← Back to the feed

FBI seizes domains tied to Chinese cyber operations targeting networks worldwide

The Register ·

The FBI seized seven domains allegedly linked to Integrity Technology Group, a Chinese security firm accused of supporting Beijing-backed cyber operations. The action aims to disrupt tools used to scan networks, install malware and steal sensitive information, as seven governments warned that Chinese government-linked attackers continue to target organisations worldwide.

Court documents allege the Flax Typhoon group used a Mirai-based botnet, the Microscan vulnerability scanner and FishHub malware. The seized domains were allegedly used to scan a South Carolina power company and other infrastructure, and to deliver malware to about 20 Taiwanese universities as recently as March. The FBI said the group’s botnet had infected 260,000 devices before it was disrupted in 2024.

  • FBI seized seven domains linked to alleged Chinese hacking tools.
  • Seven governments warned of ongoing attacks and data theft.
  • The tools were used against infrastructure and universities.

New here? Start with this

China has been conducting cyber operations targeting critical infrastructure and organisations worldwide. These campaigns, linked to the Chinese government, involve infiltrating computer networks to steal information and gather intelligence. Intelligence agencies and security researchers from multiple countries have documented these activities for several years.

The operations target a diverse range of organisations including power stations, universities, government agencies and other institutions. Attackers install malicious software to breach networks and maintain long-term access to steal data and intelligence. The scale of these campaigns affects thousands of organisations across numerous countries.

Chinese government-linked security firms and hacking groups conduct these operations, often using similar tools and techniques. The FBI and allied governments consider these campaigns a significant threat to national security and critical infrastructure worldwide. Increased awareness of these threats has prompted governments to strengthen their defences and take action against suspected operators.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

This action represents necessary law enforcement against documented cyber threats to critical infrastructure. Court documentation details specific malware, botnets and tools actively targeting American power systems and overseas organisations, whilst concurrent warnings from seven governments provide credible corroboration. Disrupting these domains prevents immediate harm to vulnerable infrastructure and civilian systems, and represents proportionate action to protect national security against ongoing, sophisticated cyber operations.

The case against

Whilst the cyber-threat is serious, significant concerns attend unilateral domain seizures. Attribution in cyber operations, though plausible here, involves technical complexity where certainty remains elusive and historical cases demonstrate potential for error. The action sidesteps due process protections and international legal norms governing enforcement against foreign actors, risking escalation with China whilst raising questions about proportionality and effectiveness—domain disruptions often prove temporary against determined state actors. Setting such precedents invites retaliation from other nations pursuing similar enforcement approaches.

Americas Cybersecurity Technology World

Read the full article at the source →

Originally published by The Register as “US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide”.