The FBI has seized seven internet domains that U.S. authorities say supported hacking tools used by China-linked operators to scan networks, gain access to victims, and remove data. The action targeted infrastructure associated with Integrity Technology Group, a China-based company alleged to have provided capabilities used in activity connected to the Flax Typhoon threat cluster.
According to the Department of Justice, the seized domains supported two platforms, known as MicroScan and FishHub. Federal investigators said the tools were used against organizations in the United States and other countries, including entities in critical infrastructure sectors.
Scanning and follow-on intrusion tools
MicroScan is described in court records and a related joint advisory as a Python-based vulnerability scanner with more than 1,300 scripts. Authorities said it was used to identify weaknesses in internet-facing services and was at times paired with devices infected by Mirai malware. Named targets included a U.S. power company, airports in Japan and Poland, and energy organizations in Taiwan.
The FBI said scanning activity was followed by confirmed compromises at two Taiwanese universities. It did not state whether other organizations identified in the investigation were breached.
FishHub allegedly supported spear-phishing, malware delivery, remote access, and data theft after an initial compromise. Investigators reported finding files associated with more than 20 organizations on infrastructure tied to the tool, including data from six Taiwanese universities. One additional seized domain was reportedly used to support SoftEther VPN access on compromised networks.
Advisory urges defensive action
The FBI, CISA, NSA, and international partners published indicators of compromise and technical details intended to help defenders hunt for related activity. The agencies said the broader targeting included government, manufacturing, healthcare, IT, law enforcement, education, and religious organizations across North America, Southeast Asia, and Africa.
- Review published indicators, including domains, IP addresses, hashes, and tooling details.
- Patch exposed applications and address known vulnerabilities promptly.
- Reduce unnecessary internet-facing services and enforce multifactor authentication.
- Investigate password-spraying, suspicious VPN use, and unusual data transfers.
The advisory noted overlaps with activity tracked as Flax Typhoon, Ethereal Panda, and Red Juliett, while cautioning that not every identified operation can necessarily be attributed to Integrity Technology Group. The disruption follows a 2024 U.S. operation against an alleged Integrity Tech-operated Mirai botnet involving more than 200,000 compromised devices.
