U.S. authorities have disrupted part of the infrastructure associated with Flax Typhoon, a China-linked threat group also tracked as Ethereal Panda and RedJuliett. The FBI and Department of Justice announced the seizure of seven domains that were allegedly used to support reconnaissance, vulnerability scanning, command-and-control activity, and in some cases intrusions targeting critical infrastructure and other organizations.
The operation matters because it targets the enabling layer behind intrusions rather than only individual compromised devices. According to the reporting, the seized domains were connected to tools and platforms used to scan networks, identify vulnerable systems, and support follow-on compromise. For defenders, the practical lesson is clear: externally exposed services, unmanaged edge devices, and weak cloud identity controls remain high-value entry points for state-linked and contractor-enabled threat activity.
What was disrupted
The seized domains reportedly included infrastructure used by tools associated with Integrity Technology Group, a Beijing-based company that U.S. authorities have linked to Flax Typhoon activity. The domains named in the report include c0cc[.]cc, 98aiblog[.]com, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net.
The activity is connected to a broader ecosystem that previously included the Raptor Train botnet, a network of compromised small office/home office and IoT devices disrupted in 2024. Court documents cited in the report allege the botnet used a Mirai variant and was managed through an application called Sparrow. Records found on one server reportedly showed more than 1.2 million infected devices as of June 2024, including hundreds of thousands of U.S. victim devices.
That scale is important. Botnets built from routers, cameras, NAS devices, and other edge hardware give attackers distributed infrastructure for scanning, relaying traffic, and hiding the origin of activity. Even when a domain seizure interrupts one part of the operation, similar tactics can be rebuilt if organizations leave the same device classes exposed and unmaintained.
Tools and targeting described in the report
One highlighted tool, Microscan, was described as a Python-based web platform used for reconnaissance and vulnerability scanning. It reportedly included more than 1,300 penetration-testing scripts and incorporated open-source scanners and discovery tools. The vulnerabilities and technologies referenced include OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts.
A second tool, FishHub, was described as supporting spear-phishing and follow-on payload deployment. Confirmed FishHub-related victim activity reportedly included Taiwanese universities. The broader targeting described in the reporting included a U.S. power company, international non-governmental organizations, airports, energy-sector entities, universities, and other critical infrastructure organizations.
The report also notes activity involving cloud services and identity abuse. Threat actors linked to the broader campaign have reportedly used Python and Go utilities, cross-site scripting attacks for credential harvesting, SoftEther VPN clients for persistence, brute-force tooling against Microsoft 365 environments, and command-line tools to access mailbox data.
Defensive actions to prioritize
Security teams should treat this as a reminder to reduce exposure before automated scanning finds it. Start with internet-facing inventory. Confirm which assets are reachable from the public internet, including VPN appliances, firewalls, routers, remote access services, web applications, development systems, and forgotten test environments. Asset lists should be reconciled against external attack surface scans, DNS records, cloud accounts, and certificate transparency data.
Next, patch the systems most often targeted by broad scanners. Prioritize edge devices, web application frameworks, CMS platforms, Java application servers, VPN gateways, identity systems, and administrative interfaces. If a product is end-of-life or cannot receive security updates, isolate or replace it rather than accepting permanent exposure.
For SOHO and branch-office equipment, disable remote administration unless it is explicitly required, enforce strong unique credentials, update firmware, and remove devices that are no longer supported. Many IoT and router compromises persist because the affected device is outside normal endpoint management and is never reviewed after installation.
Cloud identity controls also need attention. Enforce phishing-resistant multifactor authentication for administrators and high-risk users, monitor impossible travel and suspicious mailbox access, block legacy authentication, and review OAuth application consent. Where Microsoft 365 is in use, audit mailbox forwarding rules, unusual Graph API access, and command-line access patterns that do not match normal administrative behavior.
Detection opportunities
The named domains should be searched across DNS logs, proxy logs, firewall telemetry, SIEM data, EDR telemetry, and historical packet metadata where available. Because the domains are now public and likely disrupted, defenders should not rely only on fresh detections. Historical lookback is more useful: search at least the last 90 to 180 days if retention allows.
Teams should also hunt for signs of mass scanning and post-exploitation staging. Useful leads include unusual outbound connections from network appliances or IoT devices, administrative logins from residential or hosting networks, unexpected SoftEther VPN installation, abnormal Python or Go command-line utilities on servers, and mailbox access from unfamiliar automation tools.
If any of the named domains appear in logs, treat the finding as a lead rather than proof of compromise. Validate the source host, timestamp, destination, user account context, and follow-on activity. A single blocked DNS lookup may indicate scanning, a security tool test, or unrelated noise; repeated connections from sensitive systems deserve escalation.
Why this matters beyond one takedown
Domain seizures can interrupt attacker operations, expose infrastructure, and force adversaries to rebuild. They do not remove the underlying risk: organizations with exposed services, weak identity controls, unmanaged devices, and poor logging remain attractive targets. The best response is not panic; it is disciplined reduction of reachable attack surface and faster detection of the behaviors these operations depend on.
For critical infrastructure operators, universities, NGOs, and companies with globally exposed services, this is a good moment to run a focused review: external assets, edge-device patching, cloud identity hardening, DNS lookbacks, and incident response readiness. Those controls will matter even after the specific seized domains fade from relevance.
Source: The Hacker News source