US Seizes Domains Linked to Chinese Spy Tools Targeting Global Infrastructure

Federal agents seized seven web domains on Thursday, disrupting two primary hacking tools used by Chinese state-sponsored actors. The operation targets Integrity Technology Group and reveals how attackers turn routine network scans into massive data theft operations.

Domain linked spy federal
AI Generated : Nano Banana

The short version

  • The FBI seized seven web domains linked to hacking tools operated by Integrity Technology Group.
  • MicroScan is a Python-based application with over 1,300 scripts used for vulnerability scanning.
  • FishHub malware enabled remote access and file exfiltration from at least 20 Taiwanese universities.
  • Threat actors restricted access to some stolen data to IP addresses from Xiamen, China.
  • CISA added five CVEs to its Known Exploited Vulnerabilities Catalog based on this activity.

Why it matters: Understanding these tools reveals how attackers turn routine network scans into massive data theft operations targeting global critical infrastructure.

On this page
  1. The short version
  2. How the tools work
  3. Targets and timeline
  4. Sources and further reading
  5. Frequently asked questions

Federal agents seized seven web domains Thursday, disrupting two primary hacking tools used by Chinese state-sponsored actors to infiltrate critical infrastructure worldwide.

A coalition of agencies from the US, UK, Australia, Canada, Japan, New Zealand, and Spain issued a joint warning. They stated that attackers linked to the Chinese government, with support from Integrity Tech, employ malware, botnets, and other tools to intrude on global organizations and pilfer sensitive information.

How the tools work

Integrity Technology Group developed MicroScan for scanning vulnerabilities, while FishHub facilitated network breaches through spear phishing. The advisory characterizes MicroScan as a web application built on Python, featuring more than 1,300 scripts designed for penetration testing to identify specific website weaknesses.

The advisory indicates that MicroScan has targeted services including Apache Struts, Juniper ScreenOS, Jenkins, OpenSSL, Oracle, Rejetto HFS, WebLogic Server, and WordPress since at least 2017. Integrity Tech used a Mirai malware variant to build an IoT botnet that facilitated MicroScan's use for reconnaissance against victims' networks.

Victims of MicroScan scanning include a US power company, NGOs, Japanese and Polish airports, and Taiwanese critical infrastructure entities and universities. Court documents state that Flax Typhoon actors used the Microscan tool to scan for vulnerabilities on the networks of these targets on or about April 26, 2022, and on or about December 29, 2022. The targets included a U.S. power company based in South Carolina, a multi-national Non-Governmental Organization, and at least two Taiwanese critical infrastructure companies in the natural gas and power sectors.

Integrity Tech's clients used FishHub to remotely access victim networks, locate specific files, and exfiltrate them. The tool has been used in attacks against at least 20 universities in Taiwan. Adam James, an FBI special agent, wrote in court documents: "Based on my training and experience I believe the tool was named FishHub because it facilitated phishing activity".

After FishHub downloaded a file onto victims' computers, that file used the five domains to retrieve additional malicious programs and code. The malware created a file listing, searched for specific files, compressed documents, and exfiltrated the selected files to an attacker-controlled server.

Threat actors employed VPN utilities like SoftEther to maintain persistence and downloaded databases or manually pulled data from victim email addresses. For exfiltrating emails, they utilized the command-line tool office-cli and the PHP script Curlc4.txt, while DC.ex was used to harvest sensitive information from Active Directory.

The joint advisory reported that these actors gather login credentials and steal email data from cloud services and on-premises systems. Victims of this theft included religious institutions, healthcare systems, law enforcement agencies, and government bodies in Southeast Asia. In certain cases, access to the stolen data was limited to IP addresses originating in Xiamen, China.

What we know

  • MicroScan is a Python-based app with over 1,300 scripts.
  • FishHub enabled remote access and file exfiltration.
  • MicroScan has been active since at least 2017.

Still unclear

  • The specific fifth CVE added to CISA's catalog is not identified.
  • The current status of the seized domains and their final disposition remains unknown.
  • The exact volume and content of stolen data from recent intrusions have not been disclosed.

Targets and timeline

Flax Typhoon, also identified as Ethereal Panda, Red Juliett, Storm-0919, and UNC5007, was primarily linked to MicroScan. Integrity Tech is thought to have collaborated with other Chinese APTs. For reconnaissance, Flax Typhoon employed tools such as WPScan, ShuiZe, OneForAll, Nmap, masscan, ksubdomain, Fscan, dirsearch, and BBScan. Initial access was gained using the EBurst Microsoft Exchange password spraying tool and various command-line exploit utilities.

The US disrupted the Raptor Train botnet operated by Integrity Tech in 2024. In 2025, sanctions were imposed on the firm for supplying cybersecurity products to Chinese state-sponsored APTs, including Flax Typhoon. The European Union applied sanctions against Integrity Tech in March 2026.

Based on this activity, CISA has added five CVEs to its Known Exploited Vulnerabilities Catalog. Dragos said in February that China's state-sponsored spies continue attempts to compromise America's critical infrastructure, including a group whose activity overlaps with Flax Typhoon.

This group aims to secure long-term entry into OT engineering workstations and steal operational files. Its targets span government organizations, oil and gas, electric power, automotive, defense, and manufacturing sectors across the Asia-Pacific region, Europe, and the US. These court-authorized seizures represent the most recent effort by US law enforcement to dismantle the botnet and disrupt Flax Typhoon, a cybercrew backed by Beijing.

  1. 2017MicroScan active The joint advisory shows MicroScan has been active since at least 2017.
  2. April 2022Power company scanned Flax Typhoon actors used Microscan to scan a US power company in South Carolina.
  3. December 2022Airports targeted Scans targeted Japanese and Polish airports and Taiwanese infrastructure.
  4. 2024Raptor Train disrupted The US disrupted Integrity Tech's Raptor Train botnet.
  5. March 2026EU sanctions The European Union sanctioned Integrity Tech.
DomainFunction
c0cc.ccAccessed MicroScan
98aicai.comDelivered FishHub malware
98aicode.comDelivered FishHub malware
outlook3650.comDelivered FishHub malware
youtubecard.comDelivered FishHub malware
linkedinns.netDelivered FishHub malware

Sources and further reading

  1. US Disrupts Chinese State-Sponsored Hacking Tools (opens in a new tab) SecurityWeek
  2. US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide (opens in a new tab) The Register

This article was prepared by the GlobePrism editorial team from the public reporting linked above. How we report

Frequently asked questions

What are MicroScan and FishHub?

MicroScan is a Python-based web application with over 1,300 scripts used for vulnerability scanning. FishHub is a tool that enables network intrusions via spear phishing, allowing remote access and file exfiltration.

Who is behind these hacking tools?

The tools are linked to Integrity Technology Group, a firm associated with Beijing-backed cyber operatives known as Flax Typhoon. The US and six allies issued a joint advisory warning about these actors.

Which domains were seized by the FBI?

The seized domains include c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net. Five of these delivered the FishHub malware.

What victims were targeted by these tools?

Victims include a US power company, NGOs, Japanese and Polish airports, and at least 20 universities in Taiwan. Email data theft also affected government organizations and healthcare systems in Southeast Asia.

How did the attackers hide their location?

Integrity Tech used a Mirai malware variant to build an IoT botnet for reconnaissance. In some instances, threat actors restricted access to exfiltrated data to only IP addresses from Xiamen, China.