In a significant crackdown on global cyber threats, the United States has seized seven internet domains connected to a widespread Chinese hacking operation. In a statement issued on Thursday, the US Justice Department revealed that these domains were being used by hackers to aggressively scan and breach critical infrastructure systems in the United States and across the world. The hacking operation has been traced back to individuals working with a Chinese IT firm known as Integrity Technology Group.

The FBI has directly linked Integrity Technology Group to a notorious state-sponsored hacking collective nicknamed Flax Typhoon. According to previous statements by the FBI, the tech company has been carrying out extensive intelligence collection and reconnaissance operations for Beijing's security agencies.

Thursday's domain seizure marks the US government's second public effort to dismantle Integrity Tech's dangerous cyber infrastructure. Back in September 2024, the Justice Department successfully disrupted a massive botnet run by the very same group. That network had hijacked more than 250,000 consumer devices worldwide, including everyday gadgets like home Wi-Fi routers and smart cameras, using Mirai malware to launch automated cyberattacks.

The FBI and the Cybersecurity and Infrastructure Security Agency released a detailed advisory on how Flax Typhoon managed to infiltrate targeted networks. The group used large-scale botnets and automated tools to constantly hunt for weak spots in enterprise networks, frequently went after Microsoft Exchange servers using password-guessing and malicious scripts, and planted scripts to steal sensitive emails and user passwords once inside. They also relied heavily on VPN software to blend in and stay hidden within victim networks for extended periods.

By seizing these seven internet domains, US officials have essentially severed the main communication lines the hackers used to control their cyber tools. The FBI is now actively investigating the broader network in coordination with global partners, including the National Police Agency of Japan.

The Chinese Embassy in Washington did not immediately respond to requests for comment after business hours on Thursday. However, Beijing routinely denies any involvement in state-sponsored hacking operations.

For IT administrators and companies wanting to safeguard their digital borders, cybersecurity authorities recommend three fundamental security steps: turning on multi-factor authentication across all digital services and remote access points, closing unused internet ports and file-sharing protocols that businesses do not actively need, and immediately applying the latest software security patches to block hackers from injecting malicious code into systems.