Cyberwarfare / Nation-State Attacks
,
Fraud Management & Cybercrime
,
Network Firewalls, Network Access Control
Integrity Technology Group Built Botnet for Chinese Hackers, US Treasury Says
The U.S. federal government sanctioned a Beijing-based tech company for supporting a Chinese state hacking group tracked as Flax Typhoon.
See Also: Corelight’s Brian Dye on NDR’s Role in Defeating Ransomware
The Department of Treasury blacklisted Integrity Technology Group, declaring transactions with the company to be off-limits for U.S. financial institutions and persons. As is often the case with U.S. sanctions against state-sponsored malicious cyber actors, the effect will likely have more symbolic than actual disruptive effect.
Treasury said Friday that Flax Typhoon hackers used infrastructure tied to Integrity Tech between summer 2022 and fall 2023. A September advisory from U.S. intelligence agencies and partners in the international Five Eyes intelligence sharing alliance said Integrity Tech has built and managed a botnet since mid-2021. The company uses variants of Mirai botnet code that first leaked online in 2016.
The FBI in September led an operation to dismantle a Flax Typhoon botnet consisting of more than 200,000 consumer devices such as routers and digital cameras located in the United States and across the globe (see: Chinese Hackers Build Massive Botnet Targeting US Devices).
Law enforcement said that during a court-ordered operation to disable the botnet, Chinese hackers attempted to disrupt the takedown through a distributed denial-of-service attack.