The FBI has seized seven internet domains allegedly used by Chinese state-sponsored hacking group Flax Typhoon to operate two cyberattack tools, MicroScan and FishHub, which were used to target critical infrastructure and organizations worldwide.
The U.S. Department of Justice said the seized infrastructure was linked to Integrity Technology Group, a China-based company that U.S. authorities accuse of supporting Chinese government-backed cyber operations. The tools were reportedly used to identify security weaknesses, break into computer networks, steal sensitive information, and maintain unauthorized access to compromised systems.
MicroScan is a vulnerability-scanning platform developed by Integrity Tech. According to an FBI seizure affidavit, the tool was used alongside a botnet of internet-connected devices infected with Mirai malware to scan potential targets. These included a power company in South Carolina, airports in Japan and Poland, energy companies in Taiwan, and universities.
Investigators confirmed that MicroScan scanning activity was followed by successful intrusions at two Taiwanese universities. Their networks were scanned in August 2022 and March 2023 before being breached. However, the FBI did not confirm whether the specifically named power company, airports, and energy providers were successfully compromised.
Authorities seized the domain c0cc.cc, which was used to access the MicroScan platform and was reportedly still online in September 2026.
The second tool, FishHub, was allegedly used to launch spear-phishing attacks and deliver additional malware to networks that had already been compromised. The malware provided attackers with remote access, allowing them to search for specific files and transfer stolen data to servers controlled by Integrity Tech.
According to the FBI affidavit, investigators discovered files and data belonging to more than 20 organizations on a server associated with FishHub, including six Taiwanese universities.
Law enforcement also seized five domains allegedly used to deliver malware: 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, and linkedinns.net. A seventh domain, 98aiblog.com, was linked to SoftEther VPN software installed on compromised systems to help maintain remote access to victims’ networks.
The seized domains now display notices identifying the FBI’s law enforcement action and the alleged connection to Flax Typhoon and Integrity Technology Group.
The operation was accompanied by a joint cybersecurity advisory from the FBI, CISA, NSA, and international partners. The advisory describes how Chinese government-linked hackers allegedly used Integrity Tech’s tools and infrastructure to target government agencies, critical manufacturing, healthcare, information technology, law enforcement, educational institutions, and religious organizations. Targets were reported across the United States, Southeast Asia, Africa, and North America.
The activity has been associated with threat groups tracked as Flax Typhoon, Ethereal Panda, and Red Juliett. However, authorities cautioned that not all activity attributed to these groups can necessarily be linked to Integrity Tech.
The advisory describes MicroScan as a Python-based vulnerability scanner containing more than 1,300 penetration-testing scripts. The scripts were designed to identify security weaknesses in websites and services running software such as Oracle WebLogic, Apache Struts, WordPress, and Jenkins.
Investigators also identified eight vulnerabilities frequently targeted during the attacks: CVE-2015-3306 in ProFTPD, CVE-2015-5477 in ISC BIND, CVE-2016-3081 in Apache Struts, CVE-2021-3199 in ONLYOFFICE DocumentServer, CVE-2023-22894 in Strapi, CVE-2014-6278 in GNU Bash, CVE-2019-11510 in Pulse Secure VPN, and CVE-2021-22205 in GitLab.
The attackers also reportedly used the open-source EBurst tool to conduct password-spraying attacks against Microsoft Exchange servers. Other tools were used to steal emails, collect Active Directory credentials, and exfiltrate data. The FBI additionally discovered a custom web application that allowed third parties to browse stolen emails without directly accessing the compromised accounts.
The joint advisory includes indicators of compromise, such as IP addresses, domains, malware hashes, and details of the tools used in the attacks. Authorities urged organizations to review these indicators, patch vulnerable systems, disable unnecessary internet-facing services, and enforce multifactor authentication.
This is not the first time U.S. authorities have targeted Integrity Tech’s infrastructure. In September 2024, the Justice Department disrupted a Mirai-based botnet operated by the company that had infected more than 200,000 consumer devices worldwide.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The United Kingdom sanctioned Integrity Tech in 2025, while the European Union imposed sanctions on the company in 2026 over its alleged involvement in cyberattacks targeting Europe and its allies.
FBI Seizes Seven Domains Used by China-Linked Flax Typhoon Hackers



