Federal agents seized seven web domains Thursday, disrupting two primary hacking tools used by Chinese state-sponsored actors to infiltrate critical infrastructure worldwide.
A coalition of agencies from the US, UK, Australia, Canada, Japan, New Zealand, and Spain issued a joint warning. They stated that attackers linked to the Chinese government, with support from Integrity Tech, employ malware, botnets, and other tools to intrude on global organizations and pilfer sensitive information.
How the tools work
Integrity Technology Group developed MicroScan for scanning vulnerabilities, while FishHub facilitated network breaches through spear phishing. The advisory characterizes MicroScan as a web application built on Python, featuring more than 1,300 scripts designed for penetration testing to identify specific website weaknesses.
The advisory indicates that MicroScan has targeted services including Apache Struts, Juniper ScreenOS, Jenkins, OpenSSL, Oracle, Rejetto HFS, WebLogic Server, and WordPress since at least 2017. Integrity Tech used a Mirai malware variant to build an IoT botnet that facilitated MicroScan's use for reconnaissance against victims' networks.
Victims of MicroScan scanning include a US power company, NGOs, Japanese and Polish airports, and Taiwanese critical infrastructure entities and universities. Court documents state that Flax Typhoon actors used the Microscan tool to scan for vulnerabilities on the networks of these targets on or about April 26, 2022, and on or about December 29, 2022. The targets included a U.S. power company based in South Carolina, a multi-national Non-Governmental Organization, and at least two Taiwanese critical infrastructure companies in the natural gas and power sectors.
Integrity Tech's clients used FishHub to remotely access victim networks, locate specific files, and exfiltrate them. The tool has been used in attacks against at least 20 universities in Taiwan. Adam James, an FBI special agent, wrote in court documents: "Based on my training and experience I believe the tool was named FishHub because it facilitated phishing activity".
After FishHub downloaded a file onto victims' computers, that file used the five domains to retrieve additional malicious programs and code. The malware created a file listing, searched for specific files, compressed documents, and exfiltrated the selected files to an attacker-controlled server.
Threat actors employed VPN utilities like SoftEther to maintain persistence and downloaded databases or manually pulled data from victim email addresses. For exfiltrating emails, they utilized the command-line tool office-cli and the PHP script Curlc4.txt, while DC.ex was used to harvest sensitive information from Active Directory.
The joint advisory reported that these actors gather login credentials and steal email data from cloud services and on-premises systems. Victims of this theft included religious institutions, healthcare systems, law enforcement agencies, and government bodies in Southeast Asia. In certain cases, access to the stolen data was limited to IP addresses originating in Xiamen, China.
What we know
- MicroScan is a Python-based app with over 1,300 scripts.
- FishHub enabled remote access and file exfiltration.
- MicroScan has been active since at least 2017.
Still unclear
- The specific fifth CVE added to CISA's catalog is not identified.
- The current status of the seized domains and their final disposition remains unknown.
- The exact volume and content of stolen data from recent intrusions have not been disclosed.
Targets and timeline
Flax Typhoon, also identified as Ethereal Panda, Red Juliett, Storm-0919, and UNC5007, was primarily linked to MicroScan. Integrity Tech is thought to have collaborated with other Chinese APTs. For reconnaissance, Flax Typhoon employed tools such as WPScan, ShuiZe, OneForAll, Nmap, masscan, ksubdomain, Fscan, dirsearch, and BBScan. Initial access was gained using the EBurst Microsoft Exchange password spraying tool and various command-line exploit utilities.
The US disrupted the Raptor Train botnet operated by Integrity Tech in 2024. In 2025, sanctions were imposed on the firm for supplying cybersecurity products to Chinese state-sponsored APTs, including Flax Typhoon. The European Union applied sanctions against Integrity Tech in March 2026.
Based on this activity, CISA has added five CVEs to its Known Exploited Vulnerabilities Catalog. Dragos said in February that China's state-sponsored spies continue attempts to compromise America's critical infrastructure, including a group whose activity overlaps with Flax Typhoon.
This group aims to secure long-term entry into OT engineering workstations and steal operational files. Its targets span government organizations, oil and gas, electric power, automotive, defense, and manufacturing sectors across the Asia-Pacific region, Europe, and the US. These court-authorized seizures represent the most recent effort by US law enforcement to dismantle the botnet and disrupt Flax Typhoon, a cybercrew backed by Beijing.
- 2017MicroScan active The joint advisory shows MicroScan has been active since at least 2017.
- April 2022Power company scanned Flax Typhoon actors used Microscan to scan a US power company in South Carolina.
- December 2022Airports targeted Scans targeted Japanese and Polish airports and Taiwanese infrastructure.
- 2024Raptor Train disrupted The US disrupted Integrity Tech's Raptor Train botnet.
- March 2026EU sanctions The European Union sanctioned Integrity Tech.
| Domain | Function |
|---|---|
| c0cc.cc | Accessed MicroScan |
| 98aicai.com | Delivered FishHub malware |
| 98aicode.com | Delivered FishHub malware |
| outlook3650.com | Delivered FishHub malware |
| youtubecard.com | Delivered FishHub malware |
| linkedinns.net | Delivered FishHub malware |
