
FBI Seizes Seven Domains to Disrupt Integrity Technology Group's Microscan and Sparrow C2 for Flax Typhoon Botnet
FBI domain seizures targeted contractor-operated tooling behind Flax Typhoon intrusions but left the underlying botnet and PRC contractor architecture intact. Evidence from court filings shows 260,000 active devices and reusable open-source scanners that predate the operation by nearly a decade. The pattern favors temporary infrastructure swaps over structural disruption.
Court records show Integrity Technology Group operated the Raptor Train botnet variant of Mirai through the Sparrow application on infrastructure tied to 202.182.109.151, storing records for 1.2 million compromised devices as of June 2024. The Python-based Microscan tool, hosted at 198.13.53.226 and reachable via c0cc.cc, bundled 1,300+ exploit scripts plus open-source scanners to map targets in power, aviation, and academic sectors. FishHub enabled follow-on payload delivery after spear-phishing. Domain seizures alone leave the underlying contractor model untouched.
Procurement patterns and prior takedowns indicate Beijing-linked firms such as Integrity Technology Group function as scalable enablers rather than direct state units, allowing the PRC to expand reach while maintaining plausible separation. The September 2024 Raptor Train disruption already demonstrated rapid migration to new domains under w8510.com; the current operation repeats the same surface-level intervention without addressing the 385,000 U.S. devices previously logged or the continued availability of the same open-source reconnaissance stack.
Operational effect will be measured in weeks, not months. Operators retain the compromised device pool and can re-point C2 within the existing botnet footprint. Regulatory focus on domain seizures continues to prioritize visible disruption metrics over sustained degradation of contractor-enabled access operations.
Recorded Future: Flax Typhoon operators will restore >60% of prior active device count under new C2 domains within 60 days.
Sources (3)
- [1]DOJ Court Documents on Integrity Technology Group(https://www.justice.gov/usao-wdpa/pr/fbi-seizes-domains-disrupts-china-linked-botnet-operations)
- [2]Microsoft Threat Intelligence Report on Flax Typhoon(https://www.microsoft.com/en-us/security/blog/2024/09/flax-typhoon/)
- [3]FBI Pittsburgh Field Office Affidavit Details(https://www.fbi.gov/contact-us/field-offices/pittsburgh)