The FBI has seized tools used by Chinese hackers for cyber operations, officials say

LOS ANGELES (AP) — The FBI has seized scanning and phishing tools used by a group of hackers that officials say is associated with the Chinese government and is believed responsible for disruptive cyber operations in the United States and abroad, including against the power industry, academia and critical infrastructure.

The seizure of the tools, announced Thursday by the FBI and Justice Department, represents the latest law enforcement effort in recent years to go after a broad-based hacking campaign known to the private sector as Flax Typhoon.

The tools at issue, called “Microscan” and “FishHub,” were used by the hackers to scan, phish and hack targets that included U.S. and foreign critical infrastructure, officials said. Microscan was used to target, among other entities, an unnamed power company in the U.S., Japanese and Polish airports, Taiwanese universities, a multinational, nongovernmental organization and Taiwanese critical infrastructure companies. And “FishHub” facilitated phishing activity that gave hackers remote access to victim networks, the FBI said.

The latest operation has rendered the tools inoperable in what FBI and Justice Department officials said was a blow to the hacking operation.

“We aim to remove the capability from the threat actors. We target their infrastructure, their money, and their tools,” FBI Cyber Division Deputy Assistant Director Jason Bilnoski said in an interview with The Associated Press, calling the hacking operation “indiscriminate and reckless.”

The tools were operated by a Chinese-based information security company called Integrity Technology Group, which the FBI says has contracts with the Chinese government. The company is regarded by the FBI as the true identity of Flax Typhoon.

In Beijing, Chinese foreign ministry spokesperson Mao Ning said China has always cracked down on hacking activities in accordance with the law. Mao said Beijing also firmly opposes spreading disinformation and creating confusion for political purposes, adding that maintaining cybersecurity is a shared concern of both countries.

“We urge the U.S. to abandon its double standards and political manipulation, and work with China through equal dialogue and consultation to jointly address cybersecurity risks,” she said.

In September 2024, the FBI announced that it had disrupted a massive botnet associated with Flax Typhoon that installed malicious software on more than 200,000 consumer devices, including cameras, video recorders and home and office routers, to create a massive botnet. The botnet, or network of infected computers, was used to facilitate cyber crimes, such as the theft of sensitive information from victims’ networks.

FBI San Diego Supervisory Special Agent Brett Lally said that the department would continue to monitor for ways that the company might rebuild its infrastructure.

“It’ll be interesting to see what this round of disruption actions have in terms of their ability to operate as a company in China,” Lally said.

____

Tucker reported from Washington.

10/09/2026 04:53 -0400

News, Photo and Web Search

Regional News Headlines