US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide
The FBI announced that it has seized seven web domains linked to hacking tools allegedly operated by a Chinese security firm called Integrity Technology Group and used by Beijing-backed cyber operatives to scan a South Carolina power company's network and other critical infrastructure systems for vulnerabilities.
In a subsequent advisory, the FBI and other government agencies in the US, UK, Australia, Canada, Japan, New Zealand, and Spain warned that Chinese government-linked attackers, enabled by Integrity Tech, are using botnets, malware, and other intrusion tools to target organizations worldwide and steal sensitive data, including from US critical infrastructure networks.
“These actors exploit vulnerabilities by using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while establishing persistence through VPN software and exfiltrating emails and credentials using scripts,” according to the security alert.
Based on this activity, the US Cybersecurity and Infrastructure Security Agency (CISA) has added five CVEs to its Known Exploited Vulnerabilities Catalog: CVE-2015-3306 CVE-2015-5477 CVE-2016-3081 CVE-2021-3199 CVE-2023-22894 The court-authorized seizures are the latest in a long series of US law-enforcement attempts to disrupt a Beijing-backed cybercrew called Flax Typhoon and shut down its botnet.
From 2021 until its disruption, Flax Typhoon allegedly used a version of this Mirai-based botnet to infect internet-connected devices with malware, scan networks for vulnerabilities, and launch additional cyberattacks, all while hiding the PRC government hackers’ true IP addresses and physical location.
The feds allege Integrity Tech developed the botnet and a vulnerability scanner called Microscan, and operated a post-compromise tool called FishHub.
The latter allegedly downloaded additional malware to the phishing victims’ networks and stole sensitive data.
Court documents, unsealed on Thursday, allege Integrity Tech has contracts with the PRC government, and the feds have long linked Flax Typhoon to the private firm.
“Flax Typhoon actors conducted successful computer intrusions against multiple victim entities which had been scanned using the Microscan tool,” according to the court documents.
Victims include a university in Hsinchu, Taiwan, that Flax Typhoon compromised in March 2023, and a second university in Puli Township, Taiwan breached in August 2022.
“On or about April 26, 2022, and on or about December 29, 2022, Flax Typhoon actors also used the Microscan tool to scan for vulnerabilities on the networks of a U.S.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.