US seizes seven domains in fresh blow to China-linked hackers
The crackdown targets Integrity Technology Group’s hacking infrastructure as a joint advisory details tools used to breach critical infrastructure and browse stolen emails.

Spend less time finding cybersecurity news. Get more out of it.
Metacurity delivers the cybersecurity news, analysis, and insight that would take you hours—and sometimes days—to assemble yourself.
Every weekday, we sift through thousands of news articles, press releases, filings, court documents, and research reports, including details that vendor announcements and PR pitches leave out. We tell you what changed, why it matters, and what deserves your attention. Minimal vendor marketing. No outrage bait. No SEO filler.
A paid subscription gives you:
- The full Metacurity archive: Every newsletter, searchable and browsable.
- Our weekly long-reads roundup: The best cybersecurity writing from across the industry, selected and vetted to make your reading time count.
- Specialized reports and analysis: Periodic deep dives that go beyond the daily headlines.
- A direct role in sustaining independent journalism: Your subscription helps keep our editorial priorities focused on readers and the cybersecurity community.
If Metacurity saves you time, helps you spot an important development, or gives you a clearer understanding of the industry, please consider becoming a paid subscriber. Your support keeps that work going.
Subscribe today—and thank you for reading and supporting Metacurity.
US officials said they seized seven internet domains in a new effort to disrupt hackers working with Chinese IT firm Integrity Technology Group.
The Justice Department said the domains were being used to help Chinese hackers scan and hack US and foreign critical infrastructure systems.
The department said the move was the second public effort to disrupt Integrity Tech’s hacking infrastructure. In September 2024, the department announced the court-authorized disruption of an Integrity Tech botnet consisting of more than 250,000 compromised consumer devices in the United States and across the world.
In coordination with the domain seizures, the FBI, CISA, NSA, and international partners issued a joint cybersecurity advisory explaining how Chinese government-linked hackers used Integrity Tech's tools and infrastructure to compromise organizations and steal sensitive information.
The advisory says the attackers targeted US government agencies, critical manufacturing, healthcare, information technology, law enforcement, educational institutions, and religious organizations, as well as organizations in Southeast Asia, Africa, and North America.
The activity overlaps with operations tracked as Flax Typhoon, Ethereal Panda, and Red Juliett, although the agencies say that not all activity may necessarily be linked to Integrity Tech.
According to the advisory, MicroScan is a Python-based vulnerability scanner containing more than 1,300 penetration-testing scripts used to identify security flaws in websites and services.
These scripts targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, Jenkins, and other applications.
The attackers also used the open-source EBurst tool to conduct password-spraying attacks against Microsoft Exchange servers, along with other tools to steal emails, collect Active Directory credentials, and exfiltrate data.
The FBI also discovered a custom web application that let third parties browse stolen emails without needing direct access to the compromised accounts.
The joint advisory contains indicators of compromise, including IP addresses, domains, malware hashes, and details of the attackers' tools, to help organizations identify potential intrusions.
Authorities are urging organizations to review the indicators, patch vulnerable systems, disable unnecessary exposed services, and enforce multifactor authentication to protect against attacks.
This is not the first time US law enforcement disrupted Integrity Tech's hacking infrastructure.
In September 2024, the Justice Department disrupted an Integrity Tech-operated Mirai botnet consisting of more than 200,000 compromised consumer devices worldwide.
The UK government also sanctioned Integrity Tech in 2025, and the European Union sanctioned the company in 2026 for involvement in cyberattacks targeting Europe and its allies. (Raphael Satter and Laurie Chen / Reuters and Lawrence Abrams / Bleeping Computer)
Related: Justice Department, IC3, NSA, NCSC, The Record, Help Net Security, HackRead, Cyber Security News, Bleeping Computer, IT Pro
Oleg Korniev, a Ukrainian-Russian dual citizen, has pleaded guilty to running a massive money laundering operation that laundered millions for cybercriminals worldwide.
Korniev was one of the leaders of Your Mule Cashout (YMCO), a criminal organization that has operated since September 2007 and used more than 15,000 money mules from the United States.
Four other individuals who were involved with YMCO were arrested overseas more than a decade ago, extradited to the Western District of North Carolina, and pleaded guilty to conspiracy to commit money laundering. They received prison sentences ranging from 37 to 63 months and were also ordered to each pay more than $9.1 million in restitution to US victims.
Korniev managed, hired, and fired YMCO employees; rewarded or punished them based on performance; and helped develop policies and procedures for the money laundering operation.
According to court documents, YMCO recruited US residents as money mules through spam emails from fake companies, with each mule going through what appeared to be a legitimate hiring process and being told they would process payments for legitimate businesses.
Cybercriminals sent stolen money to the mules' bank accounts, and the mules allegedly wired the illicit funds through Western Union and MoneyGram to "cash-out contractors" in Moldova, Ukraine, Russia, or Latvia.
YMCO also allegedly ran similar schemes in Germany, Italy, the United Kingdom, and Australia, processing more than $10 million stolen by cybercrime gangs from over 750 US bank accounts at more than 35 banks.
"Money mules play crucial roles in cybercrime, so the Justice Department pursues mules and their recruiters wherever they operate and however long it takes," said Assistant Attorney General A. Tysen Duva.
On Thursday, Korniev pleaded guilty to money laundering, aggravated identity theft, conspiracy to commit money laundering, conspiracy to commit computer fraud, and conspiracy to commit access device theft.
Korniev now faces a minimum penalty of two years in prison and a maximum penalty of 50 years after admitting that the money laundering operation he ran with multiple accomplices was behind over $14.7 million in actual and intended losses to confirmed victims. (Sergiu Gatlan / Bleeping Computer)
Related: Justice Department
Maryland man Jonathan Spalletta was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021.
Spalletta (also known online as "Jspalletta" and "Cthulhon") surrendered to law enforcement on March 30 and was charged with computer fraud and money laundering.
According to court documents, Spalletta hacked Uranium (an automated market maker on Binance's BNB Chain) and stole nearly $53.3 million in cryptocurrency, forcing the company to shut down for lack of funds.
On April 8, 2021, during the first breach, he drained about $1.4 million out of Uranium's liquidity pool by exploiting a flaw in its smart contract code to issue zero-token withdrawal commands, which forced the exchange to pay rewards he wasn't entitled to.
Spalletta then extorted the crypto exchange into assigning a sham "bug bounty" of nearly $386,000 from the stolen funds to get the rest back.
Three weeks later, he hit Uranium again, exploiting a separate coding error that caused the exchange's transaction-verification logic to use 1,000 instead of 10,000 and allowed him to withdraw nearly 90% of the assets held in Uranium's liquidity pools while depositing effectively zero tokens.
This netted Spalletta about $53.3 million (most of Uranium's holdings) and forced the crypto exchange to shut down immediately. Next, Spalletta laundered the stolen cryptocurrency through the Tornado Cash cryptocurrency mixer and multiple decentralized exchanges.
The proceeds were spent buying 18 sealed packs of Alpha Booster Magic cards for around $1.5 million, a first-edition complete Pokémon base set for roughly $750,000, a "Black Lotus" Magic: The Gathering card for approximately $500,000, an ancient Roman coin commemorating Julius Caesar's assassination for over $601,000, among other items.
Law enforcement agents seized these collectibles from his residence in February 2025 and recovered roughly $31 million in cryptocurrency from crypto wallets linked to Spalletta.
Crypto fraud investigator ZachXBT first linked over 11,200 ETH withdrawn from Tornado Cash (worth $25 million at the time) to the Uranium hacker in December 2023. (Sergiu Gatlan / Bleeping Computer)
Related: Justice Department, Quartz, Gizmodo, CoinMarketCap, Decrypt, AFP

OpenAI defended its decision to fire three safety researchers, saying they had committed a “significant breach of trust.”
The AI lab said in a post on X that its decision to part ways with Jasmine Wang, Tomek Korbak and Mikita Balesni was not about the fact that they had raised safety concerns.
The three researchers who were let go from the company raised safety concerns in a letter addressed to OpenAI board members and its safety committees, which they posted on X on Thursday.
“We have become concerned that internal and external communications around our firing have made our former colleagues afraid to speak and operate in ways that, until last week, were an integral part of working at OpenAI,” the researchers’ letter reads.
AI safety concerns have ramped up in the past month following numerous cyber incidents caused by rogue AI systems and a flurry of calls for a slowdown from researchers at OpenAI, Anthropic and other companies developing the technology.
All three of the fired researchers had posted on X in September calling for labs to pace the frontier or highlighting safety concerns.
The decision came “after a thorough investigation found they violated clear policies on handling sensitive information,” OpenAI said.
The company added that it agrees with the ethos of the letter around “preserving the monitorability of frontier models.” It said it continues to invest significant resources in this area. (Kai Nicol-Schwarz and Michael Considine / CNBC)
Related: Fortune, The Indian Express, RuntimeWire, CNN, The Economic Times, BBC, The Verge, Engadget, Mikita Balesni blog, Digit, Business Insider, The Information, Wall Street Journal
Researchers at CrowdStrike report that the hacker suspected of infiltrating some of South Korea’s largest banks this month may have used AI tools to carry out the attacks from China.
The person used Anthropic’s Claude to conduct research and create a resume that likely belonged to the perpetrator of the cyber-intrusion, the US firm said. The profile identified the alleged attacker as a 26-year-old based in Guangdong, it said.
The report outlined the US firm’s findings in the wake of data breaches at multiple South Korean financial institutions last week. South Korean police are investigating the hacks, which are believed to have impacted some 68,000 people, including about 40,000 customers at Yegaram Savings Bank and 25,000 at Shinhan Bank.
“This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts,” CrowdStrike wrote. “While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated.”
An AI tool named ARTEX, developed in China for defensive purposes, was involved in the cyberattacks.
CrowdStrike said the suspected attacker likely used a Hong Kong-based IP address to target the Korean lenders. The person may have used DeepSeek’s V4.1 Flash — a model unveiled last month — along with tools released by Z.ai and Elon Musk’s x.AI. IP addresses linked to the hacks had hosted open directories containing Claude activity, CrowdStrike wrote. (Soobin Kim / Bloomberg)
Related: CrowdStrike, Wccftech, The Register, The Hacker News, Reuters, Infosecurity, Nikkei Asia, Cyber Security News, Kyodo News, Seeking Alpha
Several travel companies in Japan have reported potential data breaches, raising concerns that customers’ personal information might have been compromised amid a series of cyberattacks in the country.
The affected companies include Adventure, which operates the travel booking website Skyticket, travel agency H.I.S., and travel technology company Temairazu.
In the case of Skyticket, up to 14.64 million customer records may be at risk, approximately 4.13 million of which may include members’ login passwords, according to its operator. The company said Friday that data stored on internal servers and in the cloud had been accessed without authorization between Oct. 2 and Oct. 4.
Skyticket’s bus reservation service and business management system were also allegedly affected by unauthorized access between August and October.
Major travel agency H.I.S., meanwhile, said Wednesday that the passport information of up to 627 people might have been leaked following unauthorized access at its Thailand-based subsidiary, H.I.S. Tours.
H.I.S said the incident took place in December last year and that safety measures had been put in place but that an investigation later revealed passport information, including customers’ dates of birth and passport numbers, could have been compromised.
The company said the announcement was delayed because its manual investigation was complicated by large amounts of unrelated data being mixed in with personal information. (Maddie Baker / The Japan Times)
A cascade of cyberattacks has hit Japanese companies over the past few weeks, prompting the government to call for security checks as AI tools lower the barriers to large-scale hacking.
Data from cybersecurity company Trend Micro shows a higher than usual number of Japanese organizations reported breaches in September. Thirteen were reported on a single day, the most this year. Reports have continued to flow in, hitting household names from SoftBank Corp. to Daiwa Securities, one of the country’s largest brokerages.
Finance Minister Satsuki Katayama on Friday urged financial institutions to review their cybersecurity measures, while the Financial Services Agency also called for checks, including into third-party risks, and extra precautions when verifying users’ identity online.
The latest onslaught comes as AI tools that enable attacks are proliferating. According to Gambit Security, tools used to gain credit card details from e-commerce operators this summer cost an average of about $25.46 per strike.
