Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FBI Disrupts Flax Typhoon Tools in Critical Infrastructure

FBI Disrupts Flax Typhoon Tools in Critical Infrastructure

Posted on October 9, 2026 By CWS

The Federal Bureau of Investigation (FBI) and the Department of Justice (DoJ) have taken significant steps to neutralize cyber threats posed by a China-linked advanced persistent threat group, known as Flax Typhoon. This operation involved seizing multiple domains utilized by the group to infiltrate and compromise U.S. critical infrastructure.

Seized Domains and Their Impact

The domains confiscated during the operation include c0cc[.]cc, 98aiblog[.]com, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net. These platforms were used to conduct scans and, in some cases, infiltrate crucial infrastructure systems. The action by the FBI is a critical move towards safeguarding national security.

Flax Typhoon, also identified as Ethereal Panda and RedJuliett, is linked to the Integrity Technology Group, a Beijing-based firm contracting with the Chinese government. The group was previously associated with a botnet named Raptor Train, which was dismantled following a court-sanctioned operation in September 2024.

Technical Details of the Operation

According to court documents, Integrity Technology Group developed and maintained an IoT botnet utilizing a variant of the Mirai malware. This botnet employed domains, including subdomains of w8510[.]com, for command-and-control purposes, facilitating two-way communication between the botnet controllers and infected devices.

As of June 5, 2024, the botnet’s records indicated over 1.2 million compromised devices, with more than 385,000 located within the U.S. The tool known as Microscan played a pivotal role in reconnaissance and vulnerability scanning, identifying potential targets using over 1,300 penetration testing scripts. This tool, alongside open-source utilities like BBScan and NMAP, enabled the detection of vulnerabilities in network and web applications.

Broader Implications and Future Outlook

Beyond the immediate disruption, this operation underscores the international cooperation required to combat cyber threats. The U.S., alongside allies such as the U.K., Australia, and others, issued a joint advisory pinpointing Integrity Tech’s role in facilitating cyber intrusions worldwide. These activities notably included the exploitation of critical infrastructure in countries like the U.S., Japan, and Taiwan.

The U.S. State Department has offered rewards for information leading to the identification or location of individuals involved in related cyber activities. The case emphasizes the ongoing global efforts to thwart cyber threats, with a focus on holding accountable those who aid in these malicious activities.

The FBI’s recent actions against Flax Typhoon highlight the complexity of modern cyber threats and the need for robust international collaboration to protect critical infrastructure from state-sponsored cyber activities.

The Hacker News Tags:Botnet, China-linked Hackers, critical infrastructure, cyber intrusions, cyber threats, cyber tools, Cybersecurity, Domains, FBI, Flax Typhoon, Hacking, Integrity Technology Group, international cybersecurity, Malware, network security

Post navigation

Previous Post: Citrix Calls for Urgent Patching of Critical NetScaler Flaw
Next Post: Critical Fix Needed for NetScaler Vulnerability, Says Citrix

Related Posts

Google Warns Salesloft OAuth Breach Extends Beyond Salesforce, Impacting All Integrations Google Warns Salesloft OAuth Breach Extends Beyond Salesforce, Impacting All Integrations The Hacker News
Critical Golden dMSA Attack in Windows Server 2025 Enables Cross-Domain Attacks and Persistent Access Critical Golden dMSA Attack in Windows Server 2025 Enables Cross-Domain Attacks and Persistent Access The Hacker News
Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling The Hacker News
Over 24,000 BMCs Expose IPMI Passwords: Security Alert Over 24,000 BMCs Expose IPMI Passwords: Security Alert The Hacker News
Researchers Spot Surge in Erlang/OTP SSH RCE Exploits, 70% Target OT Firewalls Researchers Spot Surge in Erlang/OTP SSH RCE Exploits, 70% Target OT Firewalls The Hacker News
SonicWall Fixes Critical SSRF Vulnerability in SMA1000 SonicWall Fixes Critical SSRF Vulnerability in SMA1000 The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • US Dismantles Chinese Hacking Tools Targeting Infrastructure
  • Silent Ransom Group Nets $200M Without Encrypting Data
  • Hackers Earn Over $560K for Google Pixel 10 Exploits
  • Critical Fix Needed for NetScaler Vulnerability, Says Citrix
  • FBI Disrupts Flax Typhoon Tools in Critical Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • US Dismantles Chinese Hacking Tools Targeting Infrastructure
  • Silent Ransom Group Nets $200M Without Encrypting Data
  • Hackers Earn Over $560K for Google Pixel 10 Exploits
  • Critical Fix Needed for NetScaler Vulnerability, Says Citrix
  • FBI Disrupts Flax Typhoon Tools in Critical Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark