← Back to blog

FBI Disrupts Flax Typhoon's Critical Infrastructure Attacks

The FBI has seized domains linked to Flax Typhoon, a China-backed APT group targeting U.S. critical infrastructure. This operation disrupted ongoing cyber intrusions and intelligence-gathering activities.

TL;DR

  • FBI and DoJ seized 7 domains used by Flax Typhoon, a China-linked APT group.
  • The group was actively scanning and infiltrating U.S. critical infrastructure systems.
  • This takedown disrupts tools used for reconnaissance and initial compromise stages.
  • Flax Typhoon is known for persistent targeting of energy, water, and transportation sectors.
  • Organizations should review network logs for indicators from the seized domains.

The U.S. Federal Bureau of Investigation (FBI), working with the Department of Justice, has taken decisive action against Flax Typhoon, a sophisticated threat actor with ties to China. This group has been actively targeting American critical infrastructure, including energy, water, and transportation systems. Through coordinated domain seizures, federal agencies have disrupted the adversary's ability to conduct reconnaissance and establish initial access to vulnerable networks.

The operation represents a significant step in defending national infrastructure from state-sponsored cyber threats. By removing key components of Flax Typhoon's operational infrastructure, the FBI has limited the group's capacity to launch new attacks while investigators continue tracking their broader campaign. Security teams managing critical infrastructure assets should evaluate their exposure to these now-defunct domains and monitor for any residual indicators of compromise.

Operation Impact

  • Seven domains used by Flax Typhoon for command and control were seized by federal authorities.
  • The disrupted infrastructure was being used for both scanning and active infiltration attempts.
  • Blocking these domains prevents further use in the reconnaissance and initial access phases of attack.
  • Some targeted organizations had already been compromised prior to the takedown.

Defense Recommendations

  • Review DNS query logs for connections to the seized domains listed in the DOJ announcement.
  • Audit network perimeters for signs of scanning activity from associated IP addresses.
  • Strengthen authentication mechanisms on internet-facing critical systems.
  • Implement continuous monitoring for anomalous behavior indicative of APT activity.
  • Coordinate with CISA and FBI for threat intelligence specific to Flax Typhoon tactics.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

FBI Disrupts Flax Typhoon's Critical Infrastructure Attacks — Agent Breach Blog | Agent Breach