US seizes Chinese hacking tools weeks after Xi’s White House visit | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker



Behind the diplomatic smiles on the famous White House lawn, US investigators were preparing to dismantle cyber infrastructure allegedly used by Chinese state-sponsored hackers.

Barely a fortnight after Donald Trump rolled out the red carpet for Chinese President Xi Jinping’s state visit to the US, the US Department of Justice (DoJ) has provided a reminder that, behind the smiles, handshakes and diplomatic pleasantries, relations between the two superpowers remain decidedly less cordial.

Yesterday (8 October), the department announced that the FBI had seized seven internet domain names used to operate sophisticated hacking tools allegedly controlled by employees of a Chinese technology company with government contracts. The operation targeted infrastructure used to identify weaknesses in computer networks, gain unauthorised access to them and potentially steal sensitive data from businesses, universities and critical infrastructure operators across several countries.

The immediate concern for businesses and other institutions is whether sensitive data or access credentials have already been exposed. Taking down the infrastructure may prevent further misuse of these particular tools, but it cannot undo an intrusion that has already occurred.

The announcement follows Xi’s September visit, during which President Trump hailed the prospects for closer cooperation between Washington and Beijing.

The background

The investigation centres on the paradoxically named Integrity Technology Group, a Chinese company whose employees are alleged to have developed and operated hacking infrastructure associated with a group known to cybersecurity specialists as Flax Typhoon. According to court documents unsealed in the US District Court for the Western District of Pennsylvania, Integrity maintained a network of compromised internet-connected devices, known as a botnet, which could be used to scan other computer systems for weaknesses.

The devices had been infected with a variant of Mirai, malicious software that allows attackers to take control of equipment such as routers and other internet-connected products without their owners’ knowledge. Integrity allegedly used this network to support a tool called Microscan, which searched for vulnerabilities that could subsequently be exploited by its clients.

The targets were international and many were commercially sensitive. They included an electricity company in South Carolina, airports in Japan and Poland, Taiwanese natural-gas and electricity businesses, two Taiwanese universities and a multinational non-governmental organisation. The DoJ has stopped short of suggesting that every organisation subjected to scanning was successfully hacked: identifying a vulnerable system is not necessarily the same as gaining access to it.

The hacking operation

A second tool, the more aptly named FishHub, allegedly took the operation to another level. It was designed to support spear phishing, in which attackers send carefully targeted messages intended to trick recipients into opening malicious attachments or links. Once attackers had gained an initial foothold in a network, FishHub could download additional malware, allowing unauthorised remote access or searching for particular files and transferring them to servers controlled by Integrity. Approximately 20 Taiwanese universities were confirmed victims of FishHub activity, according to the department.

The FBI also identified a further remote-access tool, which allegedly connected several compromised networks to an Integrity server.

This latest operation is not the first time US investigators have targeted Integrity. In September 2024, the DoJ announced the disruption of an Integrity operation comprising more than 200,000 compromised consumer devices in the US and elsewhere. These latest seizures therefore represent a second attempt to dismantle infrastructure associated with the same alleged Chinese state-sponsored hacking operation.

The seizures

The operation was authorised by federal court warrants in Pennsylvania, allowing investigators to seize the seven domain names and prevent their continued use in the alleged hacking campaign. The department has not announced any arrests or criminal charges.

Assistant Attorney General for National Security John Eisenberg said in a statement: “The United States will not allow China or its proxies to operate against United States interests with impunity in cyberspace.”

FBI Cyber Division Assistant Director Brett Leatherman pointed the finger firmly in the face of the Chinese authorities, saying: “The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity.”

The operation was supported by Japanese police and accompanied by cybersecurity guidance issued jointly by various US agencies, the UK’s National Cyber Security Centre and their counterparts in Australia, Canada, Japan, New Zealand and Spain.

For all the warmth and pomp displayed during Xi’s visit, the DoJ’s message was rather less diplomatic. As US Attorney Troy Rivetti put it, the seizures demonstrate America’s determination to defend its networks against cybercriminals “from the PRC and elsewhere”.



Source link

...........