Back to Intelligence

Flax Typhoon MicroScan/FishHub Disrupted: Detect and Evict Chinese State-Sponsored C2 in Critical Infrastructure

SA
Security Arsenal Team
October 10, 2026
10 min read

The FBI’s seizure of seven domains attributed to the Chinese state-sponsored actor tracked as Flax Typhoon is a useful disruption, not a termination. Reporting indicates those domains supported two operational tools — MicroScan and FishHub — used in intrusions that reached critical infrastructure and other organizations globally. The immediate defensive risk is twofold: first, any environment that previously communicated with the seized infrastructure may still contain implants, scheduled tasks, stolen credentials, or proxy persistence; second, the actor will almost certainly migrate command-and-control, replace burned domains, and re-enable access through previously established footholds.

No CVE identifier, affected product version, or CVSS score was provided in the public summary. Treat this as a confirmed active nation-state campaign, not a single patch Tuesday problem. Your priority is retrospective hunting over DNS, proxy, NetFlow, firewall, EDR, and identity telemetry; hard egress control for servers and OT-adjacent assets; and credential/session invalidation where exposure is plausible.

Technical Analysis

Attribution and tooling. Public reporting names Flax Typhoon, MicroScan, and FishHub, and states that the FBI seized seven domains used to operate the tooling. The exact domain names were not included in the provided summary; do not invent indicators. When the FBI, CISA, or a trusted ISAC publishes the seized-domain list, pivot immediately on historical DNS and proxy logs rather than waiting for endpoint alerts.

Likely defensive observable pattern. Based on the described function — named scanning/access tooling operated through seized domains — defenders should look for behaviors that remain useful even after domains change:

  • Reconnaissance and scanning: bursts of connection attempts to many hosts/ports from a small number of internal systems, especially servers, appliances, jump hosts, or unmanaged devices that should not scan peers.
  • C2 through web-like channels: low-and-slow outbound HTTPS/DNS from endpoints using living-off-the-land binaries such as PowerShell, WMI, rundll32, mshta, certutil, bitsadmin, curl, or wget.
  • Domain replacement after seizure: sudden failure of repeated outbound connections followed by new rare domains, newly observed IPs, changed TLS certificate issuers, or altered beacon intervals.
  • Critical infrastructure exposure: any IT/OT boundary host, historian jump box, remote access gateway, vendor support system, or engineering workstation with both outbound Internet access and reachability to operational segments.
  • Credential and session reuse: impossible travel, new service principals, abnormal LSASS access, unexpected remote logons after scanning, or authentication to sensitive assets from hosts that recently showed egress anomalies.

Exploitation status. The summary describes breaches and worldwide operations, so exploitation is active/in-the-wild at the campaign level. It does not state inclusion in CISA KEV and does not disclose a specific vulnerable product. Validate against the current CISA KEV catalog separately, but do not wait for a KEV entry to hunt for the behaviors above.

Detection & Response

The rules below intentionally avoid fabricated domains or hashes. They target durable behaviors: LOLBin egress, encoded download cradles, suspicious scanning, and post-disruption infrastructure migration. Tune thresholds to your asset inventory before broad deployment.

