HomeSecurityFBI seizes seven domain names used by Integrity Tech

FBI seizes seven domain names used by Integrity Tech

The US Department of Justice and the FBI announced the seizure of seven web addresses, with court approval, to disrupt access to tools attributed to the Chinese company Integrity Technology Group (Integrity Tech). US authorities are linking the activity to the Flax Typhoon, as described in documents unsealed in Pennsylvania.

Integrity Tech and network scanning

The addresses supported two platforms, MicroScan for vulnerability scanning and FishHub for phishing attacks. According to the US Department of Justice, the goal of the legal action was to deprive their operators of access to the tools and related infrastructure.

The statement says one address allowed access to MicroScan, five were used to distribute additional malware, and the seventh was linked to remote administration software. Authorities do not name the software, but say it connected victims' networks to a company server.

Integrity Tech and its tools

The court documents, as described by the department, state that agents working for Integrity Tech operated and used the tools. The company is based in China and, according to the statement, has contracts with the Chinese government. These are allegations by US authorities, not an independent judicial review of the case. Washington classifies the activity as part of the Flax Typhoon campaign.

MicroScan was used to scan networks and find vulnerabilities that could be exploited later. The researchers connected it to a network of IoT devices infected with a variant of Mirai. According to court documents, the botnet facilitated the tool's scans.

See also: Microsoft: Flax Typhoon team uses LOLBins to evade detection

FishHub and electronic fishing

FishHub, according to the documents, facilitated the compromise of networks through targeted phishing emails. After initial access, the tool could deliver additional malware, giving operators the ability to remotely access or search for and copy specific files.

The goals and what has been confirmed

Authorities said MicroScan's scans targeted, among others, a power company in South Carolina, airports in Japan and Poland, and energy companies and universities in Taiwan. The mention of a target does not automatically mean that every organization was successfully compromised.

According to BleepingComputer 's review of the affidavit , two universities in Taiwan were breached after a previous scan. On a separate server connected to FishHub, researchers found files and data from more than 20 organizations, without publicly attributing each incident to a specific means of entry.

In addition to the seizures, the FBI, CISA, NSA and agencies from other countries issued a joint technical alert about the activities of Integrity Technology Group. The agencies describe broader activity that includes large-scale networks of infected devices, VPN infrastructure and vulnerability exploitation tools. However, they clarify that not all of the related activity is necessarily linked to the same company.

The warning is based on technical evidence from multiple FBI investigations and covers targets in sectors including government, manufacturing, healthcare and IT. The authors urge network administrators to look for signs of a potential breach and use the technical data to strengthen their defenses.

What seizure means for organizations

The seizure of addresses is intended to disrupt operators’ access to the platforms; it does not in itself prove that all infrastructure has been eliminated or that alternative means will not be deployed. In 2024, US authorities announced a separate operation against a Mirai network linked to the same company that involved more than 200,000 devices. The Justice Department is calling today’s action the second public technical disruption of Integrity Tech’s infrastructure.

Critical infrastructure network defense

CISA urges security leaders to look for signs of a potential breach and leverage the technical elements of the alert to protect their networks. Organizations managing critical services can review the relevant findings and follow the guidance of the relevant national authorities.

See also: US says Chinese botnet compromises 260,000 SOHO devices

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The FBI and the Justice Department are presenting the operation as a new blow to the infrastructure they claim Integrity Tech was using. For the defenders, the practical question is to determine whether there has been activity on their own network, without confusing the scans with confirmed breaches.

See also: UK: Chinese hackers use proxy networks to avoid detection

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS