The FBI, in collaboration with the U.S. Justice Department, has successfully seized seven domains associated with Microscan and FishHub, two hacking tools allegedly run by China-based Integrity Technology Group. This legal action, revealed on October 8, 2026, aims to disrupt access to systems used for scanning critical infrastructure, supporting spear phishing, and illicitly acquiring files from compromised networks.
Connection to Chinese Hacking Group
Unsealed court documents in the Western District of Pennsylvania have connected this activity to Flax Typhoon, a hacking group closely monitored by cybersecurity experts. These documents suggest that Integrity Technology Group, which has contracts with the Chinese government, provided tools to clients enabling them to exploit vulnerable systems and gain unauthorized access. The operation primarily targets the underlying infrastructure without confirming the security of every affected network.
Integrity Tech reportedly constructed a botnet comprising internet-connected devices infected with a variant of Mirai malware. This network was used in conjunction with other infrastructures to run Microscan, identifying weaknesses that clients could exploit. Despite the capability to find potential entry points, these scans do not confirm network breaches.
Microscan and FishHub Operations
The joint cybersecurity advisory describes Microscan as a Python-based web application with over 1,300 penetration testing scripts designed to identify specific vulnerabilities in various systems. These include Oracle WebLogic Server, WordPress, Jenkins, Apache Struts, OpenSSL, and Juniper ScreenOS. The advisory includes a dashboard that illustrates how operators manage numerous findings centrally. The domain c0cc[.]cc, which facilitated access to Microscan, was among those seized to disrupt the scanning operations.
FishHub served a different purpose by supporting spear phishing attacks. Prosecutors allege the tool enabled malware downloads following initial access, allowing clients remote network access and the ability to transfer targeted files to controlled servers. Around 20 Taiwanese universities were confirmed as victims of FishHub, separate from those targeted by Microscan.
Impact and Recommendations
The seized domains also include 98aicai[.]com, 98aicode[.]com, linkedinns[.]net, outlook3650[.]com, and youtubecard[.]com, which supported malware delivery. The domain 98aiblog[.]com was linked to unauthorized remote access via SoftEther VPN software. These actions follow a previous court-authorized disruption in September 2024, which dismantled a botnet of over 200,000 consumer devices worldwide.
Brett Leatherman, assistant director of the FBI’s Cyber Division, emphasized the importance of disrupting enablers of such operations to hinder potential attacks on American networks and infrastructure. The advisory offers indicators of compromise and details on intrusion methods. Organizations are advised to patch vulnerable systems, disable unused services, enforce multifactor authentication, and monitor for suspicious activities.
Entities detecting signs of compromise should isolate affected systems, preserve logs, and conduct thorough investigations before removing access. While domain seizures can disrupt malicious connections, it remains crucial for defenders to identify stolen credentials and other access paths within networks.
