Back to Newsroom
Threat Intel

FBI Seizes Domains Powering Flax Typhoon's Hacking Tools

U.S. authorities seized seven domains tied to a China-linked hacking operation, disrupting a vulnerability-scanning tool and a Mirai-based botnet that compromised more than a million devices worldwide.

FBI Seizes Domains Powering Flax Typhoon's Hacking Tools

What happened

The FBI and the Department of Justice have seized seven domains linked to Flax Typhoon, a state-sponsored hacking group connected to China, disrupting two of the group's core operational tools: a large-scale vulnerability scanner and a Mirai-based IoT botnet used for command-and-control.

Court documents tie the infrastructure to Integrity Technology Group, a Beijing-based contractor the U.S. government says works on behalf of Chinese state interests. Investigators allege the company built and ran an IoT botnet — previously tracked as "Raptor Train" and dismantled in a 2024 court-authorized operation — that at its peak controlled more than 260,000 actively infected devices, including over 126,000 in the United States, drawn from a pool of over 1.2 million victim machines logged on the botnet's database server.

Alongside the botnet, the seized domains hosted "MicroScan," a scanning platform investigators say has been in use since at least 2017. The tool reportedly bundles more than 1,300 scripts built on common open-source scanning frameworks to identify exploitable flaws in widely deployed software — OpenSSL, Oracle WebLogic, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts among them — and was reachable from one of the now-seized domains as recently as early September 2026.

A second tool attributed to the group, "FishHub," allegedly supported spear-phishing campaigns and follow-on malware delivery; the DOJ says confirmed victims of FishHub-linked activity include 20 Taiwanese universities.

Why it matters

The case illustrates a model authorities are increasingly worried about: state-linked actors outsourcing offensive infrastructure to "cyber proxy" firms that build, maintain, and sell scanning and access tools at scale. A joint advisory issued alongside the seizure — from cybersecurity and intelligence agencies across the US, UK, Australia, Canada, Japan, New Zealand, and Spain — specifically calls out this for-profit, contractor-enabled model as a way to expand the reach of state cyber activity while adding a layer of deniability.

Targets tied to the campaign reportedly span critical infrastructure and research: a U.S. power utility, a multinational NGO, airports in Japan and Poland, and natural gas and power operators in Taiwan, in addition to the universities named above. Investigators also describe the group relying on legitimate remote-access software (including SoftEther VPN clients) for persistence, Python-based brute-forcing against Microsoft 365 accounts, and cross-site scripting to harvest credentials — a reminder that sophisticated campaigns increasingly blend custom tooling with off-the-shelf and "living off the land" techniques.

What to do

  • Treat internet-facing IoT and SOHO devices (routers, VPN appliances, NAS devices) as a priority patching target — they remain the preferred entry point for botnet-building operations like this one.
  • Audit Microsoft 365 tenants for unusual mailbox access, forwarding rules, or sign-ins from unfamiliar locations, and enforce MFA with conditional access policies.
  • Monitor for unexpected SoftEther or similar VPN client installations on endpoints and servers — these are increasingly used by intrusion actors for low-noise persistence.
  • Keep scanning-prone software (WebLogic, Struts, Jenkins, ScreenOS, WordPress and its plugins) on a short patch cycle; tools like the one disrupted here are built specifically to catch stragglers.
  • If you operate infrastructure in the sectors named above (energy, transport, higher education, NGOs), review exposure against published seizure details and feed any related indicators into your detection stack.
SHARE