YAML
---
title: Flax Typhoon Style LOLBin Outbound C2 to Public Network
id: 9b2f6a41-7c35-4d8e-a21b-5f0a9c7e2d11
status: experimental
description: Detects common Windows living-off-the-land processes initiating outbound network connections to non-private destinations, consistent with web-based C2 after domain infrastructure changes.
references:
  - https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/
  - https://attack.mitre.org/techniques/T1071/001/
  - https://attack.mitre.org/techniques/T1105/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.command_and_control
  - attack.t1071.001
  - attack.t1105
logsource:
  category: network_connection
  product: windows
detection:
  selection:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wmic.exe'
      - '\rundll32.exe'
      - '\mshta.exe'
      - '\certutil.exe'
      - '\bitsadmin.exe'
      - '\curl.exe'
      - '\wget.exe'
  filter_private:
    DestinationIp|startswith:
      - '10.'
      - '172.16.'
      - '172.17.'
      - '172.18.'
      - '172.19.'
      - '172.20.'
      - '172.21.'
      - '172.22.'
      - '172.23.'
      - '172.24.'
      - '172.25.'
      - '172.26.'
      - '172.27.'
      - '172.28.'
      - '172.29.'
      - '172.30.'
      - '172.31.'
      - '192.168.'
      - '127.'
      - '169.254.'
  condition: selection and not filter_private
falsepositives:
  - Admin automation, package managers, and update tooling; baseline by host role and approved egress destinations.
level: medium
---
title: Encoded PowerShell Download Cradle With Transfer Utility
id: 41d8c0aa-2e77-4b5f-9f34-8b1de6c905aa
status: experimental
description: Detects encoded or obfuscated command execution combined with common download/transfer strings, a repeatable pattern for staging state-sponsored tooling after initial access.
references:
  - https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/
  - https://attack.mitre.org/techniques/T1059/001/
  - https://attack.mitre.org/techniques/T1027/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.execution
  - attack.defense_evasion
  - attack.t1059.001
  - attack.t1027
logsource:
  category: process_creation
  product: windows
detection:
  selection_encoded:
    CommandLine|contains:
      - ' -enc'
      - ' -e '
      - '-encodedcommand'
      - 'frombase64string'
      - 'downloadstring'
  selection_transfer:
    CommandLine|contains:
      - 'invoke-webrequest'
      - 'iwr '
      - 'curl.exe'
      - 'certutil -urlcache'
      - 'bitsadmin /transfer'
      - 'wget '
  condition: selection_encoded and selection_transfer
falsepositives:
  - Legitimate admin scripts and software deployment; review parent process, user context, and destination.
level: high
KQL — Microsoft Sentinel / Defender
// Hunt 1: LOLBin or scripting egress to rare public destinations after C2 disruption
let Lookback = 14d;
let RareThreshold = 5;
let LolBins = dynamic(["powershell.exe","pwsh.exe","wmic.exe","rundll32.exe","mshta.exe","certutil.exe","bitsadmin.exe","curl.exe","wget.exe"]);
DeviceNetworkEvents
| where TimeGenerated >= ago(Lookback)
| where RemoteIPType == "Public"
| where InitiatingProcessFileName in~ (LolBins)
| summarize Connections=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Ports=make_set(RemotePort), Account=any(InitiatingProcessAccountName), Command=any(InitiatingProcessCommandLine) by DeviceName, RemoteIP, RemoteUrl, InitiatingProcessFileName
| summarize DestinationsPerProcess=count(), TotalConnections=sum(Connections), SampleCommand=any(Command), Account=any(Account) by DeviceName, InitiatingProcessFileName
| where DestinationsPerProcess <= RareThreshold or TotalConnections >= 200
| join kind=leftouter (DeviceInfo | project DeviceName, DeviceGroup=DeviceGroup, OSPlatform, MachineGroup) on DeviceName
| project DeviceName, OSPlatform, InitiatingProcessFileName, DestinationsPerProcess, TotalConnections, Account, SampleCommand
| order by TotalConnections desc;
// Hunt 2: Firewall/syslog view of internal scanning bursts toward critical infrastructure ranges
CommonSecurityLog
| where TimeGenerated >= ago(7d)
| where DeviceAction in~ ("allow","allowed","permit") or isnull(DeviceAction)
| summarize Targets=dcount(DestinationIP), Ports=dcount(DestinationPort), Events=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated) by SourceIP, DeviceVendor, DeviceProduct
| where Targets > 50 or Ports > 25
| order by Targets desc;
VQL — Velociraptor
-- Flax Typhoon response: enumerate processes with public sockets and LOLBin-style command lines
LET suspicious_proc(name, cmdline) = name =~ '(?i)(powershell|pwsh|wmic|rundll32|mshta|certutil|bitsadmin|curl|wget)' OR cmdline =~ '(?i)(-enc|frombase64string|downloadstring|bitsadmin /transfer|certutil -urlcache)'
SELECT Proc.Pid AS Pid, Proc.Name AS ProcessName, Proc.CommandLine AS CommandLine, Proc.Exe AS ExePath, Proc.Username AS Username, Proc.CreateTime AS ProcessStart, Conn.LocalAddr AS LocalAddr, Conn.RemoteAddr AS RemoteAddr, Conn.Status AS SocketStatus
FROM foreach(row={ SELECT * FROM pslist() WHERE suspicious_proc(Name, CommandLine) }, query={ SELECT * FROM netstat() })
WHERE Conn.Pid = Proc.Pid AND NOT Conn.RemoteAddr =~ '^(10\.|192\.168\.|127\.|169\.254\.|172\.(1[6-9]|2[0-9]|3[0-1])\.)'
ORDER BY ProcessStart DESC
PowerShell
# Run as administrator on Windows servers, jump hosts, and suspected endpoints. Audit-first; review before blocking.
$OutDir = "$env:ProgramData\FlaxTyphoonHunt"
New-Item -ItemType Directory -Force -Path $OutDir | Out-Null

