The United States has announced a significant disruption of hacking tools employed by Chinese state-backed threat actors. These tools, identified as MicroScan and FishHub, have been implicated in cyberattacks on critical infrastructure globally, including in the US.
Targeted Network Vulnerability Scanning
MicroScan, developed by Integrity Technology Group, was specifically designed for scanning network vulnerabilities. It played a crucial role in breaches involving entities from various sectors such as energy, non-governmental organizations, and international airports in Japan and Poland. The application was reportedly utilized to execute reconnaissance operations, facilitated by a Mirai malware variant IoT botnet.
FishHub, another tool from Integrity Tech, enabled threat actors to infiltrate networks and extract sensitive information. This tool was notably used against numerous Taiwanese universities, allowing unauthorized access and data exfiltration.
Government Action Against Cyber Threats
In response, US authorities have seized control of domains linked to these malicious operations, including addresses like c0cc[.]cc and outlook3650[.]com. This move is part of broader efforts to counteract cybersecurity threats posed by state-sponsored hacking activities.
Previously, the US had taken down the Raptor Train botnet in 2024 and imposed sanctions on Integrity Tech in 2025 for its affiliations with Chinese APTs, including Flax Typhoon. The European Union followed suit with sanctions in March 2026, highlighting the international scope of these cybersecurity challenges.
Ongoing Cybersecurity Challenges
A joint advisory from multiple countries, including the US, UK, and Australia, has revealed that MicroScan has been operational since at least 2017. It has targeted a wide range of services, from Apache Struts to WordPress, using a comprehensive set of penetration testing scripts.
Flax Typhoon, also known by other names such as Ethereal Panda, has been linked to a variety of reconnaissance tools beyond MicroScan. These include BBScan and Nmap, among others. The group has also utilized advanced techniques for accessing and extracting data, often focusing on email accounts from government and healthcare institutions in Southeast Asia.
This coordinated international response underscores the persistent threat posed by Chinese hacking groups and the importance of continued vigilance in protecting digital infrastructure worldwide.
