Saudi Press

Saudi Arabia and the world
Friday, May 22, 2026

FBI Hacks Vulnerable US Computers in Sweeping Takedown of Malware Blamed on China

FBI Hacks Vulnerable US Computers in Sweeping Takedown of Malware Blamed on China

Software giant Microsoft accused China of orchestrating a hack attack in March, alleging that a “state-sponsored threat actor” referred to as “Hafnium” had taken advantage of multiple security vulnerabilities in Microsoft’s email service software to steal data.

The Federal Bureau of Investigation (FBI) has been hacking into “hundreds” of vulnerable computers of US companies to remove malware from their software, the US Department of Justice (DOJ) announced on Tuesday.

The operation, approved by a federal court, presupposed wiping out “back doors” into American-based servers that were earlier exposed to malware by a Microsoft Exchange vulnerability identified by the company, reported The Washington Post.

“Today’s court-authorised removal of the malicious web shells demonstrates the Department’s commitment to disrupt hacking activity using all of our legal tools, not just prosecutions,” Assistant Attorney General John C. Demers of the Justice Department’s National Security Division said in a statement.

With the hacking operation still ongoing, the DOJ said it was “committed to playing its integral and necessary role in such efforts.”

HackersExploit 'Flaws'


The move comes after Microsoft accused Chinese hackers of carrying out a massive and sophisticated cyber attack on its Exchange email service in March.

The software giant claimed that a “state-sponsored threat actor” referred to as “Hafnium” had exploited multiple security flaws in Microsoft’s email service software – now fixed – to steal data and plant malware from January 2021.

China dismissed the claims, with Chinese Foreign Ministry Spokesman Wang Wenbin saying Beijing “firmly opposes and combats cyber attacks and cyber theft in all forms,” and warning that blaming any nation without providing evidence is a “highly sensitive political issue."

Sweeping ‘Takedown’


In line with the sweeping recent "takedown," the FBI ran insecure versions of Microsoft software in order to patch the flaws, in other words, exploiting the same weaknesses in the servers that have still not been fixed to preclude further hacking attacks.

Cyber space


The shells removed by law enforcement “each had a unique file path and name, they may have been more challenging for individual server owners to detect and eliminate than other web shells,” according to the DOJ.

US officials and Microsoft claim the damage from the major security flaw allowed hackers to infiltrate the servers of at least 30,000 American organisations.

While removing malware placed by one hacker group, the operation carried out by the FBI stopped short of actively fixing the underlying vulnerability.

This leaves the affected computers vulnerable to malware in the future, unless their owners take action to protect them. The FBI is “attempting” to notify all the owners, it added.

Newsletter

Related Articles

Saudi Press
0:00
0:00
Close
The Great Western Exit: Why Best Citizens Are Fleeing the Rich World [PODCAST]
The New Robber Barons of Intelligence: Are AI Bosses More Powerful Than Rockefeller?
The AI Gold Rush Is Coming for America’s Last Open Spaces [Podcast]
The Pentagon’s AI Squeeze: Eight Tech Giants Get In, Anthropic Gets Shut Out [Podcast]
The War Map: Professor Jiang’s Dark Theory of Iran, Trump, China, Russia, Israel, and the Coming Global Shock [Podcast]
AI Isn’t Stealing Your Job. It’s Dismantling It Piece by Piece.
Kennedy’s Quiet War on Antidepressants Sparks Alarm Across America’s Medical Establishment
Russian Oligarch’s Superyacht Crosses Hormuz via Iran-Controlled Route
Crypto Scammers Capitalize on Maritime Chaos Near the Strait of Hormuz: A Rising Threat to Shipping Companies
Changi Airport: How Singapore Engineered the World’s Most Efficient Travel Experience
News Roundup
Microsoft lost 2.5 millions users (French government) to Linux
Strategic Saudi-Bahrain Causeway Closed Amid Security Concerns as Trump Deadline Approaches
Saudi Arabia Keeps Red Sea Oil Exports Flowing Despite Regional Tensions
Pipeline Attack Cuts Significant Share of Saudi Arabia’s Oil Export Capacity
Saudi Business Leader Abudawood Appointed Chairman of Merit Incentives Group
TotalEnergies Confirms Damage at Saudi Refinery Following Security Incident
Saudi Arabia Launches Early Construction Phase for King Salman Stadium Project
Saudi Shift Away from Longstanding Dollar Oil Framework Gains Attention Amid Iran Conflict
Türkiye and Saudi Arabia Resolve Long-Running Transit Visa Dispute
Saudi Oil Capacity and Pipeline Flows Reduced as Supply Risks Intensify
TotalEnergies Reports Damage to Saudi SATORP Refinery Following Security Incidents
Gulf States Assess Prospects of U.S.-Iran Truce as Regional Stability Efforts Intensify
South Korea Resumes Honey Exports to Saudi Arabia Following Sanitary Approval
Saudi Arabia Carries Out Sentences in Eastern Province Following Security Convictions
Saudi Sovereign Wealth Fund Backs King Street’s Regional Credit Strategy
Saudi Arabia Secures World Cup Return as Egypt Celebrates Landmark Qualification
Iran and Saudi Arabia Intensify Diplomatic Engagement Amid Regional Tensions
Russia and Saudi Arabia Open Visa-Free Travel Corridor for Citizens
Saudi Oil Output Capacity Reduced by 600,000 Barrels Per Day Amid Regional Conflict
Saudi Arabia Suspends Operations at Select Energy Sites as Precautionary Measure
Saudi Arabia Halts Operations at Multiple Energy Facilities Amid Heightened Tensions
Global Markets Jolt as Iran Signals Ceasefire Breakdown and Rising Regional Tensions
King Street Aligns with Saudi Sovereign Wealth Fund to Expand Alternative Investments in Middle East
Attack on Saudi Arabia’s Jubail Petrochemical Hub Raises Global Supply Concerns
Debate Emerges Over Saudi Strategic Decisions as Gulf Cooperation Council Dynamics Come Into Focus
Saudi Arabia Expands Full Workforce Localisation to 69 Professions in Major Labour Reform
Emerging Alliance of Pakistan, Turkey, Egypt and Saudi Arabia Signals New Regional Power Dynamic Amid Iran Conflict
Iran Linked to Strikes Across Gulf States Following Refinery Attack Escalation
Saudi Arabia Voices Concern Over Fragile US–Iran Ceasefire Stability
Starmer Warns Sustained Effort Needed to Ensure US–Iran Ceasefire Holds
Saudi Arabia’s Key East-West Oil Pipeline Targeted Following Ceasefire Announcement
Iran Targets Saudi Arabia’s East-West Oil Pipeline in Escalating Regional Tensions
Trump Warns of Civilizational Stakes as Iran Halts Negotiations
Saudi Companies Expand Remote Work Measures Ahead of Iran-Related Security Concerns
Iran Warns of Strikes on Saudi Energy Infrastructure if US Targets Its Facilities
Iran Urges Civilians to Form Human Shields Around Nuclear Sites as Diplomatic Deadline Approaches
Saudi Arabia Raises Oil Prices to Record Premiums Amid Supply Pressures Linked to Iran Conflict
Key Saudi-Bahrain Causeway Closed Amid Heightened Security Concerns Linked to Iran
Formula One Calendar Gap Explained as Fans Await Next Grand Prix
×