FBI Seizes Seven Domains Linked to Flax Typhoon Hacking Tools Used Against Critical Infrastructure
The FBI has seized seven domains used by the Chinese state-sponsored hacking group known as Flax Typhoon to operate MicroScan and FishHub, two tools used to target critical infrastructure and organizations around the world.
The seized infrastructure supported two hacking platforms operated by China-based Integrity Technology Group, also known as Integrity Tech. U.S. authorities say the company has contracts with the Chinese government.
According to the U.S. Department of Justice, the tools were used to scan for vulnerabilities, compromise networks, and steal sensitive information from critical infrastructure organizations in the United States and other countries.
“Integrity Technology Group provided China-linked threat actors with capabilities that were used to conduct extensive vulnerability scans and, in some cases, carry out targeted intrusions of critical infrastructure in the United States and abroad,” said Brett Leatherman, deputy director of the FBI’s cyber division.
Leatherman said the Chinese government relies on contractors and other companies to expand the reach of its cyber operations. Disrupting these organizations, he added, makes it more difficult for China-linked hackers to target U.S. networks.
MicroScan used to scan critical infrastructure
MicroScan is a vulnerability-scanning platform developed by Integrity Tech to identify security weaknesses in target networks.
According to an FBI seizure affidavit, MicroScan was used with a botnet of internet-connected devices infected with Mirai malware to identify potential targets.
Targets included a power company in South Carolina, airports in Japan and Poland, natural gas and power companies in Taiwan, and a university.
The affidavit also confirms that scanning activity led to successful breaches. Two universities in Taiwan were scanned with MicroScan in August 2022 and March 2023 and were subsequently compromised.
The FBI acknowledged that the hacking tools were used to breach critical infrastructure but did not say whether the specific electricity companies, airports, or energy providers identified in the affidavit were successfully compromised.
The FBI seized the c0cc.cc domain, which Integrity Tech used to access the MicroScan platform. Law enforcement observed the domain online in September 2026.
FishHub enabled spear-phishing and data theft
The second platform, FishHub, was used to conduct spear-phishing attacks and deliver additional malware to already compromised networks.
The malware provided attackers with unauthorized remote access to victims’ networks. This allowed them to search for specific files and exfiltrate data to servers managed by Integrity Tech.
Investigators found data and files belonging to more than 20 organizations, including six Taiwanese universities, on servers linked to the FishHub data-theft tool, according to an FBI seizure affidavit.
Law enforcement seized five domains used to distribute the malware:
98aicai.com98aicode.comoutlook3650.comyoutubecard.comlinkedinns.net
The seventh seized domain, 98aiblog.com, was associated with SoftEther VPN software installed on compromised systems to maintain remote access to victims’ networks.
The seized domains currently display FBI notices identifying the Flax Typhoon hacking group and Integrity Technology Group.

Source: BleepingComputer
Chinese hackers targeted government, healthcare, and education
Alongside the domain seizure, the FBI, CISA, NSA, and international partners issued a joint cybersecurity advisory detailing how Chinese government-affiliated hackers used Integrity Tech’s tools and infrastructure to compromise organizations and steal sensitive information.
The advisory says the attackers targeted U.S. government agencies, critical manufacturing companies, healthcare organizations, information technology providers, law enforcement agencies, educational institutions, and religious organizations. Organizations in Southeast Asia, Africa, and North America were also targeted.
The activity overlaps with operations tracked as Flax Typhoon, Ethereal Panda, and Red Juliet. However, authorities said that not all activity associated with those names is necessarily connected to Integrity Tech.
MicroScan included more than 1,300 penetration-testing scripts
According to the advisory, MicroScan is a Python-based vulnerability scanner containing more than 1,300 penetration-testing scripts designed to identify security flaws in websites and online services.
The scripts targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, Jenkins, and other applications.
Investigators also identified eight vulnerabilities commonly targeted by the attackers:
- CVE-2015-3306: ProFTPD illegal file read vulnerability.
- CVE-2015-5477: ISC BIND denial-of-service vulnerability.
- CVE-2016-3081: Apache Struts remote code execution vulnerability.
- CVE-2021-3199: ONLYOFFICE DocumentServer illegal file write vulnerability.
- CVE-2023-22894: Strapi information leak vulnerability.
- CVE-2014-6278: GNU Bash Shellshock remote code execution vulnerability.
- CVE-2019-11510: Pulse Secure VPN arbitrary file read vulnerability.
- CVE-2021-22205: GitLab remote code execution vulnerability.
The attackers also used the open-source EBurst tool to conduct password-spray attacks against Microsoft Exchange servers. Other tools were used to steal emails, harvest Active Directory credentials, and exfiltrate data.
The FBI discovered a custom web application that allowed third parties to view stolen emails without having direct access to the compromised accounts.
Authorities release indicators of compromise
The joint advisory includes indicators of compromise such as IP addresses, domains, malware hashes, and details about the attackers’ tools. Organizations can use the information to identify potential intrusions.
Officials are urging organizations to review security metrics, patch vulnerable systems, disable unnecessary public services, and enforce multifactor authentication to help protect against similar attacks.
Previous disruption of Integrity Tech infrastructure
This is not the first time U.S. law enforcement has disrupted Integrity Tech’s hacking infrastructure.
In September 2024, the Department of Justice disrupted the Mirai botnet operated by Integrity Tech. The botnet consisted of more than 200,000 compromised consumer devices around the world.
The UK government also took action against Integrity Tech in 2025. In 2026, the European Union sanctioned the company for its involvement in cyberattacks targeting Europe and its allies.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