# Enable PowerShell visibility and protected process logging where supported
New-Item -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging" -Force | Out-Null
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging" -Name "EnableScriptBlockLogging" -Value 1
New-Item -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ModuleLogging" -Force | Out-Null
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ModuleLogging" -Name "EnableModuleLogging" -Value 1
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Lsa" -Name "RunAsPPL" -Value 1 -ErrorAction SilentlyContinue

# Disable legacy SMBv1 if present
Set-SmbServerConfiguration -EnableSMB1Protocol $false -Confirm:$false -ErrorAction SilentlyContinue
Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol -NoRestart -ErrorAction SilentlyContinue

# Collect persistence and execution artifacts for IR triage
Get-CimInstance Win32_StartupCommand | Export-Csv "$OutDir\startup_commands.csv" -NoTypeInformation
Get-CimInstance Win32_Service | Select-Object Name, DisplayName, State, StartMode, PathName, StartName | Export-Csv "$OutDir\services.csv" -NoTypeInformation
Get-ScheduledTask | ForEach-Object { $_ | Select-Object TaskName, TaskPath, State, @{n='Actions';e={($_.Actions.Execute + ' ' + $_.Actions.Arguments)}} } | Export-Csv "$OutDir\scheduled_tasks.csv" -NoTypeInformation
Get-NetTCPConnection -State Established | Where-Object { $_.RemoteAddress -notmatch '^(10\.|192\.168\.|127\.|169\.254\.|172\.(1[6-9]|2[0-9]|3[0-1])\.)' } | Export-Csv "$OutDir\public_tcp_connections.csv" -NoTypeInformation
wevtutil epl Security "$OutDir\Security.evtx"
wevtutil epl System "$OutDir\System.evtx"

# Verify Defender core controls; do not disable tamper protection via script
Get-MpPreference | Select-Object DisableRealtimeMonitoring, DisableBehaviorMonitoring, DisableIOAVProtection, DisableScriptScanning, PUAProtection | Export-Csv "$OutDir\defender_prefs.csv" -NoTypeInformation
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntivirusEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, NISEnabled, RealTimeProtectionEnabled, IsTamperProtected | Export-Csv "$OutDir\defender_status.csv" -NoTypeInformation

Write-Output "Artifacts collected in $OutDir. Review services/tasks/public connections before containment."
Bash / Shell
#!/usr/bin/env bash
# Egress validation for Linux servers and sensor-adjacent systems. Test in a maintenance window.
set -euo pipefail

echo "[1/5] Show current outbound policy and listening services"
ss -lntup || true
ufw status verbose || true
nft list ruleset 2>/dev/null | head -200 || true

echo "[2/5] Recommended default: deny direct egress except approved proxy/DNS/NTP"
echo "ufw default deny outgoing"
echo "ufw allow out to <internal_dns_1> port 53 proto udp"
echo "ufw allow out to <internal_dns_2> port 53 proto udp"
echo "ufw allow out to <proxy_ip> port 3128 proto tcp"
echo "ufw allow out to <ntp_ip> port 123 proto udp"

