The FBI has dismantled a suite of cyber tools used by a hacking operation that U.S. officials attribute to the Chinese government, marking the latest move in an ongoing campaign to disrupt state-sponsored cyber espionage. The operation, disclosed Thursday by the FBI and the Justice Department, targeted a group known in the private sector as Flax Typhoon, which has been linked to a Chinese information security firm with government contracts.
The seized tools, named "Microscan" and "FishHub," were employed to scan, phish, and breach networks belonging to U.S. and international critical infrastructure, including an unnamed American power company, airports in Japan and Poland, Taiwanese universities, and a multinational NGO. According to the FBI, Microscan was used for network reconnaissance, while FishHub facilitated phishing campaigns that granted hackers remote access to victim systems.
FBI Cyber Division Deputy Assistant Director Jason Bilnoski described the hacking operation as "indiscriminate and reckless," emphasizing that the seizure renders the tools inoperable. "We aim to remove the capability from the threat actors. We target their infrastructure, their money, and their tools," Bilnoski told the Associated Press.
The FBI identifies the Chinese-based Integrity Technology Group as the operator behind Flax Typhoon, a company that U.S. officials say maintains contracts with the Chinese government. This connection underscores the state-backed nature of the cyber campaign, which has targeted sectors ranging from energy to academia.
In Beijing, Chinese foreign ministry spokesperson Mao Ning defended China's record on cybersecurity, stating that Beijing "has always cracked down on hacking activities in accordance with the law." Mao also accused Washington of "double standards and political manipulation" and called for "equal dialogue and consultation" to address cybersecurity risks. The exchange highlights the ongoing tensions between the two nations over cyber issues.
The seizure follows a September 2024 FBI operation that disrupted a massive botnet attributed to Flax Typhoon, which had infected over 200,000 consumer devices—including cameras, routers, and video recorders—to steal sensitive information. That botnet was used to facilitate a range of cybercrimes, including data theft from victim networks.
FBI San Diego Supervisory Special Agent Brett Lally said the agency will continue monitoring for attempts by Integrity Technology Group to rebuild its infrastructure. "It'll be interesting to see what this round of disruption actions have in terms of their ability to operate as a company in China," Lally said.
This latest action is part of a broader U.S. strategy to impose costs on state-sponsored hacking groups, a tactic that has gained traction amid rising concerns over cyberattacks on public institutions. The FBI's move also comes as Pentagon operations expand globally, reflecting a heightened focus on national security threats. The seizure of these tools is a significant blow to a group that has repeatedly targeted critical infrastructure, though experts caution that such groups often adapt and rebuild.
