Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
US Dismantles Chinese Hacking Tools Targeting Infrastructure

US Dismantles Chinese Hacking Tools Targeting Infrastructure

Posted on October 9, 2026 By CWS

The United States has announced a significant disruption of hacking tools employed by Chinese state-backed threat actors. These tools, identified as MicroScan and FishHub, have been implicated in cyberattacks on critical infrastructure globally, including in the US.

Targeted Network Vulnerability Scanning

MicroScan, developed by Integrity Technology Group, was specifically designed for scanning network vulnerabilities. It played a crucial role in breaches involving entities from various sectors such as energy, non-governmental organizations, and international airports in Japan and Poland. The application was reportedly utilized to execute reconnaissance operations, facilitated by a Mirai malware variant IoT botnet.

FishHub, another tool from Integrity Tech, enabled threat actors to infiltrate networks and extract sensitive information. This tool was notably used against numerous Taiwanese universities, allowing unauthorized access and data exfiltration.

Government Action Against Cyber Threats

In response, US authorities have seized control of domains linked to these malicious operations, including addresses like c0cc[.]cc and outlook3650[.]com. This move is part of broader efforts to counteract cybersecurity threats posed by state-sponsored hacking activities.

Previously, the US had taken down the Raptor Train botnet in 2024 and imposed sanctions on Integrity Tech in 2025 for its affiliations with Chinese APTs, including Flax Typhoon. The European Union followed suit with sanctions in March 2026, highlighting the international scope of these cybersecurity challenges.

Ongoing Cybersecurity Challenges

A joint advisory from multiple countries, including the US, UK, and Australia, has revealed that MicroScan has been operational since at least 2017. It has targeted a wide range of services, from Apache Struts to WordPress, using a comprehensive set of penetration testing scripts.

Flax Typhoon, also known by other names such as Ethereal Panda, has been linked to a variety of reconnaissance tools beyond MicroScan. These include BBScan and Nmap, among others. The group has also utilized advanced techniques for accessing and extracting data, often focusing on email accounts from government and healthcare institutions in Southeast Asia.

This coordinated international response underscores the persistent threat posed by Chinese hacking groups and the importance of continued vigilance in protecting digital infrastructure worldwide.

Security Week News Tags:APT groups, Chinese hackers, critical infrastructure, cyber espionage, cybersecurity threat, Flax Typhoon, hacking tools, Integrity Tech, IoT botnet, network intrusion, US cybersecurity, vulnerability scanning

Post navigation

Previous Post: Silent Ransom Group Nets $200M Without Encrypting Data
Next Post: Malicious PDF App on Google Play Spreads Anatsa Trojan

Related Posts

UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks Security Week News
Android Crypto Wallets at Risk Due to SDK Flaw Android Crypto Wallets at Risk Due to SDK Flaw Security Week News
Cyberattack Disrupts France’s Postal Service and Banking During Christmas Rush Cyberattack Disrupts France’s Postal Service and Banking During Christmas Rush Security Week News
July 2026 Cybersecurity M&A: Key Acquisitions July 2026 Cybersecurity M&A: Key Acquisitions Security Week News
FBI Alert on Security Risks from Chinese Mobile Apps FBI Alert on Security Risks from Chinese Mobile Apps Security Week News
Android’s August 2025 Update Patches Exploited Qualcomm Vulnerability Android’s August 2025 Update Patches Exploited Qualcomm Vulnerability Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in React Server Components Puts Next.js Servers at Risk
  • Android Devices with Preinstalled Malware Threaten Users Globally
  • GoBalance Bug Puts Dark Web Sites at Risk of Hijacking
  • Malicious PDF App on Google Play Spreads Anatsa Trojan
  • US Dismantles Chinese Hacking Tools Targeting Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in React Server Components Puts Next.js Servers at Risk
  • Android Devices with Preinstalled Malware Threaten Users Globally
  • GoBalance Bug Puts Dark Web Sites at Risk of Hijacking
  • Malicious PDF App on Google Play Spreads Anatsa Trojan
  • US Dismantles Chinese Hacking Tools Targeting Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark