FBI Seizes Chinese Hackers Tools They Had Pointed at Our Power Grid

FBI Seizes Chinese Hackers Tools They Had Pointed at Our Power Grid

A South Carolina power company. Airports in Japan and Poland. Natural gas and electric infrastructure in Taiwan. Twenty Taiwanese universities. A multinational NGO. All confirmed targets of a Beijing-linked hacking group called Flax Typhoon — operating through a Chinese government contractor called Integrity Technology Group.

On October 8, the Department of Justice and FBI seized seven internet domains that served as the backbone of the operation.

The tools had names that sound like video game weapons but worked like digital crowbars. Microscan — a vulnerability scanning tool powered by Mirai malware — crawled American networks looking for weak points. FishHub delivered spear-phishing malware to targets once those weak points were found. SoftEther kept the hackers embedded in compromised systems so they could come back whenever they wanted.

FBI Cyber Division Assistant Director Brett Leatherman explained that companies like Integrity Technology Group "expand the reach and scale of Beijing's cyber operations by giving China-linked actors the tools to scan and penetrate American networks." This wasn't freelance hacking. This was a state-backed contractor providing the Chinese government with industrial-grade cyber weapons aimed at critical American infrastructure.

Assistant Attorney General for National Security John Eisenberg made the DOJ's position plain: the United States would not allow China or its proxies to operate against American interests with impunity in cyberspace. The seizure of the seven domains was the enforcement action behind those words.

This wasn't the first time Flax Typhoon's infrastructure got dismantled. In September 2024, a related botnet — a network of hijacked devices used to launch attacks — was taken down. That one had compromised more than 200,000 devices. Roughly half of them were located inside the United States.

Two years between takedowns. Same contractor. Same Chinese state backing. Same target list: American critical infrastructure.

The pattern here isn't subtle. Beijing uses nominally private companies as cutouts for state-directed cyber operations. Integrity Technology Group isn't some rogue outfit freelancing on the dark web. It's a Beijing-based contractor doing exactly what the Chinese government wants done — probing the systems that keep American lights on, water flowing, and communications running.

The previous administration spent four years treating China as a trade partner who occasionally misbehaved. Meanwhile, Chinese government hackers were literally inside a South Carolina power company's network.

Seven domains seized. Two hundred thousand devices previously compromised. A contractor in Beijing with tools named Microscan and FishHub pointed at American power grids.

The seizure was announced October 8. The tools had been operational for years.


Most Popular

Most Popular