The Justice Department today announced a court-authorized law enforcement operation that disrupted a botnet consisting of more than 200,000 consumer devices in the United States and worldwide. As described in court documents unsealed in the Western District of Pennsylvania, the botnet devices were infected by People’s Republic of China (PRC) state-sponsored hackers working for Integrity Technology Group, a company based in Beijing, and known to the private sector as “Flax Typhoon.”
The botnet malware infected numerous types of consumer devices, including small-office/home-office (SOHO) routers, internet protocol (IP) cameras, digital video recorders (DVRs), and network-attached storage (NAS) devices. The malware connected these thousands of infected devices into a botnet, controlled by Integrity Technology Group, which was used to conduct malicious cyber activity disguised as routine internet traffic from the infected consumer devices.
Read more…
Source: U.S. Justice Department
Related:
- US using cyber warfare to fracture Islamic regime from within its ranks
March 1, 2026
The United States is using cyber operations not only to disrupt Iran’s military capabilities but to pressure senior regime officials to defect, a former top commander of US Cyber Command told The Jerusalem Post on Sunday, describing an information warfare campaign aimed at accelerating regime change from within. Using information warfare, Lt. Gen. Charles L. Moore Jr. ...
- US Military Used Anthropic AI to Crunch Intel and Pick Targets in Iran Strike, Despite Trump’s Ban
March 1, 2026
The US military reportedly used Anthropic’s Claude AI during a major strike in the Middle East against Iran, just hours after US President Donald Trump ordered all federal agencies to stop using the technology. According to WSJ, officials say the AI helped with intelligence analysis, spotting potential targets, and running ‘what-if’ battle scenarios. Even though Trump had ...
- Conduent data breach gets bigger, more than 25 million people across the US are now affected
February 26, 2026
A ransomware attack that caused a massive data breach for one of the largest government contractors in the U.S. keeps expanding. In early February, it was reported that 10 million people were impacted by the Conduent breach a year after it was discovered. Now though, it’s been revealed that the breach may affect more than 25 ...
- Threat intelligence supply chain is full of weak links, researchers find
February 25, 2026
Researchers from Georgia Tech have found that the supply chain for threat intelligence data is susceptible to adversarial action, and proposed a method to improve data sharing that they think will make it stronger. Brenden Kuerbis, a research scientist at the Georgia Tech’s School of Public Policy sketched the proposal on Monday by noting that in ...
- Anthropic ditches its core safety promise in the middle of an AI red line fight with the Pentagon
February 25, 2026
Anthropic, a company founded by OpenAI exiles worried about the dangers of AI, is loosening its core safety principle in response to competition. Instead of self-imposed guardrails constraining its development of AI models, Anthropic is adopting a nonbinding safety framework that it says can and will change. In a blog post Tuesday outlining its new policy, ...
- ShinyHunters demands $1.5M not to leak Vegas casino and resort chain data
February 20, 2026
Las Vegas hotel and casino giant Wynn Resorts appears to be the latest victim of data-grabbing and extortion gang ShinyHunters. On Friday, the cybercrime crew listed the hospitality company on its blog, claiming to have stolen more than 800,000 records containing employees’ Social Security numbers and other private details. The extortionists set a February 23 deadline ...
