify and steal files and otherwise exploit victims’ vulnerabilities,” said U.S. Attorney Troy Rivetti for the Western District of Pennsylvania.

    Cybersecurity

    Court documents allege that Integrity Tech created and operated an IoT botnet that leveraged a variant of the Mirai malware. According to the FBI, the botnet is said to have used a number of domains, including subdomains of w8510[.]com, for command-and-control (C2), enabling bidirectional communications between the operators and devices in the botnet. The botnet itself was controlled and managed by an application named Sparrow.

    A database server hosted on the server (“202.182.109[.]151”) contained records for more than 1.2 million infected devices as of June 5, 2024, including over 385,000 unique U.S. victim devices. In all, more than 260,000 devices, including approximately 126,000 U.S. devices, were actively infected as of June 5, 2024.

    The botnet made use of a tool called Microscan to facilitate reconnaissance and computer vulnerability scanning, allowing the threat actors to identify targets of interest. The Python-based web tool, originally hosted on “198.13.53[.]226,” was accessible via the domain “c0cc[.]cc” as recently as September 9, 2026, according to an FBI affidavit. The tool is believed to have been put to use as early as 2017.

    MicroScan features over 1,300 penetration testing scripts to scan websites for specific vulnerabilities, including OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts. The scanner is complemented by open-source tooling like BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe, and wpscan that are used to find vulnerabilities in networks and web-based applications.

    Some of the targeted companies include a U.S. power company based in South Carolina, a multi-national Non-Governmental Organization, Japanese and Polish airports, Taiwanese critical infrastructure companies in the natural gas and power sectors, and two Taiwanese universities.

    A second Integrity Tech tool is FishHub, which allegedly enabled the exploitation of computer networks through spear-phishing attacks and the deployment of follow-on payloads. Confirmed victims of FishHub-related activity include 20 Taiwanese universities.

    “This malware provided Integrity Tech’s clients with unauthorized remote access to the victim network or searched for specific files and sent them to servers controlled by Integrity Tech,” the DoJ said.

    “Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division.

    “The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure.”

    In tandem, a joint advisory issued by cybersecurity and intelligence agencies from the U.S., the U.K., Australia, Canada, Japan, New Zealand, and Spain has called out the for-profit company for enabling malicious cyber actors to target organizations worldwide by acquiring or building cyber tools for use and sale and compromising networks.

    Cybersecurity

    Since at least mid-January 2021, the threat actors have been observed breaking into victim networks and cloud-based services using Python- and Go-based command line utilities, while also relying on cross-site scripting (XSS) attacks to conduct user credential harvesting.

    Besides installing SoftEther VPN software clients on victim devices for persistence, the threat actors have been found to use EBurst, an open-source Python-based brute-force tool, to target accounts in Microsoft 365 Cloud environments, and gain unauthorized access to mailbox data using a command-line utility known as office-cli.

    “Malicious cyber actors, enabled by Integrity Tech, are uniquely using AI tools, such as automated scanning, alongside large-scale botnets and manual exploitation techniques to compromise and steal confidential data from companies around the world, including critical sectors,” the U.K. National Cyber Security Centre (NCSC) said.

    The development comes as the U.S. State Department announced rewards of up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the U.S. in connection with the 2021 Microsoft Exchange Server attacks.

    The activity is tracked under the moniker Silk Typhoon (formerly Hafnium). In April 2026, co-defendant Xu Zewei was extradited to the U.S. from Italy to face charges related to allegedly stealing COVID-19 research from U.S.-based universities, immunologists, and virologists.

    critical Disrupts Domains FBI Flax infrastructure Intrusions Seizes Tools Typhoon
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft: Outdated Windows devices will stop receiving security updates

    Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security

    Citrix Urges Immediate Patching of Critical NetScaler Vulnerability

    Formula Predicts When AI Chatbots Are at Risk of Turning Bad

    UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

    Low-cost Android phones ship with residential proxy malware

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Popular AI leaderboard Arena nearly doubles valuation to $3.1B valuation in 10 months

    October 9, 2026

    Microsoft: Outdated Windows devices will stop receiving security updates

    October 9, 2026

    France Proposes Stablecoin Swap Tax and Crypto Exit Tax

    October 9, 2026

    Maricopa County’s Housing Hub Is a Dead End for Homeless Families — ProPublica

    October 9, 2026
    Latest Posts

    Wisconsin’s partisan primary election is Tuesday. Learn more about who’s on your ballot.

    August 10, 2026

    Gabon ends fisheries partnership agreement with EU

    August 10, 2026

    Science backs calls for limiting screens in schools

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Popular AI leaderboard Arena nearly doubles valuation to $3.1B valuation in 10 months

    October 9, 2026

    Microsoft: Outdated Windows devices will stop receiving security updates

    October 9, 2026

    France Proposes Stablecoin Swap Tax and Crypto Exit Tax

    October 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.