US authorities announced on Thursday that they had disrupted two tools that, they say, Chinese state-sponsored hacking groups used against critical infrastructure in the US and other countries1. The tools are MicroScan, used for vulnerability scanning, and FishHub, used to break into networks through spear phishing; according to the US, both were built by Integrity Tech1. The US says a Mirai-variant IoT botnet supported reconnaissance, with targets including a US power company, Japanese and Polish airports and Taiwanese organisations1. The US seized domains the attackers used to access the tools1. A joint advisory from agencies in seven countries says MicroScan has been active since at least 2017, targeting services such as Apache Struts, Jenkins, WebLogic and WordPress1. Editorial takeaway: organisations should patch internet-facing services promptly and strengthen phishing resilience. It remains unclear how far the domain seizures will limit further attacks.
Industry news · security
US disrupts two hacking tools linked to Chinese state-sponsored groups
According to SecurityWeek, US authorities announced the disruption of Integrity Tech's MicroScan and FishHub tools, which the US says were used against critical infrastructure, and seized related domains[^1].
BlockSpam · 1 min read
Published:
Prepared with AI; checked before publication
Discussion
Comments appear after moderation. Do not post restricted material or personal data.
Sign in to participate