FBI Seizes Domains Used by China-Linked Hackers to Target Critical Infrastructure

· Original article ↗

Summary

The FBI seized seven domains tied to Flax Typhoon tools MicroScan and FishHub, which authorities say were used to scan for vulnerabilities, breach organizations, steal data, and maintain access to victim networks.

Key points

  • The FBI seized seven domains linked to MicroScan and FishHub, platforms allegedly operated by China-based Integrity Technology Group for Flax Typhoon.
  • MicroScan used Mirai-infected devices to scan for vulnerabilities; investigators say scans led to breaches, including at two Taiwanese universities.
  • FishHub supported spear-phishing, malware delivery, remote access, file searches, and data theft; investigators found files from more than 20 organizations on a linked server.
  • Authorities say the activity targeted critical infrastructure and organizations across sectors and multiple regions; they did not confirm that every named target was breached.
  • The FBI, CISA, NSA, and international partners issued an advisory with indicators of compromise and details of attacker tools and activity.
  • Authorities urge organizations to review the indicators, patch vulnerable systems, disable unnecessary exposed services, and enforce multifactor authentication.

Article Details

Event Type
Law-enforcement seizure of hacking infrastructure
Impact
The FBI seized seven domains supporting vulnerability scanning, malware delivery, and persistent remote access. Investigators confirmed breaches of two Taiwanese universities following scans and found data belonging to more than 20 organizations, including six universities in Taiwan, on a server linked to the data-theft platform. Authorities confirmed intrusions involving critical infrastructure but did not disclose whether the specifically mentioned power companies, airports, and energy providers were successfully breached.

Indicators of compromise

TypeIndicatorContext
DOMAIN98aiblog[.]comSeized domain tied to SoftEther VPN installed on compromised systems to maintain remote access.
DOMAIN98aicai[.]comSeized domain used to deliver malware associated with FishHub.
DOMAIN98aicode[.]comSeized domain used to deliver malware associated with FishHub.
DOMAINc0cc[.]ccSeized domain used by Integrity Tech to access the MicroScan vulnerability-scanning platform.
DOMAINlinkedinns[.]netSeized domain used to deliver malware associated with FishHub.
DOMAINoutlook3650[.]comSeized domain used to deliver malware associated with FishHub.
DOMAINyoutubecard[.]comSeized domain used to deliver malware associated with FishHub.

MITRE ATT&CK

CVE

People

Threat Actors

Malware

Products

Active Directoryattacks against Microsoft Exchange servers, along with other tools to steal emails, collect Active Directory credentials, and exfiltrate data.Apache StrutsThese scripts targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, Jenkins, and other applications.GitLabCVE-2021-22205: GitLab remote code execution vulnerability.GNU BashCVE-2014-6278: GNU Bash (Shellshock) remote code execution vulnerability.ISC BINDCVE-2015-5477: ISC BIND denial-of-service vulnerability.JenkinsThese scripts targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, Jenkins, and other applications.Microsoft Exchange ServerThe attackers also used the open-source EBurst tool to conduct password-spraying attacks against Microsoft Exchange servers, along with other tools to steal emails, collect Active Directory credentials, and exfiltrateONLYOFFICE DocumentServerCVE-2021-3199: ONLYOFFICE DocumentServer unauthorized file write vulnerability.Oracle WebLogicThese scripts targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, Jenkins, and other applications.ProFTPDCVE-2015-3306: ProFTPD unauthorized file read vulnerability.Pulse Secure VPNCVE-2019-11510: Pulse Secure VPN arbitrary file read vulnerability.SoftEther VPNA seventh seized domain, 98aiblog.com, was tied to the SoftEther VPN software installed on compromised systems to maintain remote access to victim networks.StrapiCVE-2023-22894: Strapi information disclosure vulnerability.WordPressThese scripts targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, Jenkins, and other applications.

Tools

Countries

Industries

Related Articles