THE FBI and Department of Justice announced the disruption of a China-linked threat group activity known as Flax Typhoon, which used a set of compromised domains to scan and, in some cases, intrude into U.S. critical infrastructure. Seven domains were seized, including c0cc[.]cc, 98aiblog[.]com, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net. Flax Typhoon—also tracked as Ethereal Panda and RedJuliett—has been tied to Integrity Technology Group in Beijing.
Court filings describe the group as operating an IoT botnet, employing a Mirai-like variant, with command-and-control communications facilitated by subdomains hosted on domains such as w8510[.]com and other infrastructure, and managed via an application named Sparrow.
Evidence cited by the DoJ and FBI describes a database server hosting records for more than 1.2 million infected devices (as of 5 June 2024), including over 385,000 unique U.S. victims, with more than 260,000 devices actively infected at that time (about 126,000 in the U.S.).
The operation reportedly relied on Microscan, a Python-based web tool enabling vulnerability scanning across OpenSSL, Oracle WebLogic, WordPress, Juniper ScreenOS, Jenkins, Apache Struts and related components, and on FishHub for spear-phishing and follow-on payload deployment. Targeted organisations included a U.S. power company in South Carolina, a multinational NGO, airports in Japan and Poland, Taiwanese natural gas and power firms, and two Taiwanese universities.
The DoJ described Integrity Tech as providing tools for broad vulnerability scanning and intrusions, with U.S. and international partners coordinating to curb the actors’ access to networks and data.