Executive Summary
In December 2024, the Department of Justice and FBI seized two hacking tools linked to Chinese state-sponsored group Flax Typhoon and Integrity Technology Group, a sanctioned Chinese firm. The seizure targeted Microscan, a vulnerability scanning tool, and FishHub, a spearphishing platform that facilitated attacks on critical infrastructure including South Carolina power companies, airports in Japan and Poland, and Taiwanese universities. The operation disrupted a sophisticated campaign combining automated scanning, large-scale botnets, and targeted exploitation techniques to steal sensitive data from organizations worldwide, with particular focus on U.S. critical infrastructure sectors.
This incident underscores the escalating threat from Chinese APT groups positioning themselves within critical infrastructure networks for potential future disruption. The coordinated law enforcement response reflects growing urgency around protecting operational technology systems and preventing pre-positioned access that could enable catastrophic attacks during geopolitical tensions.
Why This Matters Now
Chinese state actors are actively pre-positioning within critical infrastructure networks, including operational technology systems, with the capability to disrupt essential services at will during future conflicts or geopolitical tensions.
Attack Path Analysis
Flax Typhoon leveraged Microscan vulnerability scanning tool to identify exposed Microsoft Exchange servers and other critical infrastructure, followed by spearphishing campaigns using FishHub to deliver malware. After establishing initial foothold, attackers escalated privileges and moved laterally across network segments. Command and control was maintained through VPN software and scripts, enabling systematic exfiltration of emails and credentials from targeted organizations including power companies, airports, and universities.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Automated Microscan vulnerability scanning identified exposed Microsoft Exchange servers and other internet-facing assets, followed by exploitation of discovered vulnerabilities and cross-site scripting attacks
MITRE ATT&CK® Techniques
Spearphishing Attachment
Vulnerability Scanning
Password Spraying
Exploit Public-Facing Application
Windows Command Shell
Exfiltration Over Web Service
External Remote Services
Domains
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Network Architecture and Segmentation
Control ID: ID.AM-3
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
Digital Operational Resilience Act (DORA) – ICT Risk Management Framework
Control ID: Article 8
PCI DSS 4.0 – Software Engineering Techniques
Control ID: 6.2.4
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.8.8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Advanced persistent threats targeting power companies via vulnerability scanning and botnet infrastructure pose critical risks to operational technology systems and grid stability.
Airlines/Aviation
Aviation infrastructure directly targeted by Microscan tool demonstrates vulnerability to Chinese government-linked APT groups compromising airport systems and critical transportation networks.
Higher Education/Acadamia
Universities face dual threats from automated scanning tools and spearphishing campaigns, with validated attacks on Taiwanese institutions exposing research data and credentials.
Government Administration
Critical infrastructure sectors face state-sponsored threats combining automated scanning, botnet operations, and credential theft targeting Microsoft Exchange servers and VPN infrastructure.
Sources
- DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHubhttps://cyberscoop.com/doj-fbi-seize-flax-typhoon-hacking-tools-microscan-fishhub/Verified
- FBI and DOJ Announce Domain Seizures Related to Chinese Hacking Toolshttps://www.fbi.gov/news/press-releases/fbi-and-doj-announce-domain-seizures-related-to-chinese-hacking-toolsVerified
- CISA Advisory: Chinese Government-Linked Actors Target Critical Infrastructurehttps://www.cisa.gov/news-events/cybersecurity-advisoriesVerified
- Flax Typhoon APT Group Analysis - Microsoft Security Intelligencehttps://www.microsoft.com/en-us/security/blog/threat-intelligence/flax-typhoon/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the scope of Flax Typhoon's critical infrastructure compromise by constraining lateral movement between network segments and limiting access to operational technology systems through workload isolation and east-west traffic controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security fabric controls would likely limit the attacker's ability to pivot from compromised Exchange servers to internal cloud workloads and reduce reachability across hybrid infrastructure environments.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely constrain the scope of privilege escalation by limiting access to resources based on identity verification rather than network location or compromised system privileges.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain lateral movement pathways between critical infrastructure segments and reduce the attacker's ability to reach operational technology systems from compromised IT networks.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely detect and constrain unauthorized VPN installations and reduce the attacker's ability to maintain persistent command channels across distributed critical infrastructure environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely constrain data exfiltration pathways and reduce the volume of sensitive information extracted by enforcing data loss prevention policies at network boundaries.
Remaining attacker presence would likely be constrained to specific network segments with limited ability to impact operational technology systems or cause widespread infrastructure disruption due to workload isolation boundaries.
Impact at a Glance
Affected Business Functions
- Power Generation and Distribution
- Critical Infrastructure Operations
- Airport Security and Operations
- University Research Systems
Estimated downtime: N/A
Estimated loss: N/A
Email credentials and sensitive data from targeted organizations including South Carolina power companies, airports in Japan and Poland, critical infrastructure companies, and Taiwanese universities. Exposure includes corporate emails, authentication credentials, and potentially operational technology system access.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between network segments and limit blast radius of compromised credentials
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts and command and control communications
- • Enable Multicloud Visibility & Control to identify anomalous interactions and suspicious automation patterns across hybrid environments
- • Strengthen East-West Traffic Security with workload-to-workload inspection to detect internal reconnaissance and lateral movement activities
- • Deploy Inline IPS capabilities to identify and block known exploit patterns and malicious payloads targeting Exchange servers and other critical infrastructure



