DEV Community

Anoymask
Anoymask

Posted on

Flax Typhoon: MicroScan Scanned Japanese Airports; U.S. Seizes Seven Domains

1. Basic Information

2. Executive Summary

Flax Typhoon actors linked to Integrity Tech used a Mirai botnet and MicroScan to probe for vulnerabilities, employed FishHub for remote access and file theft following spearphishing, and U.S. authorities seized 7 domains.

3. Attack Flow

IoT Botnet Probing and FishHub Compromise

The following tactics were identified across multiple investigations. MicroScan probing and compromise, FishHub malware distribution, and SoftEther access persistence were not necessarily executed consecutively against the same victim.

  1. Integrity Tech-associated actors used a Mirai IoT botnet as a distributed probing infrastructure for MicroScan.
  2. MicroScan used over 1,300 scripts to search for vulnerabilities in public services.
  3. Clients exploited discovered vulnerabilities or gained initial access via FishHub spearphishing.
  4. FishHub deployed additional malware to perform remote access and specific file searches.
  5. FishHub-related malware sent files to attacker servers. Separately, at compromised systems in a Taiwanese university, persistence via SoftEther VPN was also confirmed.

4. Attacker Position and Execution Vector

  • State-sponsored actors target internet-facing critical infrastructure using IoT botnets, scanning platforms, and phishing delivery domains.

5. Victim and Administrator Perspective

  • Users: Malicious activity may resemble routine scanning or legitimate business email.
  • Administrators: Can observe distributed scanning, phishing, additional malware, SoftEther, specific file access, and data egress.

6. Conditions for Success and Failure

Success Conditions

  • The presence of exploitable vulnerabilities in public-facing services or successful phishing.
  • Execution of additional malware and remote access tools with permitted egress.

Failure Conditions and Countermeasures

  • Patch vulnerable internet-facing services and restrict unnecessary network access to reduce exposure to exploitation. Apply separate controls against spearphishing.
  • Detecting and blocking unauthorized VPNs, malware, specific file access, and data egress.

7. Outcomes of Successful Exploitation

  • Unauthorized access to critical infrastructure networks.
  • Remote command execution and long-term persistence.
  • Discovery and exfiltration of specific files.
  • Conversion of IoT devices into a botnet for additional scanning.

8. Observable Logs

The following items are candidates for internal investigation, and not all events were necessarily observed in this specific incident.

  • Email: Check for lookalike domains, spearphishing links or attachments, and delivery domains.
  • Proxy / SWG / DNS: Check for seized domains, FishHub delivery domains, malware downloads, and SoftEther control traffic.
  • Endpoint / EDR: Check for additional malware, specific file searches, archiving or staging, and SoftEther installation.
  • Identity / IdP: Check for logins from unusual locations, token and credential use, permission changes, and service account operations.
  • SaaS / Cloud: Check administrative APIs, audit logs, repository and cloud resource access, and large downloads.
  • Network: Check for MicroScan probes, distributed scanning originating from the Mirai botnet, and large outbound transfers.

9. Assessing Attack Success

Confirmed in Public Information

  • Attack attempts observed (success unconfirmed): Japanese and Polish airports were among the MicroScan targets. The cited sources document scanning of these airports but do not establish successful intrusion into them.
  • Subsequent compromises confirmed: Infiltration following MicroScan scans was documented for two Taiwanese universities. The scale of FishHub victims was reported by the DOJ as approximately 20 universities, while the seizure warrant affidavit states over 20 organizations (including 6 Taiwanese universities); the reason for these differing figures remains unclear.

Internal Assessment Criteria

  • Correlate requests, processes, authentication, data access, and outbound transmissions to distinguish between attack attempts and successes.
  • Do not determine success based solely on HTTP status codes or single alerts when not supported by public information.

10. Investigation Playbook

  • Investigation Origin: Start from published domains, distributed vulnerability scans, FishHub malware, and SoftEther installations.
  • Initial Verification: Verify target products, versions, configurations, external accessibility, exposure duration, and update/containment times.
  • Endpoint and Server Investigation: Check for malware, remote access, file searches, archiving, VPN services, and persistence.
  • Authentication and Cloud Investigation: Check for suspicious accounts, tokens, API usage, privilege changes, unusual connection sources, and resource access.
  • Subsequent Activity: Track credential access, lateral movement, additional downloads, outbound transmissions, and account creation following initial events.
  • Containment: Isolate compromised hosts and IoT devices, block domains and C2, and rotate credentials.
  • Categorization: Distinguish between scanning/attack attempts, initial execution, successful authentication, data theft, and subsequent compromises.

