Cybersecurity

FBI Seizes Seven Domains Linked to Chinese Tools for Hacking Critical Infrastructure

The FBI seized seven domains used by the China-linked Flax Typhoon group to operate the MicroScan and FishHub tools, which were used to scan networks, breach organizations, and steal data worldwide. U.S. and international agencies issued indicators of compromise and defensive recommendations alongside the operation.

2026-10-08
4 min read
113 views
certi.news Editorial Team
FBI Seizes Seven Domains Linked to Chinese Tools for Hacking Critical Infrastructure

The U.S. Federal Bureau of Investigation seized seven internet domains that authorities said supported the operations of the China-linked hacking group Flax Typhoon and operated the MicroScan and FishHub tools used to scan and breach organizational networks and steal data from them. The operation targeted infrastructure linked to Integrity Technology Group, which U.S. authorities say holds contracts with the Chinese government.

According to the U.S. Department of Justice, these tools enabled broad vulnerability-scanning operations against critical-infrastructure networks in the United States and other countries, some of which led to actual breaches. Brett Leatherman, assistant director of the FBI’s Cyber Division, said the company provided capabilities to China-linked threat actors and that disrupting these companies and their affiliated infrastructure makes it more difficult to target U.S. networks.

A Platform for Scanning and a Tool for Control and Data Theft

MicroScan is a vulnerability-scanning platform developed by Integrity Tech. It contains more than 1,300 penetration-testing scripts written in Python. Attackers used the platform with a network of devices infected with the Mirai malware to scan potential targets, including an electric utility in South Carolina, airports in Japan and Poland, natural-gas and electric companies in Taiwan, and universities.

The seizure affidavit confirms that the networks of two universities in Taiwan were scanned in August 2022 and March 2023 and were subsequently breached. However, the FBI did not determine whether the energy companies and airports named in the affidavit were actually compromised. Authorities seized the domain c0cc.cc, which was used to access MicroScan and was available on the internet in September 2026.

FishHub, meanwhile, was used in targeted phishing attacks to deliver malware to previously compromised networks. The malware gave attackers remote access and enabled them to search for and extract specific files to servers controlled by Integrity Tech. Investigators found files and data belonging to more than 20 organizations on a server linked to the tool, including six universities in Taiwan.

Five domains used to deliver the malware were seized: 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, and linkedinns.net. The domain 98aiblog.com was also linked to the SoftEther VPN software, which was used to maintain remote access to compromised systems.

What Does the Campaign Reveal?

U.S. and international agencies said the activity targeted U.S. government agencies, biomanufacturing, healthcare, information technology, law enforcement, education, and religious organizations, as well as institutions in Southeast Asia, Africa, and North America. The activity overlaps with operations attributed to Flax Typhoon, Ethereal Panda, and Red Juliett, while official agencies warned that not all of these activities may be connected to Integrity Tech.

MicroScan targeted widely used software such as Oracle WebLogic, Apache Struts, WordPress, and Jenkins, as well as known vulnerabilities in ProFTPD, ISC BIND, ONLYOFFICE, Strapi, GNU Bash, Pulse Secure VPN, and GitLab. The attackers also used the open-source EBurst tool to conduct password-guessing attacks against Microsoft Exchange servers, along with tools to collect Active Directory credentials and steal email. The FBI also discovered a custom web application that allowed third parties to browse stolen email messages without direct access to the compromised accounts.

What Changes in Practice for Defenders?

The FBI, CISA, NSA, and international partners issued a joint security advisory alongside the seizure containing IP addresses, domains, malware fingerprints, and details about the tools used. The agencies recommend that organizations review indicators of compromise, install updates for vulnerable systems, disable unnecessary exposed services, and enforce multifactor authentication.

The operation follows a U.S. disruption in September 2024 of a Mirai network operated by Integrity Tech that included more than 200,000 compromised consumer devices worldwide. The United Kingdom also sanctioned the company in 2025, and the European Union imposed sanctions on it in 2026 because of its connection to cyberattacks targeting Europe and its allies.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news