Flax Typhoon: MicroScan Scanned Japanese Airports; U.S. Seizes Seven Domains
本文为原文前 6,000 字符的节选翻译,完整内容请查看原文。
-
Basic Information Article Name: Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers Publisher: U.S. Department of Justice Publication Date: 2026-10-08 Original Source: U.S. Department of Justice Related Sources: Seizure Warrant Affidavit, CISA/FBI Joint Advisory, BleepingComputer, The Record Related Malware and Threat Groups: FishHub, Mirai variant, Flax Typhoon, Integrity Technology Group Related CVEs: None specified Related Products: MicroScan, FishHub, SoftEther VPN Severity: Critical
-
基本信息 文章名称:司法部和联邦调查局查封由中国国家支持的黑客运营和使用的漏洞扫描及鱼叉式网络钓鱼工具 发布者:美国司法部 发布日期:2026年10月8日 原始来源:美国司法部 相关来源:查封令宣誓书、CISA/FBI联合公告、BleepingComputer、《记录》杂志 相关恶意软件及威胁组织:FishHub、Mirai变体、Flax Typhoon、Integrity Technology Group 相关CVE:未指定 相关产品:MicroScan、FishHub、SoftEther VPN 严重程度:严重
-
Executive Summary Flax Typhoon actors linked to Integrity Tech used a Mirai botnet and MicroScan to probe for vulnerabilities, employed FishHub for remote access and file theft following spearphishing, and U.S. authorities seized 7 domains.
-
执行摘要 与Integrity Tech有关联的Flax Typhoon攻击者利用Mirai僵尸网络和MicroScan探测漏洞,在鱼叉式网络钓鱼后使用FishHub进行远程访问和文件窃取,美国当局已查封了7个域名。
-
Attack Flow IoT Botnet Probing and FishHub Compromise The following tactics were identified across multiple investigations. MicroScan probing and compromise, FishHub malware distribution, and SoftEther access persistence were not necessarily executed consecutively against the same victim. Integrity Tech-associated actors used a Mirai IoT botnet as a distributed probing infrastructure for MicroScan. MicroScan used over 1,300 scripts to search for vulnerabilities in public services. Clients exploited discovered vulnerabilities or gained initial access via FishHub spearphishing. FishHub deployed additional malware to perform remote access and specific file searches. FishHub-related malware sent files to attacker servers. Separately, at compromised systems in a Taiwanese university, persistence via SoftEther VPN was also confirmed.
-
攻击流程 物联网僵尸网络探测与FishHub入侵 在多项调查中发现了以下战术。MicroScan探测与入侵、FishHub恶意软件分发以及SoftEther访问持久化并不一定针对同一受害者连续执行。与Integrity Tech相关的攻击者使用Mirai物联网僵尸网络作为MicroScan的分布式探测基础设施。MicroScan使用超过1300个脚本搜索公共服务中的漏洞。客户端利用发现的漏洞或通过FishHub鱼叉式网络钓鱼获得初始访问权限。FishHub部署了额外的恶意软件以执行远程访问和特定文件搜索。与FishHub相关的恶意软件将文件发送到攻击者服务器。此外,在台湾某大学的受感染系统中,还确认了通过SoftEther VPN实现的持久化。
-
Attacker Position and Execution Vector State-sponsored actors target internet-facing critical infrastructure using IoT botnets, scanning platforms, and phishing delivery domains.
-
攻击者定位与执行向量 国家支持的攻击者利用物联网僵尸网络、扫描平台和网络钓鱼投递域名,针对面向互联网的关键基础设施进行攻击。
-
Victim and Administrator Perspective Users: Malicious activity may resemble routine scanning or legitimate business email. Administrators: Can observe distributed scanning, phishing, additional malware, SoftEther, specific file access, and data egress.
-
受害者与管理员视角 用户:恶意活动可能看起来像常规扫描或合法的商务电子邮件。 管理员:可以观察到分布式扫描、网络钓鱼、额外恶意软件、SoftEther、特定文件访问和数据外泄。
-
Conditions for Success and Failure Success Conditions: The presence of exploitable vulnerabilities in public-facing services or successful phishing. Execution of additional malware and remote access tools with permitted egress. Failure Conditions and Countermeasures: Patch vulnerable internet-facing services and restrict unnecessary network access to reduce exposure to exploitation. Apply separate controls against spearphishing. Detecting and blocking unauthorized VPNs, malware, specific file access, and data egress.
-
成功与失败条件 成功条件:面向公众的服务中存在可利用的漏洞或网络钓鱼成功。执行了额外的恶意软件和允许外联的远程访问工具。 失败条件与对策:修补面向互联网的易受攻击服务,并限制不必要的网络访问以减少暴露。针对鱼叉式网络钓鱼实施单独的控制措施。检测并阻止未经授权的VPN、恶意软件、特定文件访问和数据外泄。
-
Outcomes of Successful Exploitation Unauthorized access to critical infrastructure networks. Remote command execution and long-term persistence. Discovery and exfiltration of specific files. Conversion of IoT devices into a botnet for additional scanning.
