U.S. authorities, including the FBI and DOJ, seize infrastructure used by Chinese state-sponsored hackers known as Flax Typhoon and take control of two alleged malware tools, MicroScan and FishHub. According to the reports, the operation includes the seizure of seven domains associated with the group’s activity and is tied to intrusions that have targeted critical infrastructure as well as other organizations worldwide.
The announcements are accompanied by warnings from U.S. cyber agencies. CyberScoop and Bleeping Computer both describe coordinated messaging involving the FBI, along with the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA), outlining that the tools were used in attacks and that organizations should review defenses and detection capabilities. One outlet emphasizes the disruption through domain seizures, while the other focuses on the DOJ/FBI-led takedown of the named tools.
Across coverage, the alleged operator is linked to a Chinese firm called Integrity Tech, and the actions are framed as an effort to reduce ongoing access by the hacking group to affected environments.