The FBI has taken down infrastructure used by a hacking group tied to the Chinese government, seizing scanning and phishing tools that officials say were deployed in disruptive cyber operations against U.S. and international targets, including power grids, universities, and critical infrastructure.

Announced Thursday by the FBI and the Justice Department, the action is the latest in a series of law enforcement moves against the group, known in the private sector as Flax Typhoon. The seized tools—dubbed “Microscan” and “FishHub”—were used to scan for vulnerabilities, conduct phishing, and gain remote access to victim networks, according to officials.

Read also
Technology
FBI seizes hacking tools tied to Chinese state-linked group
The FBI announced the seizure of cyber tools used by a Chinese state-linked hacking group, disrupting operations against critical infrastructure in the U.S. and abroad.

Microscan was used to target a U.S. power company, airports in Japan and Poland, Taiwanese universities, a multinational NGO, and Taiwanese critical infrastructure firms. FishHub facilitated phishing campaigns that allowed hackers to infiltrate networks, the FBI said. The operation has rendered both tools inoperable, dealing what officials described as a significant blow to the group's capabilities.

“We aim to remove the capability from the threat actors. We target their infrastructure, their money, and their tools,” said Jason Bilnoski, deputy assistant director of the FBI's Cyber Division, in an interview with the Associated Press. He characterized the hacking operation as “indiscriminate and reckless.”

The tools were operated by Integrity Technology Group, a Chinese-based information security company with contracts with the Chinese government, which the FBI identifies as the true identity of Flax Typhoon. In Beijing, foreign ministry spokesperson Mao Ning said China has always cracked down on hacking in accordance with the law, and accused the U.S. of spreading disinformation for political purposes. “We urge the U.S. to abandon its double standards and political manipulation, and work with China through equal dialogue and consultation to jointly address cybersecurity risks,” she said.

This seizure follows a September 2024 FBI operation that disrupted a massive botnet linked to Flax Typhoon, which had infected more than 200,000 consumer devices—including cameras, video recorders, and routers—to facilitate cyber crimes such as stealing sensitive information. The latest action is part of a broader U.S. effort to counter state-sponsored hacking, which has also included exposing vulnerabilities in public institutions and scrutinizing tech companies' security practices.

FBI San Diego Supervisory Special Agent Brett Lally said the department will continue to monitor for any attempts by the company to rebuild its infrastructure. “It’ll be interesting to see what this round of disruption actions have in terms of their ability to operate as a company in China,” Lally said.

The seizure underscores ongoing tensions between Washington and Beijing over cyber espionage, with the U.S. increasingly using legal and technical measures to dismantle hacking operations. The move also highlights the growing threat to critical infrastructure and the need for robust cybersecurity defenses.