The United States Department of Justice announced on 8 October that the FBI had authorized the seizure of seven Internet domain names through the courts, cutting off two sets of tools used to scan, seduce and invade networks. The Ministry of Justice directed these tools at the Integrity Technology Group, an enterprise established in China and contracted by the Chinese Government. This is not an ordinary hacking device: United States law enforcement claims that the targets of the attack included critical infrastructure, offshore agencies and about 20 universities in Taiwan. Two attack routes behind the seven domain names.

According to the United States Department of Justice ' s public seizure bulletin and summary of the Tribunal ' s materials, the first set of tools, Microscan, was used to detect weaknesses in networked equipment and servers on a large scale; Another set of FishHubs serves target-specific online fishing, which can induce targets to carry out malicious procedures. The Ministry of Justice indicated that five sealed domain names assisted in the delivery of malicious software, including addresses imitating office software, video websites and social platforms, such as outlook3650.com, yooutubecard.com and linkedins.net. This designation is not random: it packages malicious access into familiar daily Internet experience and uses the habits of the addressee to reduce vigilance.

原始来源 · justice.gov美国司法部原始查封公告justice.gov ↗

The Ministry of Justice also described another key capability: an unauthorized remote management process that connects the network to a server controlled by good faith technology. This allowed the event to evolve from “a person scanning a gap on the Internet” to a specific intrusion chain that would allow permanent access to other people's networks, retrieve documents and send information. The United States confirmed that the victims of the FishHub operation included some 20 universities in Taiwan; This figure corresponds to the confirmed range and should not be misinterpreted as the total number of targets. Why did the zombie network, which was destroyed in 2024, come up with another seizure two years later?

The investigation into the operation cannot be conducted without a passing September

  1. At that time, the United States Department of Justice had announced court-mandated technical actions to dismantle the Mirai zombie network, which was linked to good science and technology and comprised more than 200,000 units of equipment of consumption-grade size that had been attacked. Once the personal router and other networked equipment is lost, it can become a springboard for the attackers to launch connections, conceal sources and expand the scanning range around the world.

In two years, law enforcement seized not the same household equipment, but rather the domain names that supported the gap scanning, cyber fishing and remote control. This change shows that a single Zombies Clearing Network is not the end of the ecological attack. The attackers can adapt tools and infrastructure; The defensive party must continuously track the services of the enterprise, domain name, equipment and evidence that carries the attack capability.

VulnCheck整理的Flax Typhoon历史网络攻击涉及设备类别图表
VulnCheck整理的Flax Typhoon历史网络攻击涉及设备类别图表 · 查看图片来源 ↗
原始来源 · bleepingcomputer.com安全行业对查封行动的技术说明bleepingcomputer.com ↗

From Cybersecurity to National Security Disputes

The Ministry of Justice stated that the good faith technology had a contractual relationship with the Chinese Government and concluded that its personnel were involved in what the private security industry called “Flax Typhoon” (typhoon sub-leap). The link between government contracts and a particular cyber invasion is one of the most public parts of the case: what kind of business arrangement does a business run in the form of technical goods and services provide a specific customer with a gap-scan, permanent access and information-access capability?

亚麻台风攻击路径示意图,资料分析而非现场影像|来源:Vectra AI
亚麻台风攻击路径示意图,资料分析而非现场影像|来源:Vectra AI · 查看图片来源 ↗

This is also the line that needs to be precisely drawn in the present case. Public seizure and allegations by United States law enforcement agencies can support reporting on domain names, tools and targets, but this does not mean that journalists have received specific command orders for all original contracts or each attack. China has long denied that State-sponsored cyberattacks are being carried out; Court documents surrounding the relationship between specific tools and server control are therefore more worthy of public scrutiny than general diplomatic rebuke statements. Why did Taiwan University become a notable target?

The University not only keeps the personal data of teachers and students, but also carries scientific cooperation, international exchanges, technical design and academic mail systems. The presence of some 20 universities in Taiwan among identified victims means that security threats may enter the field of education and scientific research, going beyond the military, government agencies and energy systems that are usually noted. (b) It cannot be concluded from the public information that all data on these schools have been released; However, the ability of the school to independently take evidence, to account for the risks to the affected persons, and to keep a log directly relates to the detection of damage and to the remedy.

The case raises a more acute question about the relationship between political power and the technological industry in Beijing: when government contracts, cyber-security tools and unauthorized invasion capabilities meet with the same company, responsibility cannot stop with several anonymous hacker accounts. The people who buy, deploy and use technology, who have the data that they obtain, and the ordinary users and civil society organizations who bear the consequences of these actions should be tracked. After the sealing, the network was left behind, not the case.

Seven domain names have been seized, which means that part of the operational path of the tool has been cut; It does not mean that all those involved are caught or that the systems that have been attacked in history are automatically secure. The United States simultaneously issues transnational cyber security alerts for the defence to compare the intrusion indicators, check exposed servers and evidence. The practical value of this advice lies in the opportunity for affected institutions to move from “political news readers” to network managers who can sort out risks on a case-by-case basis.

美国司法部建筑资料照,非本次查封行动现场|来源:Reuters
美国司法部建筑资料照,非本次查封行动现场|来源:Reuters · 查看图片来源 ↗

The Ministry of Justice has twice intervened openly in the same enterprise-related infrastructure, demonstrating the inescapable reality of cross-border cyber attacks: the destructive capacity of cyberspace can be constantly migrated between commercial subjects, attack platforms and global commons, and power responsibility can easily be diluted between these links. The operation revealed not only the use of seven domain names, but also the systemic question of who is entitled to use them, who has the capacity to monitor and whether victims can be accounted for when national security activities expand through the civil technological infrastructure.

MEMBER DISCUSSION

Article discussion

Verified members can discuss this report publicly and manage their own content.