International Coalition Dismantles Tools of Chinese State-Sponsored Hacking Firm Integrity Tech
An international law enforcement coalition has seized digital tools and infrastructure belonging to Beijing-based Integrity Tech, a firm accused of aiding China's state-sponsored cyber operations, including the Flax Typhoon campaign.

An international coalition of law enforcement agencies, including the United States, has successfully dismantled critical digital tools and infrastructure utilized by Beijing-based Integrity Tech, a cybersecurity firm implicated in supporting China's state-sponsored cyber operations. The operation targeted the company's capabilities, which were instrumental in the long-running Flax Typhoon campaign, enabling widespread vulnerability scanning and facilitating intrusions into critical infrastructure organizations globally.
Integrity Tech, reportedly hired by China's Ministry of State Security, provided hacking tools and services to facilitate attacks against a diverse range of targets. These included universities, government agencies, telecommunications providers, and media organizations. FBI Assistant Director Brett Leatherman stated that the firm provided capabilities for "widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure," highlighting the PRC's reliance on such contractors to expand its malicious cyber activities.
The U.S. Department of Justice seized multiple websites associated with two key hacking tools developed by Integrity Tech: "Microscan" and "FishHub." These tools have been in use for at least six years as part of the Flax Typhoon campaign. Microscan was designed for reconnaissance, identifying vulnerabilities that Chinese hackers could exploit. Court documents reveal that victims of Microscan's scanning activities include a power company in South Carolina, airports in Japan and Poland, and critical infrastructure entities in Taiwan's natural gas and power sectors.
FishHub, another tool developed by Integrity Tech, was created to streamline phishing attacks, allowing attackers to deploy malware onto a victim's network after an initial breach. Authorities noted that FishHub's remote access capabilities were specifically used against approximately 20 universities in Taiwan. The technical advisory detailing these tools was compiled from multiple incident response investigations conducted by the FBI.
According to advisories from CISA and the NSA, Integrity Tech often targeted edge devices that were not closely monitored, enabling persistent and covert access to victim networks. These devices, including operational technology (OT) systems, are crucial for critical infrastructure. The international cooperation in this takedown extended to Australia, Japan, the U.K., Spain, New Zealand, and Canada, underscoring the global nature of the threat.
Integrity Tech is described as a significant component of China's cyber-espionage apparatus, involved in acquiring, selling, and hosting tools used by various threat groups. The company has also been linked to tools like EBurst, which targets compromised Microsoft Exchange servers for credential harvesting and data exfiltration, with victims including government organizations, law enforcement, and healthcare systems, particularly in Southeast Asia.
This is not the first time U.S. agencies have targeted Integrity Tech. Sanctions and previous takedown efforts have been implemented over the past three years due to its involvement in Flax Typhoon, which was first publicly identified by Microsoft researchers in 2023. In September 2024, the DOJ disrupted a Mirai-based botnet operated by Integrity Tech, comprising over 260,000 consumer devices, by removing malware and seizing control of its internet infrastructure.
Integrity Tech is also known in China for developing the country's cyber ranges, advanced training platforms simulating real-world digital environments. Founded in 2010 by Cai Jingjing, a notable figure in China's hacking community, the company has historically benefited from extensive government funding. This coordinated takedown aims to significantly degrade the capabilities of a key enabler of state-sponsored cyber operations.
The U.S. Department of Justice and FBI have announced the seizure of two hacking tools, Microscan and FishHub, linked to the China-linked threat group Flax Typhoon and the sanctioned Chinese firm Integrity Technology Group. These tools were used for vulnerability scanning and spearphishing attacks, with targets including U.S. critical infrastructure. The operation, which involved court-authorized domain name seizures, aims to disrupt the capabilities of actors supported by Integrity Technology Group, a company previously targeted by U.S. sanctions and a botnet takedown operation.
The FBI has seized seven internet domains that were instrumental in the Flax Typhoon campaign, a series of cyber intrusions attributed to the China-linked Integrity Technology Group. These domains facilitated critical functions for the threat actors, including scanning for vulnerable networks, delivering malware via spear-phishing, and exfiltrating stolen data from compromised victims. This action represents the second major disruption of Integrity Technology Group's infrastructure by U.S. authorities in as many years, underscoring ongoing efforts to dismantle state-sponsored hacking operations.