11. Defense and Detection Ideas

  • Single Events: Detect communications with seized domains, unauthorized SoftEther usage, and specific file search tools.
  • Chronological Correlation: Correlate scanning or phishing with subsequent malware execution, remote access, file searches, and outbound transfers where evidence links the events. Do not assume that every victim experienced the same sequence.
  • Threat Hunting: Search for DOJ/FBI IoCs, MicroScan patterns, FishHub domains, SoftEther, and Mirai traffic.
  • Log Limitations: The boundary between scanning and successful intrusion cannot be determined by network flow alone; endpoint and identity evidence is required.
  • Priority Countermeasures: Prioritize patching, asset inventories, phishing defenses, IoT isolation, prohibition of unauthorized VPNs, and egress monitoring.

12. Facts, Inference, and Hypothesis

Facts

  • The DOJ and FBI seized 7 domains via court-authorized seizures to deny access to MicroScan and FishHub.
  • Integrity Tech used an IoT botnet comprising over 200,000 devices infected with a Mirai variant (disrupted by U.S. authorities in September 2024) to probe targets with MicroScan, which features over 1,300 penetration-testing scripts.
  • MicroScan targets included U.S. electric utilities, airports in Japan and Poland, and gas and power companies as well as universities in Taiwan. This does not imply successful compromise of all named organizations.
  • The seizure warrant affidavit notes intrusions following MicroScan scans for two Taiwanese universities. The scope of FishHub victims was reported by the DOJ as approximately 20 Taiwanese universities, while paragraph 37 of the affidavit describes data and files from over 20 organizations, including 6 Taiwanese universities; the reason for these differing figures remains unclear.
  • FishHub downloaded additional malware following spearphishing, performed remote access, searched for specific files, and transmitted them to attacker-controlled servers.
  • SoftEther VPN was used to maintain remote access to compromised systems.

Inference

  • Because scanning sources are distributed across residential and IoT botnets, vulnerability probe patterns and asset exposure should be prioritized alongside IP reputation.
  • Because Japanese airports are included among the targets, aviation, transportation, and energy organizations should hunt through historical logs using MicroScan and FishHub IoCs.

Hypothesis

No additional hypotheses. Unconfirmed items are listed in "14. Open Questions and Additional Investigation".

13. MITRE ATT&CK Mappings

ID Technique Confidence Basis
T1595.002 Active Scanning: Vulnerability Scanning high Probed critical infrastructure vulnerabilities using MicroScan.
T1566 Phishing high FishHub facilitated network exploitation via spearphishing.
T1133 External Remote Services high Abused legitimate VPN software, SoftEther, to maintain persistent remote access to compromised systems.

14. Open Questions and Additional Investigation

  • Whether FishHub-related file exfiltration used an existing command-and-control channel.
  • Whether successful intrusions occurred after scans at Japanese airports, along with the targeted systems and timeframes.
  • The reason for the discrepancy in the number of victims and category definitions between the DOJ announcement and the seizure warrant affidavit regarding FishHub.
  • Complete samples of FishHub malware, initial phishing methods, credential theft, and compromised data.
  • Whether the actors migrated to alternative domains, tools, or botnets following the seizures.

15. Impact on SOCs and Organizations

Japanese airports are explicitly included among the scan targets. Critical infrastructure organizations should retroactively check for seized domains, MicroScan probes, FishHub delivery domains, and SoftEther installations, while investigating the correlation between internet-facing asset vulnerabilities and post-phishing file access.

16. Summary by Role

  • For SOCs: Correlate MicroScan probes, FishHub domains, malware downloads, SoftEther, specific file searches, and data egress.
  • For Administrators: Update internet-facing assets, restrict management planes, and eliminate unauthorized VPNs and IoT devices.
  • For Users: Avoid opening suspicious spearphishing links or attachments, and report emails impersonating airports or critical infrastructure.

Top comments (0)