Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers

Today the Justice Department and FBI announced court-authorized seizures to deny malicious cyber actors access to two hacking tools, “Microscan” and “FishHub,” used to scan and, in some cases, hack, U.S. and foreign critical infrastructure systems and other networks. As alleged in court documents unsealed in the Western District of Pennsylvania, malicious cyber actors working for Integrity Technology Group (Integrity Tech), a company based in the People’s Republic of China (PRC), operated and used the tools. Integrity Tech has contracts with the PRC government.

“The United States will not allow China or its proxies to operate against United States interests with impunity in cyberspace,” said Assistant Attorney General for National Security John A. Eisenberg. “The National Security Division will continue to respond decisively and use every tool at our disposal to disrupt the Flax Typhoon threats, dismantle the infrastructure sustaining them, and protect the critical networks that power our daily lives and on which our Nation’s security depends.”

“These state-sponsored hackers continue to aggressively target and access networks and systems throughout the world in an effort to identify and steal files and otherwise exploit victims’ vulnerabilities,” said U.S. Attorney Troy Rivetti for the Western District of Pennsylvania. “These seizures, our second disruption of Integrity Tech’s massive operations in as many years, send another clear message to cybercriminals from the PRC and elsewhere of the Department’s dedication to defending and maintaining cybersecurity in the United States and abroad.”

Read more: Department of Justice