
FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions
The FBI and Department of Justice have seized seven domains and disrupted malicious tools used by China-linked threat group Flax Typhoon to scan and infiltrate U.S. critical infrastructure.
The U.S. Federal Bureau of Investigation (FBI) and the Department of Justice (DoJ) have announced the seizure of seven domains and the disruption of malicious tools used by Flax Typhoon, a China-linked advanced persistent threat group, to scan and in some cases infiltrate U.S. critical infrastructure.
Seized Domains
The seized domains are c0cc[.]cc, 98aiblog[.]com, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com and linkedinns[.]net. Flax Typhoon, also tracked as Ethereal Panda and RedJuliett, is associated with Integrity Technology Group, a Beijing-based company that contracts with the Chinese government. The group was previously linked to Raptor Train, a botnet of compromised SOHO and IoT devices taken down in a court-authorized operation in September 2024.
Botnet Infrastructure
Court documents allege that Integrity Tech created and operated an IoT botnet using a variant of the Mirai malware. The botnet used domains, including subdomains of w8510[.]com, for command-and-control and was managed through an application named Sparrow. A database server at 202.182.109[.]151 contained records for more than 1.2 million infected devices as of June 5, 2024, including over 385,000 unique U.S. victim devices. More than 260,000 devices, about 126,000 of them U.S. devices, were actively infected.
Scanning and Intrusion Tools
The group used a Python-based web tool called Microscan for reconnaissance and vulnerability scanning. Hosted at 198.13.53[.]226 and reachable via c0cc[.]cc as recently as September 9, 2026, the tool is believed to have been in use as early as 2017 and features over 1,300 penetration testing scripts targeting vulnerabilities in products such as OpenSSL, Oracle WebLogic, WordPress, Jenkins and Apache Struts. A second tool, FishHub, allegedly enabled exploitation through spear-phishing and follow-on payloads, with confirmed victims including 20 Taiwanese universities.
Other targets included a U.S. power company based in South Carolina, a multi-national non-governmental organization, Japanese and Polish airports, Taiwanese critical infrastructure companies in the natural gas and power sectors, and two Taiwanese universities.
International Response
A joint advisory from cybersecurity and intelligence agencies of the U.S., the U.K., Australia, Canada, Japan, New Zealand and Spain called out the company for enabling malicious cyber actors worldwide. Since at least mid-January 2021, the threat actors have used Python- and Go-based command line utilities and cross-site scripting attacks to harvest credentials, installed SoftEther VPN clients for persistence, and used the open-source Python brute-force tool EBurst against Microsoft 365 accounts, accessing mailbox data via a command-line utility known as office-cli.
The U.K. National Cyber Security Centre said malicious actors enabled by Integrity Tech are uniquely using AI tools such as automated scanning alongside large-scale botnets and manual exploitation techniques to steal confidential data, including from critical sectors.
The State Department has offered rewards of up to $10 million for information leading to the identification of Zhang Yu, a Chinese national charged in the 2021 Microsoft Exchange Server attacks, tracked as Silk Typhoon and formerly known as Hafnium. In April 2026, co-defendant Xu Zewei was extradited from Italy to face charges of stealing COVID-19 research from U.S. universities, immunologists and virologists.
Sources: The Hacker News
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.