The United States announced the disruption of two cyberhacking tools used by state-backed Chinese threat actors against U.S. and foreign critical infrastructure. The action targets two tools developed by Integrity Technology Group, also known as Integrity Tech: MicroScan and FishHub.
Two Tools With Different Functions
MicroScan was used for vulnerability scanning and network reconnaissance, while FishHub enabled targeted phishing and remote network compromise, followed by the search for and extraction of specific files from targeted systems. The United States said Integrity Tech used a version of the Mirai malware to build a botnet of Internet of Things devices that helped operate MicroScan and conduct reconnaissance operations.
The targets included a U.S. energy company, nongovernmental organizations, and airports in Japan and Poland, as well as critical infrastructure entities and universities in Taiwan. FishHub was also used against at least 20 Taiwanese universities.
Disrupting the Operational Infrastructure
The United States seized domains used by the attackers to access the two tools, including c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net.
The operation follows the disruption of the Integrity Tech-linked Raptor Train network in 2024 and the imposition of sanctions on the company in 2025 for providing cybersecurity products to advanced persistent Chinese actors such as Flax Typhoon. The European Union also imposed sanctions on the company in March 2026.
Scope of the Tools and Targeted Entities
A joint security advisory issued by agencies from the United States, the United Kingdom, Australia, Canada, Japan, New Zealand, and Spain showed that MicroScan has been active since at least 2017. Its targets included services and products such as Apache Struts, Juniper ScreenOS, Jenkins, OpenSSL, Oracle, Rejetto HFS, WebLogic Server, and WordPress. The advisory described the tool as a Python-based web application containing more than 1,300 scripts for penetration testing and scanning websites for specific vulnerabilities.
MicroScan was particularly associated with Flax Typhoon activity, also known as Ethereal Panda, Red Juliett, Storm-0919, and UNC5007, with U.S. authorities believing that Integrity Tech also collaborated with other Chinese groups.
What Matters to Defense Officials?
The campaign shows that the risk is not tied to a single tool, but to a chain that begins with automated reconnaissance and then initial access, continuing through tools such as BBScan, dirsearch, Fscan, ksubdomain, masscan, Nmap, OneForAll, ShuiZe, and WPScan. The attackers also used command-line exploitation tools, the EBurst tool to password-spray Microsoft Exchange, and VPN tools such as SoftEther to maintain access.
According to the advisory, credentials and email messages were collected from local systems and cloud services, and data theft affected government entities, law enforcement agencies, healthcare systems, and religious organizations in Southeast Asia. In some cases, access to the stolen data was restricted to IP addresses originating from Xiamen, China. This confirms that disrupting the domains strikes an important part of the operational infrastructure, but it alone does not prove that the ability to rebuild the tools or use other channels has been eliminated.