FBI Seizes Chinese Hacking Tools Used for Critical Infrastructure Scanning and Spear Phishing
The FBI and U.S. Justice Department have dismantled a significant cyber operation by seizing seven domains linked to Microscan and FishHub, tools allegedly used by China-based Integrity Technology Group and associated with the Flax Typhoon hacking group.

The FBI and U.S. Justice Department announced on October 8, 2026, the court-authorized seizure of seven domains associated with Microscan and FishHub, two sets of hacking tools operated by the China-based Integrity Technology Group. This action aims to disrupt the group's ability to scan critical infrastructure for vulnerabilities, conduct spear phishing attacks, and exfiltrate data from compromised networks. Court documents unsealed in the Western District of Pennsylvania link this activity to the Flax Typhoon hacking group, a threat actor that security researchers have been tracking.
Integrity Technology Group, reportedly holding contracts with the Chinese government, allegedly developed and supplied these tools to its clients, enabling them to identify weak systems and gain unauthorized access to networks. The operation specifically targets the infrastructure supporting these malicious activities, rather than claiming that every affected network has been secured. The Justice Department detailed how Integrity Tech constructed a botnet using a variant of the Mirai malware, infecting over 200,000 consumer devices worldwide, including routers, IP cameras, and storage devices. This compromised network was then used to run Microscan against potential targets, disguising malicious traffic as ordinary internet activity.
Microscan, described in a joint cybersecurity advisory as a Python-based web application, contains over 1,300 penetration testing scripts. These scripts were designed to probe websites and services for specific vulnerabilities, including known weaknesses in popular software such as Oracle WebLogic Server, WordPress, Jenkins, Apache Struts, OpenSSL, and Juniper ScreenOS. Investigators traced the use of Microscan back to at least 2017, with its dashboard providing operators a centralized interface to manage scan results and identify potential entry points into target networks. The seized domain, c0cc[.]cc, was a direct access point for this scanning workflow.
FishHub served a distinct but complementary purpose, allegedly supporting spear phishing campaigns and facilitating the delivery of additional malware once an initial foothold was established. This secondary malware could grant Integrity Tech's clients remote network access or enable the exfiltration of specific files to servers controlled by the company. Approximately 20 Taiwanese universities were confirmed as victims of FishHub activity, separate from the Taiwanese universities targeted by Microscan scans. The five seized domains supporting FishHub were 98aicai[.]com, 98aicode[.]com, linkedinns[.]net, outlook3650[.]com, and youtubecard[.]com. A seventh domain, 98aiblog[.]com, was linked to the use of SoftEther VPN software for maintaining unauthorized remote access.
This latest action follows a previous court-authorized disruption in September 2026, which targeted a large Integrity Tech botnet comprising over 200,000 compromised consumer devices globally. While that operation focused on the botnet infrastructure, the current seizures target the tools and services that enable scanning and intrusion, demonstrating a multi-pronged approach to dismantling the group's capabilities. "By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure," stated Brett Leatherman, assistant director of the FBI’s Cyber Division, emphasizing the role of contractors in providing attack infrastructure.
The FBI-led advisory provides crucial indicators of compromise (IOCs) and details on related intrusion methods observed beyond Microscan, including password spraying against Microsoft Exchange, VPN-based persistence, and automated email theft. These findings offer a broader picture of the activities facilitated by Integrity Technology Group. Defenders are urged to review their logs for matching activity, patch exposed systems, disable unused services, enforce multifactor authentication, and scrutinize cloud applications with access to sensitive data.
Organizations detecting signs of compromise are advised to isolate affected hosts, preserve relevant logs for forensic analysis, and conduct thorough investigations to understand the full scope of the intrusion before attempting to remove attacker access. While domain seizures can disrupt critical connections, proactive defense and diligent investigation remain paramount for identifying and mitigating residual threats within compromised networks.