US Justice Dept Takes Action Against Chinese Hacking Group ‘Flax Typhoon’

The CSR Journal Magazine

The United States has undertaken significant measures against a Chinese hacking operation by seizing seven internet domains allegedly connected to this extensive cyber threat. On Thursday, the US Justice Department announced that hackers were exploiting these domains to scan and compromise critical infrastructure systems both in the US and globally. This operation has been traced to the Integrity Technology Group, a Chinese IT firm.

The Federal Bureau of Investigation (FBI) has established a direct link between the Integrity Technology Group and a well-known state-sponsored hacking collective named ‘Flax Typhoon’. Previous comments from former FBI Director Christopher Wray indicate that this tech company has been actively involved in intelligence gathering and reconnaissance for China’s security agencies.

Previous Efforts and Context

This seizure is not the first initiative to address the threats posed by this hacking group. The action taken on Thursday represents the second public step by the US government to dismantle the cyber infrastructure associated with Integrity Tech. In September 2024, the Justice Department successfully disrupted a substantial botnet connected to the same group, which had compromised more than 250,000 consumer devices worldwide.

The devices included common items such as home Wi-Fi routers and smart cameras, which were infected using Mirai malware to facilitate automated cyberattacks. To offer insights into the tactics employed by Flax Typhoon, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) shared a detailed advisory. They noted that the group relied on automated botnets and tools to conduct extensive searches for vulnerabilities within enterprise networks.

A common target for the hackers was Microsoft Exchange servers, where they frequently utilised password-guessing and malicious scripts to gain access. After breaching a network, the hackers deployed scripts designed to exfiltrate sensitive data, such as emails and user passwords. To maintain their stealth, they made extensive use of VPN software, allowing them to blend into the compromised network for prolonged periods.

Future Implications and Investigations

The seizure of these domains has effectively cut off crucial communication channels that the hackers used to manage their cyber operations. Currently, the FBI is conducting investigations into the broader network of these cyber threats, in coordination with international counterparts, including Japan’s National Police Agency. On Thursday evening, the Chinese Embassy in Washington did not respond to requests for comment.

However, the Chinese government routinely denies any involvement in state-sponsored hacking activities. For organisations and IT administrators seeking to enhance their cybersecurity, CISA has recommended several basic protective measures. Enforcing Multi-Factor Authentication (MFA) across all digital platforms and remote access points is crucial. Additionally, disabling any unused internet ports, automatic configurations, or file-sharing protocols is advisable to secure digital assets.

Lastly, applying the latest software security patches immediately can prevent hackers from injecting malicious code into systems. The ongoing situation underscores the importance of robust cybersecurity practices in an era where state-sponsored hacking remains a prevalent threat. The measures taken by the US government reflect a growing emphasis on protecting critical infrastructure from external cyber threats.

Long or Short, get news the way you like. No ads. No redirections. Download Newspin and Stay Alert, The CSR Journal Mobile app, for fast, crisp, clean updates!

App Store –  https://apps.apple.com/in/app/newspin/id6746449540 

Google Play Store – https://play.google.com/store/apps/details?id=com.inventifweb.newspin&pcampaignid=web_share

Latest News

Popular Videos