US seizes seven domains linked to China-based hacking group

scanx
Reviewed by
Anirudha BScanX News Team
Key Highlights
  • US DOJ and FBI seized seven domains linked to Integrity Technology Group
  • Tools Microscan and FishHub targeted power grids, airports, and universities
  • Approximately 20 Taiwanese universities confirmed as victims of FishHub activity
  • This is the second public disruption of the group's infrastructure since September 2024
powered bylight_fuzz_icon
53087482

*this image is generated using AI for illustrative purposes only.

The US Department of Justice and FBI seized seven internet domains on Thursday, targeting infrastructure allegedly operated by China-linked cyber actors. The action disrupts tools used to scan networks and compromise critical systems, including power companies, airports, and universities.

Targets include power grids and airports

Court documents unsealed in the Western District of Pennsylvania identify the operators as employees of Integrity Technology Group, a China-based firm with contracts with the Chinese government. The seized domains supported two primary hacking tools: Microscan and FishHub.

Microscan was designed to identify network vulnerabilities for later exploitation. Authorities listed confirmed targets including:

  • A South Carolina-based power company
  • Airports in Japan and Poland
  • Natural gas and power companies in Taiwan
  • Two Taiwanese universities
  • A multinational non-governmental organization

FishHub facilitated spear phishing attacks, allowing attackers to download malware for remote access or data exfiltration. Approximately 20 Taiwanese universities were identified as confirmed victims of FishHub activity.

Part of broader disruption efforts

This operation marks the second public technical disruption of Integrity Technology Group’s infrastructure by US authorities. In September 2024, agencies dismantled a botnet involving more than 200,000 consumer devices infected with Mirai malware. The latest seizure follows an August action against QTFY, another China-linked platform that concealed attack origins.

Separately, researchers reported an August incident where suspected China-linked hackers used artificial intelligence agents to target Taiwanese government systems, compromising at least 85 accounts and stealing over 2,500 personnel records.

The FBI’s San Diego and Baltimore field offices are investigating the case alongside the agency’s Cyber Division. A cybersecurity advisory containing indicators for network defenders has been released by the FBI and international partners.

Disclaimer: This article is AI-generated using data from ViewTrade. ScanX is not liable for any inaccuracies.

How might Beijing retaliate against US cyber infrastructure or economic interests in response to these domain seizures?

Will the identified vulnerabilities in power grids and airports prompt immediate regulatory mandates for enhanced network segmentation?

What impact will the use of AI agents in recent attacks have on the speed and sophistication of future state-sponsored espionage?

like16
dislike