Trusence Every claim has a source
Last updated 9 October 2026 Search Türkçe
← All stories
Security

FBI seizes seven domains used by Flax Typhoon hacking tools

The seizure cuts off infrastructure used to scan and break into targets, while a joint advisory gives defenders indicators and steps to check for compromise.

The FBI seized seven domains tied to Chinese hacking infrastructure used by the Flax Typhoon cluster to run MicroScan and FishHub, tools that helped scan for weaknesses, break into networks, and steal data from critical infrastructure and other targets. U.S. authorities say the infrastructure was linked to China-based Integrity Technology Group, but they describe that link as alleged and say some of the activity overlaps with what they track as Flax Typhoon, Ethereal Panda, and Red Juliett. In parallel, the FBI, CISA, NSA, and foreign partners issued guidance with indicators of compromise and defensive steps for organizations that may have been targeted. The advisory says the operators hit sectors including U.S. government, manufacturing, healthcare, IT, law enforcement, education, and religious organizations, and that MicroScan included more than 1,300 scripts aimed at products such as Oracle WebLogic, Apache Struts, WordPress, and Jenkins.

Why it matters

The takedown removes part of the setup used to reach critical infrastructure and other organizations, but the advisory shows the campaign reached across multiple sectors and regions. For defenders, the immediate change is practical: they now have indicators of compromise and guidance to look for signs of intrusion and tighten response around the software the tools targeted.

Sources

  • BleepingComputer