Protect.Computer
NEWS

FBI Seizes Flax Typhoon's MicroScan and FishHub Hacking Tools

· 2 min read · Got hacked Network safety
FBI Seizes Flax Typhoon's MicroScan and FishHub Hacking Tools

The U.S. Department of Justice and FBI announced court-authorized seizures of seven domains used to run two hacking tools, MicroScan and FishHub, which US authorities say were operated by China-based Integrity Technology Group (Integrity Tech) and used by the China-linked Flax Typhoon actors. Court documents unsealed in the Western District of Pennsylvania say the company has contracts with the Chinese government. The seized domains now show FBI seizure notices.

MicroScan is a Python-based vulnerability scanner with more than 1,300 penetration-testing scripts aimed at software such as Oracle WebLogic, Apache Struts, WordPress and Jenkins. According to the FBI seizure affidavit, it was used together with a botnet of Mirai-infected devices to scan targets including a South Carolina power company, airports in Japan and Poland, Taiwanese gas and electricity companies and universities. Two Taiwanese universities scanned in August 2022 and March 2023 were later breached. FishHub was used for spear-phishing and to deliver malware that gave attackers remote access and let them search for files and exfiltrate data. The FBI found data from more than 20 organizations, including six Taiwanese universities, on a server linked to FishHub, plus a custom web application that let third parties browse stolen emails without access to the compromised accounts.

The FBI, CISA, NSA and international partners published a joint advisory with indicators of compromise. It says targets included US government agencies, critical manufacturing, healthcare, IT, law enforcement, education and religious organizations, and that the activity overlaps with groups tracked as Flax Typhoon, Ethereal Panda and Red Juliett, though not all of it is necessarily tied to Integrity Tech. Per BleepingComputer, the Justice Department disrupted an Integrity Tech-operated Mirai botnet of more than 200,000 devices in September 2024, and the UK and EU have sanctioned the company.

How to check if you’re affected

Affected products are mostly older, unpatched internet-facing software that MicroScan probes. The advisory names eight commonly targeted CVEs: CVE-2015-3306 (ProFTPD), CVE-2015-5477 (ISC BIND), CVE-2016-3081 (Apache Struts), CVE-2021-3199 (ONLYOFFICE DocumentServer), CVE-2023-22894 (Strapi), CVE-2014-6278 (GNU Bash/Shellshock), CVE-2019-11510 (Pulse Secure VPN) and CVE-2021-22205 (GitLab). Check any server you run for versions that still carry these flaws and patch them.

Also search your logs and DNS records for the seized domains, which were 98aicai.com, 98aicode.com, 98aiblog.com, outlook3650.com, youtubecard.com, linkedinns.net and c0cc.cc, and compare them with the full indicator list in the advisory. The advisory also urges disabling unnecessary exposed services and enforcing multifactor authentication, and the attackers used the open-source EBurst tool for password spraying against Microsoft Exchange servers.

Sources

Related reading