US authorities have disrupted two hacking platforms linked to a Chinese state-sponsored cyber espionage operation that targeted power companies, airports, universities and other critical infrastructure around the world. The operation involved seizing seven internet domains and cutting off access to tools used to identify vulnerable networks and launch attacks.
The FBI and Department of Justice announced the action on October 8, identifying the hacking group as Flax Typhoon. Investigators linked the operation to Integrity Technology Group, a Chinese cybersecurity company that has contracts with the Chinese government.
According to US officials, the company operated two platforms known as Microscan and FishHub. These tools allowed attackers to search for security weaknesses, gain unauthorized access to computer systems, and collect sensitive information.
Microscan was designed to scan websites and networks for vulnerabilities that hackers could exploit. Investigators found that it contained more than 1,300 scripts capable of checking for weaknesses in widely used software and network equipment.
FishHub supported more targeted attacks, including phishing campaigns that tricked victims into opening malicious files or providing access to their systems. Once attackers gained entry, additional malware could allow them to search for documents and transfer stolen information to external servers.
The tools were used against organizations in several countries. Identified targets included a South Carolina power company, airports in Japan and Poland, Taiwanese energy companies and universities, and an international nonprofit organization.
Authorities confirmed that some operations resulted in successful network intrusions. Among the documented victims were Taiwanese universities whose systems were compromised after being targeted by the group’s scanning activities.
Flax Typhoon has been under investigation for years. In September 2024, US authorities disrupted a botnet associated with the same group that had infected more than 200,000 internet-connected devices, including home routers and security cameras.
The latest operation represents another attempt to dismantle the infrastructure supporting the group’s cyberattacks. By seizing the domains used by Microscan and FishHub, investigators prevented the operators from continuing to access those platforms through their existing infrastructure.
US officials believe Chinese government contractors play an important role in supporting cyber espionage operations by developing tools and identifying potential targets. China has repeatedly denied allegations of involvement in state-sponsored hacking.
Alongside the seizures, US and international cybersecurity agencies published guidance to help organizations identify signs of compromise associated with Integrity Technology Group. The disruption limits access to the identified tools, although it does not establish that the broader hacking operation has ended.