Interestana
Home/News/FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools

FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools

The U.S. Federal Bureau of Investigation (FBI) and the Department of Justice (DoJ) announced on May 23, 2024, the disruption of malicious tools utilized by an advanced persistent threat (APT) group linked to China, identified as Flax Typhoon. This operation involved the seizure of seven internet domains and the blocking of access to platforms that Flax Typhoon employed for scanning and infiltrating U.S. critical infrastructure. The group has been actively targeting organizations within sectors such as government, education, and critical manufacturing since at least mid-2021.

Flax Typhoon's tactics, techniques, and procedures (TTPs) were detailed in a joint advisory issued by the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency (NSA). The advisory highlighted the group's use of legitimate network administration tools, often referred to as "living off the land" techniques, to maintain persistence and evade detection within victim networks. These tools include legitimate utilities like PowerShell, PsExec, and Cobalt Strike, which are repurposed for malicious activities. The group's primary objective appears to be espionage, with a focus on gathering intelligence from targeted entities.

The seized domains were instrumental in Flax Typhoon's command and control (C2) infrastructure, enabling the group to communicate with compromised systems and exfiltrate data. By taking control of these domains, the FBI and DoJ have effectively dismantled a significant portion of the group's operational capabilities within the United States. The operation underscores the persistent threat posed by state-sponsored APT groups to U.S. national security and economic interests, particularly concerning the protection of critical infrastructure.

This action is part of a broader, ongoing effort by U.S. law enforcement and intelligence agencies to counter cyber threats originating from foreign adversaries. The FBI's Cyber Division, in collaboration with international partners, continuously monitors and disrupts malicious cyber activities. The disruption of Flax Typhoon's infrastructure serves as a warning to other threat actors and reinforces the commitment to safeguarding the digital landscape of the United States. The advisory also provides specific technical details and recommended mitigation strategies for organizations to enhance their defenses against similar attacks.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next