Microsoft seizes 42 domains allegedly used by a Chinese cyber espionage group that targeted organizations in 29 countries including the US
Microsoft said today that its legal team has successfully obtained a court warrant that allowed it to seize 42 domains used by a Chinese cyber-espionage group … Source: Microsoft On the Issues .
Context & Ripple Effects
Microsoft had already used court orders to take control of infrastructure attributed to other state-linked groups, including 99 websites tied to an Iranian hacking operation and 50 domains attributed to North Korean group Thallium. The 42-domain action extends that legal-disruption playbook to a Chinese espionage operation.
Related coverage later records the same approach against Russia-linked Strontium, underscoring that Microsoft treats domain seizures as a repeatable part of disrupting state-linked attack infrastructure, not a one-off response.
First-order effects
- The Chinese cyber-espionage group loses control of 42 domains identified in Microsoft's court action, interrupting infrastructure it allegedly used against organizations across 29 countries.
- Organizations targeted by the group gain an immediate disruption of those identified domains, while Microsoft assumes control of the infrastructure named in the order.
Second-order effects
- The group must replace or reconfigure the seized infrastructure to continue using the affected channels, increasing the operational burden of its campaign.
- Microsoft's repeated resort to court orders makes domain registrars and hosting intermediaries a more consequential enforcement layer in responses to alleged espionage activity.
Third-order effects
- If this pattern persists, large technology platforms will increasingly combine threat research with civil legal action to remove attacker infrastructure across national boundaries.
- The model shifts part of cyber defense from detecting attacks inside customer networks toward contesting the internet services attackers depend on.
The trend: Microsoft is institutionalizing court-ordered infrastructure seizures as an ecosystem-defense tool against alleged state-linked and criminal cyber operations.