FBI Seizes 260,000-Device Botnet Operated by Chinese State Hackers
U.S. authorities take control of a massive botnet run by the Chinese hacking group Flax Typhoon to target critical infrastructure. The FBI successfully removes the malware despite attempted counterattacks from the hackers.
The FBI takes control of a massive botnet consisting of 260,000 compromised internet-connected devices, including cameras, routers, and storage systems. FBI Director Christopher Wray reveals that the botnet operates under a Chinese government hacking group known as Flax Typhoon. This network specifically targets critical infrastructure across the United States and internationally, threatening corporations, universities, media organizations, and government agencies.
Through court-authorized operations, U.S. authorities seize the botnet's infrastructure and actively remove the malware from the infected devices. When the hackers realize their network is compromised, they attempt to migrate their bots to new servers and launch a Distributed Denial of Service (DDoS) attack against the FBI. Despite these counterattacks, the law enforcement operation successfully neutralizes the immediate threat.
A joint advisory from the FBI, the Cyber National Mission Force, and the NSA links this botnet to Integrity Technology Group, a company that allegedly works on behalf of the Chinese government. The hackers use the Mirai malware to exploit vulnerable devices and conceal their operations within the large network. This takedown represents the latest U.S. effort to disrupt China-backed cyberattacks amid growing warnings from senior officials about potential real-world harm to Americans during a future conflict.