The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon.

To that end, the agencies seized several domains and blocked access to platforms that were used to scan, and in some cases infiltrate, U.S. critical infrastructure.

According to the FBI, the botnet is said to have used a number of domains, including subdomains of w8510[.

In all, more than 260,000 devices, including approximately 126,000 U.S. devices, were actively infected as of June 5, 2024.

The botnet made use of a tool called Microscan to facilitate reconnaissance and computer vulnerability scanning, allowing the threat actors to identify targets of interest.