echo "[3/5] Validate direct web egress fails from servers that must use proxy"
curl -I --max-time 5 https://example.com || echo "Direct HTTPS blocked as expected"
curl -I --max-time 5 --proxy http://<proxy_ip>:3128 https://example.com || true

echo "[4/5] Detect recent unusual outbound connect attempts"
last -a | head -50
journalctl --since "14 days ago" | grep -Ei 'curl|wget|nc |ncat|bash -i|/dev/tcp|powershell|certutil|bitsadmin' | tail -200 || true

echo "[5/5] DNS guardrail: ensure only approved resolvers are configured"
grep -R "^nameserver" /etc/resolv.conf /run/systemd/resolve/resolv.conf 2>/dev/null || true
resolvectl status 2>/dev/null | sed -n '1,80p' || true

Remediation

  1. Get the official seized-domain list before IOC blocking. Use FBI/CISA/ISAC releases for the seven domains. Do not rely on screenshots or reposted indicators without provenance. When published, search historical DNS, proxy, TLS SNI, NetFlow, EDR network events, and mail gateway logs for at least the last 12 months where retention allows.

  2. Assume migration and hunt behaviorally. Domain seizure typically causes short-term C2 failure and rapid reconstitution. Watch for repeated failed egress followed by new rare destinations, changed beacon timing, new TLS issuers, or fallback channels such as DNS tunneling and legitimate cloud storage.

  3. Contain candidate hosts safely. For any asset with suspicious LOLBin egress plus critical-infrastructure reachability: isolate from the network, preserve memory if feasible, collect triage artifacts, capture firewall/DNS/proxy logs for the host, and disable local accounts used by the process. Do not wipe before credential scope is understood.

  4. Reset credentials and sessions in a deliberate order. Prioritize accounts on suspected hosts, service accounts with interactive logons, vendor remote-access accounts, domain/enterprise admins if tier-0 exposure is possible, API tokens, SSH keys, and cloud refresh tokens. Revoke sessions before password resets where IdP token theft is plausible.

  5. Enforce egress by default. Servers, OT DMZ assets, jump hosts, appliances, printers, cameras, and engineering workstations should not have arbitrary outbound 80/443/53. Force web traffic through authenticated proxy with TLS inspection where lawful and operationally safe; restrict DNS to approved resolvers; alert on direct egress attempts.

  6. Segment critical infrastructure. Deny workstation-to-OT, server-to-OT, and vendor-to-OT paths by default; require brokered access through a jump host with MFA, recording, file-transfer control, and time-bound approval. Validate that historians, HMIs, PLCs, safety systems, and engineering laptops cannot be reached from general user VLANs.

  7. Reduce scanning blast radius. Block inbound scanner traffic at the edge, rate-limit repeated connection attempts, alert on internal sweep behavior, and investigate any asset that initiates broad port discovery. Treat unexpected scanning as an incident trigger, not background noise.

  8. Harden Windows execution and logging. Enable PowerShell Script Block/Module Logging, process command-line auditing, LSASS protection, Defender ASR where compatible, tamper protection, and attack surface reduction for Office/script abuse. Forward logs to a tamper-resistant SIEM with retention aligned to IR needs.

  9. Check exposure management separately. Although this news item provides no CVE, continue prioritizing internet-facing VPN, firewall, remote access, identity, and appliance patches using CISA KEV and vendor advisories. Reference points: https://www.cisa.gov/known-exploited-vulnerabilities-catalog, https://www.cisa.gov/china, https://www.fbi.gov/investigate/cyber, and https://www.ic3.gov/.

  10. Brief leadership with concrete evidence. Report affected assets, observed C2 timing, credentials reset, segments isolated, external exposure closed, and residual risk. The business question after a takedown is not “are we safe now,” but “what access survived the disruption, and how fast can we prove eviction.”

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.