The performance of open-weight AI models, which can be downloaded for free, is also improving. Yoji Watanabe, chief technology officer at Cyber Security Cloud, said cyberattacks are becoming something that “even amateurs can carry out.”
The company’s analysis of unauthorized-access logs suggests AI may be being used to manage and control multiple attack tools. Humans make the judgments while leaving “the small, tedious tasks to AI,” Watanabe said, adding that signs of this kind have been increasing since September. (Sarah Hilton / Bloomberg)
Related: Associated Press, Reuters, Seoul Economic Daily
Italy's Foreign Ministry said its website had come under cyber attack but security systems had successfully mitigated the threat, with no disruption to services.
The ministry offered no details on the nature of the attack nor did it identify any culprits behind the incident. (Alessia Pe / Reuters)
Related: Italian Ministry of Foreign Affairs, Silicon Republic, Verdict
Anthropic is launching a new cybersecurity initiative designed to bring its most powerful AI models and engineers to companies protecting power grids, water utilities, and other critical infrastructure called the Critical Infrastructure Defense Program.
Anthropic will provide its frontier AI models, on-site engineers, and threat research to companies already responsible for securing critical infrastructure systems.
Participating companies will use these resources to identify and fix vulnerabilities in their customers' systems.
The program's founding partners include Accenture, Booz Allen Hamilton, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.
Anthropic said several partners are already using Claude to fix vulnerabilities and help customers do the same.
Anthropic is also launching a free AI-powered vulnerability scanning service for open-source software projects, called OSS Scanner. (Sam Sabin / Axios)
Related: Anthropic, Anthropic, SiliconANGLE, CyberScoop, The Verge, Unite.AI, CyberScoop, The Information, The Register, Security Week, Cyber Press
The credential-hijacking Shai-Hulud worm has struck again, this time burrowing its way into a popular AI agent platform SDK.
Multiple security researchers reported that they had detected Shai-Hulud infection in a recent release of the npm package for version 0.5.144 of Tensorlake’s SDK. That package has somewhere in the neighborhood of 12,000 downloads per week, while its GitHub repository has more than a thousand stars, suggesting it’s quite popular and that the infection could pose a serious risk to anyone who installed the malicious version.
Analysis of the malicious release suggests it shares code and techniques with the Shai-Hulud variant dubbed ChainDrop by researchers, which was used in August to compromise npm dependencies including keyv and flat-cache. Like other variants of Shai-Hulud, the worm is designed to steal credentials and self-propagate.
This particular version, according to supply chain security firm SafeDep, is designed to steal everything from crypto wallets to browser passwords, GitHub Actions secrets, cloud credentials, service-account tokens, and whatever else it can get its hands on. It exfiltrates that data and keeps an open line to its C2 infrastructure to await further instructions.
To make matters worse, this Shai-Hulud variant monitors certain stolen GitHub tokens and, if one is revoked, can trigger the deletion of the infected user's home directory under specific conditions, making removal tricky. Socket recommends rebuilding compromised systems from a trusted source before restoring access to secrets, while researchers warn that the malicious token monitor should be disabled before revoking affected credentials. (Brandon Vigliarolo / The Register)
Related: Aikido, SC Media, Cyber Press, Endor Labs, Techzine, SafeDep, Sonatype, Step Security
Researchers at Bitdefender report that a malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.
The malware is believed to have been introduced somewhere in the device supply chain, but it remains unclear who is responsible for modifying the firmware or at what stage the tampering occurred.
The malware is embedded directly into the firmware of low-cost Android devices using MediaTek chipsets, giving it system-level privileges that allow it to install and remove applications, grant sensitive permissions, and execute remotely downloaded code without user interaction.
The campaign affected thousands of devices across more than 150 countries over approximately two years, with the highest number of victims in Mexico, France, Italy, the United States, Germany, Brazil, and Spain.
The researchers found preinstalled malware on devices with model names associated with legitimate manufacturers, including the Doogee S200 X and Cubot KINGKONG X, as well as phones impersonating Samsung and Apple products.
Unlike typical Android malware that requires users to install a malicious application, Midnight Mimosa is already installed in the device's system partition when customers receive their phones.