-
成功利用后的结果 未经授权访问关键基础设施网络。远程命令执行和长期持久化。发现并窃取特定文件。将物联网设备转化为用于额外扫描的僵尸网络。
-
Observable Logs The following items are candidates for internal investigation, and not all events were necessarily observed in this specific incident. Email: Check for lookalike domains, spearphishing links or attachments, and delivery domains. Proxy / SWG / DNS: Check for seized domains, FishHub delivery domains, malware downloads, and SoftEther control traffic. Endpoint / EDR: Check for additional malware, specific file searches, archiving or staging, and SoftEther installation. Identity / IdP: Check for logins from unusual locations, token and credential use, permission changes, and service account operations. SaaS / Cloud: Check administrative APIs, audit logs, repository and cloud resource access, and large downloads. Network: Check for MicroScan probes, distributed scanning originating from the Mirai botnet, and large outbound transfers.
-
可观测日志 以下项目是内部调查的候选对象,并非所有事件都在本次特定事件中被观察到。 电子邮件:检查仿冒域名、鱼叉式网络钓鱼链接或附件以及投递域名。 代理/SWG/DNS:检查被查封的域名、FishHub投递域名、恶意软件下载和SoftEther控制流量。 终端/EDR:检查额外的恶意软件、特定文件搜索、归档或暂存以及SoftEther安装。 身份/IdP:检查来自异常位置的登录、令牌和凭据使用、权限更改以及服务账户操作。 SaaS/云:检查管理API、审计日志、存储库和云资源访问以及大文件下载。 网络:检查MicroScan探测、源自Mirai僵尸网络的分布式扫描以及大量出站传输。
-
Assessing Attack Success Confirmed in Public Information: Attack attempts observed (success unconfirmed): Japanese and Polish airports were among the MicroScan targets. The cited sources document scanning of these airports but do not establish successful intrusion into them. Subsequent compromises confirmed: Infiltration following MicroScan scans was documented for two Taiwanese universities. The scale of FishHub victims was reported by the DOJ as approximately 20 universities, while the seizure warrant affidavit states over 20 organizations (including 6 Taiwanese universities); the reason for these differing figures remains unclear. Internal Assessment Criteria: Correlate requests, processes, authentication, data access, and outbound transmissions to distinguish between attack attempts and successes. Do not determine success based solely on HTTP status codes or single alerts when not supported by public information.
-
评估攻击成功与否 公开信息确认:观察到的攻击尝试(成功与否未确认):日本和波兰的机场在MicroScan的目标之列。引用的来源记录了对这些机场的扫描,但并未证实成功入侵。 后续确认的入侵:记录显示MicroScan扫描后,两所台湾大学遭到入侵。司法部报告称FishHub的受害者规模约为20所大学,而查封令宣誓书称超过20个组织(包括6所台湾大学);这些数字差异的原因尚不清楚。 内部评估标准:关联请求、进程、身份验证、数据访问和出站传输,以区分攻击尝试和成功。在没有公开信息支持的情况下,不要仅根据HTTP状态码或单一警报来判定成功。
-
Investigation Playbook Investigation Origin: Start from published domains, distributed vulnerability scans, FishHub malware, and SoftEther installations. Initial Verification: Verify target products, versions, configurations, external accessibility, exposure duration, and update/containment times. Endpoint and Server Investigation: Check for malware, remote access, file searches, archiving, VPN services, and persistence. Authentication and Cloud Investigation: Check for suspicious accounts, tokens, API usage, privilege changes, unusual connection sources, and resource access. Subsequent Activity: Track credential access, lateral movement, additional downloads, outbound transmissions, and account creation following initial events. Containment: Isolate compromised hosts and IoT devices, block domains and C2, and rotate credentials. Categorization: Distinguish between scanning/attack attempts, initial execution, successful authentication, data theft, and subsequent compromises.
-
调查手册 调查起点:从已公布的域名、分布式漏洞扫描、FishHub恶意软件和SoftEther安装开始。 初步验证:验证目标产品、版本、配置、外部可访问性、暴露时长以及更新/遏制时间。 终端与服务器调查:检查恶意软件、远程访问、文件搜索、归档、VPN服务和持久化。 身份验证与云调查:检查可疑账户、令牌、API使用、权限更改、异常连接源和资源访问。 后续活动:追踪初始事件后的凭据访问、横向移动、额外下载、出站传输和账户创建。 遏制:隔离受感染的主机和物联网设备,封锁域名和C2,并轮换凭据。 分类:区分扫描/攻击尝试、初始执行、成功身份验证、数据窃取和后续入侵。
-
Defense and Detection Ideas Single Events: Detect communications with seized domains, unauthorized SoftEther usage, and specific file search tools. Chronological Correlation: Correlate scanning or phishing with subsequent malware execution, remote access, file searches, and outbound transfers where evidence links the events.
-
防御与检测思路 单一事件:检测与被查封域名的通信、未经授权的SoftEther使用以及特定文件搜索工具。 时间序列关联:在有证据关联的情况下,将扫描或网络钓鱼与随后的恶意软件执行、远程访问、文件搜索和出站传输进行关联。