US sanctions Chinese company linked to Flax Typhoon hackers

Share:

​The U.S. Treasury Department has sanctioned Beijing-based cybersecurity company Integrity Tech for its involvement in cyberattacks attributed to the Chinese state-sponsored Flax Typhoon hacking group.

As the Treasury’s Office of Foreign Assets Control (OFAC) said on Friday, the Chinese state-sponsored hackers used the company’s infrastructure to launch attacks targeting networks of victims in Europe and the United States for over a year, starting in the summer of 2022.

“Between summer 2022 and fall 2023, Flax Typhoon actors used infrastructure tied to Integrity Tech during their computer network exploitation activities against multiple victims. During that time, Flax Typhoon routinely sent and received information from Integrity Tech infrastructure,” OFAC said.

“The actors maliciously used virtual private network software and remote desktop protocols to facilitate this access. In summer 2023, Flax Typhoon compromised multiple servers and workstations at a California-based entity.”

These sanctions follow a September 2024 court-authorized operation to disrupt a botnet of hundreds of thousands of consumer and small business devices in the U.S. and worldwide, tracked as “Raptor Train” and controlled by Integrity Tech (also known as Yongxin Zhicheng).

As the FBI revealed at the time, in coordination with the Cyber National Mission Force, NSA, and Five Eye partners, Flax Typhoon used this botnet for DDoS attacks and as a proxy to launch stealthy attacks against entities in the military, government, higher education, telecommunications, defense industrial base (DIB), and IT sectors, mainly in the U.S. and Taiwan.

Within four years of activity, since May 2020, Raptor Train grew into a massive, multi-tiered network with an enterprise-grade control system and infected over 260,000 networking devices, including routers and modems, NVRs and DVRs, IP cameras, and network-attached storage (NAS) servers.

“Integrity Tech is a large PRC government contractor with ties to the Ministry of State Security. It provides services to country and municipal State Security and Public Security Bureaus, as well as other PRC cybersecurity government contractors,” the State Department added today.

“PRC-based hackers working for Integrity Tech, known to the private sector as ‘Flax Typhoon,’ were working at the direction of the PRC government, targeting critical infrastructure in the United States and overseas.”

Following today’s sanctions, U.S. organizations and citizens are prohibited from conducting transactions with Integrity Tech (short for Integrity Technology Group, Incorporated). Additionally, any assets in the U.S. associated with them will be frozen. U.S. financial institutions and foreign entities that engage in transactions with them may also face penalties.

On Monday, the Treasury Department disclosed that unknown Chinese government threat actors had hacked its network. Since then, U.S. officials have stated that the attackers specifically targeted the agency’s OFAC department, likely to collect intelligence on future sanctions targeting Chinese individuals and organizations.

Another Chinese state-backed hacking group tracked as “Salt Typhoon” has also been linked to a wave of breaches impacting nine U.S. telecom firms, including Verizon, AT&T, and Lumen.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:54 am, Jan 16, 2025
weather icon 8°C
L: 6° | H: 8°
overcast clouds
Humidity: 92 %
Pressure: 1034 mb
Wind: 5 mph W
Wind Gust: 7 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:58 am
Sunset: 4:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
6° | 8°°C 0 mm 0% 4 mph 95 % 1034 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 4 mph 95 % 1035 mb 0 mm/h
Sat Jan 18 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 4 mph 89 % 1033 mb 0 mm/h
Sun Jan 19 9:00 pm
weather icon
1° | 6°°C 0 mm 0% 5 mph 93 % 1023 mb 0 mm/h
Mon Jan 20 9:00 pm
weather icon
3° | 8°°C 0 mm 0% 5 mph 95 % 1023 mb 0 mm/h
Today 3:00 am
weather icon
5° | 8°°C 0 mm 0% 3 mph 92 % 1033 mb 0 mm/h
Today 6:00 am
weather icon
5° | 7°°C 0 mm 0% 4 mph 93 % 1033 mb 0 mm/h
Today 9:00 am
weather icon
5° | 6°°C 0 mm 0% 3 mph 95 % 1034 mb 0 mm/h
Today 12:00 pm
weather icon
8° | 8°°C 0 mm 0% 4 mph 80 % 1034 mb 0 mm/h
Today 3:00 pm
weather icon
9° | 9°°C 0 mm 0% 3 mph 81 % 1033 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 4 mph 93 % 1034 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 3 mph 94 % 1034 mb 0 mm/h
Tomorrow 12:00 am
weather icon
4° | 4°°C 0 mm 0% 4 mph 95 % 1034 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€97,377.43
3.07%
Ethereum(ETH)
€3,312.06
5.29%
XRP(XRP)
€2.96
9.22%
Tether(USDT)
€0.97
0.05%
Solana(SOL)
€198.07
8.12%
Dogecoin(DOGE)
€0.366987
4.80%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000021
2.70%
Pepe(PEPE)
€0.000018
7.03%
Peanut the Squirrel(PNUT)
€0.63
7.18%
Scroll to Top