Flax Typhoon: Integrity Tech hacking tools seized

Flax Typhoon: Integrity Tech hacking tools seized

Cybersecurity and law enforcement agencies from several countries have taken down tools that Chinese state-backed hackers used against critical infrastructure organizations. The operation focused on Integrity Tech, a Beijing-based cybersecurity company that the People's Republic of China's (PRC) Ministry of State Security hired to help attack universities, government agencies, telecommunications providers and media organizations around the world.

The US Justice Department seized several websites that supported two hacking tools, "Microscan" and "FishHub." US officials also released a 58-page advisory on these and other tools that Chinese actors have used over the past six years in the long-running Flax Typhoon campaign.

"Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure," said FBI Assistant Director Brett Leatherman. "The PRC relies on contractors and enabling companies to expand the reach and scale of its malicious cyber activity."

Two tools at the center of the takedown

According to court documents and the advisories, Integrity Tech built Microscan to find vulnerabilities that Chinese hackers could later exploit. The tool has been in use since 2017 and runs penetration testing scripts that scan websites for specific flaws. Its victims include a South Carolina power company, airports in Japan and Poland, and Taiwanese critical infrastructure companies in the natural gas and power sectors.

FishHub was designed to speed up phishing attacks. Once a network had been breached, it let attackers download malware onto the victim's systems. Authorities said the remote access it provided was used against about 20 universities in Taiwan.

The company combines automated scanning tools, botnets and hands-on-keyboard techniques to steal sensitive data.

Edge devices and email accounts

The advisory came out of multiple FBI incident response investigations into organizations attacked by Integrity Tech or by other Chinese groups using its tools. The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) said the company usually went after edge devices that are poorly monitored, since these gave the hackers long-term, hidden access.

Chris Butera, CISA's acting executive assistant director for cybersecurity, said Chinese government hackers "continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing."

Integrity Tech also acquires, sells or hosts tools used by several groups. One of them, EBurst, targets Microsoft Exchange email accounts through password spraying and password guessing across multiple interfaces. Others are built to access emails, calendars and contacts.

"The FBI recovered an archived email database the threat actors used to target email accounts of victim organizations," the agencies said. Victims of email data theft included government organizations, law enforcement agencies, healthcare systems and religious institutions in Southeast Asia. In some cases, access to the stolen data was limited to IP addresses from Xiamen, China.

Australia, Japan, the UK, Spain, New Zealand and Canada contributed to the advisory. Paul Chichester, director of operations at the UK's National Cyber Security Centre, said the "breadth of sectors that have been targeted across the globe demonstrate the extent of the threat."

A familiar target

US agencies have gone after Integrity Tech with sanctions and takedowns repeatedly over the last three years. Microsoft researchers first publicly identified Flax Typhoon in 2023. In September 2024, the DOJ disrupted the company's Mirai-based botnet of more than 260,000 consumer devices, using a court authorization to remove malware from infected devices and take control of the group's infrastructure.

At home, Integrity Tech is best known for building China's cyber ranges, training platforms that simulate real-world networks and systems. Researchers from the Natto Thoughts team said it was founded in 2010 by Cai Jingjing, a well-known Chinese hacker.

Our Take

This action fits a pattern of Western governments targeting the private contractors behind Chinese state hacking rather than just the operators, much like the recent reward offered for Hafnium hacker Zhang Yu. Seizing websites is a disruption, not an end point: Integrity Tech has survived sanctions and a botnet takedown before, which suggests these tools may be rebuilt or replaced.

For defenders, the advisory's focus on poorly monitored edge devices and on-premise Exchange servers is the practical takeaway. Organizations should check those systems against the published indicators. The warning about OT systems also adds weight to calls for stronger OT security rules. It is worth watching whether further indictments or sanctions against named individuals follow.