The malicious programs impersonate legitimate Android system packages, using names such as com.android.system.lite, com.android.sys.prot, and com.android.sys.gmsprot.
Because these applications are signed and run with elevated system privileges, they cannot be removed through Android's normal application uninstall process. (Lawrence Abrams / Bleeping Computer)
Related: Bitdefender, Android Headlines, Android Police, HackRead, Cybersecurity Insiders, The Record, xda Forums

The Trump administration completed another major transaction involving seized cryptocurrency hours after moving a significant amount of Bitcoin to a Coinbase Prime wallet.
Blockchain data showed that a wallet associated with crypto seized by the US government had transferred more than 12,267 Bitcoin (BTC), worth more than $1 billion at the time of publication. The move came just hours after similar transfers from the government totaling $770 million in BTC to a Coinbase Prime wallet.
Arkham Research linked the wallet moving the Bitcoin to the recovery of funds from the 2016 Bitfinex hack, in which hackers stole 119,756 BTC. The identity of the owner of the recipient address was unknown at the time of publication.
Estimates suggest the US government held 328,372 BTC as of 2026, resulting from seized assets in criminal cases and investigations. US President Donald Trump signed an executive order in March 2025 establishing a strategic Bitcoin and crypto reserve, but lawmakers are still attempting to codify the order into law. (Turner Wright / Cointelegraph)
Related: CoinMarketCap
The US Federal Communications Commission said it will vote on October 29 to bar all Chinese labs from testing electronic devices such as smartphones, cameras and computers for use in the US, widening a previous action targeting Beijing.
The FCC said it will prohibit test labs and certification bodies in countries including China that deny reciprocal treatment to US-based test labs.
The FCC prohibitions are slated to take effect in December 2028.
In 2025, the FCC banned testing of US electronics by labs owned or controlled by the Chinese government, and several dozen labs were barred. But the agency said this year that a substantial majority of China-based test labs were still testing US electronics. (David Shepardson / Reuters)
Related: Federal Communications Commission
In a report produced as part of its ongoing inquiries into foundation AI models, the UK's Information Commission (formerly Information Commissioner’s Office, ICO) has outlined its findings to date.
The report states that AI models themselves may contain personal data and can therefore be subject to data protection law. A key question is when and how that law should apply.
“Special category data merits specific protection under data protection law because its use can create significant risks to people's fundamental rights and freedoms,” the report states.
It cites social media posts as an example, noting that they may reveal political opinions, religious beliefs or health information that could later be output by a model.
It says it is taking steps to address this challenge by identifying conditions potentially applicable to special category data processed for foundation model training.
The ICO acknowledges the difficulties developers face in ensuring that training data is GDPR-compliant, but insists that processing must still comply with principles such as data minimization and transparency.
The regulator pushes back against developers' arguments that broad objectives such as "benefitting humanity" can justify the use of personal data for model training.
The regulator adds that transparency around training data remains poor, accusing AI developers of relying on "vague or imprecise language" in privacy notices and failing to explain clearly how personal data is used.
The report also notes the danger to personal information posed by agentic AI in light of the Hugging Face incident, warning: “These incidents … demonstrate that AI systems can cause real-world harm, including the potential for models to autonomously access and exfiltrate personal data (and potentially special category data).”
The ICO says it has secured commitments from ten of the world's largest foundation model developers to improve data protection.
Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI have “made, or committed to make, data protection changes,” it says.
One frontier developer, X.AI, is notable by its absence. The ICO suspended engagement after opening a formal investigation into X and X.AI over the Grok nudification scandal. (John Leonard / Computing)
Related: ICO, Infosecurity Magazine, ghacks, The Next Web
Best Thing of the Day: It's Probably Bad for Your Soul to Abuse Claude Anyway
Anthropic's new usage policy prohibits “sustained and needless abusive or cruel behavior” toward Claude.
Worst Thing of the Day: How Did We Get to This Point?
Top executives at Anthropic, OpenAI, and other AI companies are privately gaming out what they would do if their technologies led to a large-scale event, most likely a cyberattack, that shuts down access to financial services, internet connectivity, or even power and water.
Closing Thought
