Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers

(FIle Photo of the Federal Bureau of Investigation (FBI) Logo)

Noah haswell, Beaver County Radio News

(Washington, D.C.) The Justice Department and FBI announced yesterday court-authorized seizures, which included seven domains, to deny access to “Microscan” and “FishHub.”

These are two intrusion tools that are used by malicious cyber actors to scan and, in some cases, hack U.S. and foreign critical infrastructure systems and other networks.  

As alleged in court documents that were unsealed in the Western District of Pennsylvania, cyber actors who were working for Integrity Technology Group (Integrity Tech), which is a company based in the People’s Republic of China (PRC), operated and used the tools as part of their hacking activity known to the private sector as “Flax Typhoon.”  

Integrity Tech has contracts with the PRC government. 

According to court documents, Integrity Tech created and used a network of internet-
connected devices infected with a variant of Mirai malware.

This botnet employed the Microscan tool to conduct reconnaissance among other things, via the botnet and otherwise, of victim computer networks for vulnerabilities that its clients would later exploit.

Integrity Tech was able to access Microscan through one of the domains that was seized.

The targets of Microscan vulnerability scanning included a U.S. power company that is based in South Carolina, a multi-national Non-Governmental Organization, airports in Japan and Poland, Taiwanese critical infrastructure companies that are in the natural
gas and power sectors, and two universities in Taiwan.

FishHub is alleged to have facilitated the exploitation of computer networks through spear phishing.

FishHub downloaded additional malware to the victim network after an initial network compromise.

This malware, which was delivered through five of the domains that were seized, provided clients of Integrity Tech with unauthorized remote access to the
victim network or searched for specific files and sent them to servers that were controlled by Integrity Tech.

The confirmed victims of FishHub activity included approximately 20 universities in Taiwan.

Integrity Tech also used an unauthorized remote administration software that was tied to a seventh seized domain to connect several victims’ networks to a server from Integrity Tech.