Breaking
Cyber CrimeDeveloping Story

FBI Seizes Domains Tied to Chinese Hacking Tools

The FBI has seized seven domains linked to Chinese state-sponsored hackers, disrupting two key platforms used in attacks on critical infrastructure.

··1 hour ago·5 min read
a rack of electronic equipment in a dark room
Photo by Tyler on Unsplash

The FBI has seized seven domains that Chinese state-sponsored hackers used to operate two intrusion platforms, MicroScan and FishHub. The domains formed the backbone of attack infrastructure tied to Integrity Technology Group, a China-based company that U.S. authorities say holds contracts with the Chinese government. The move follows prior disruptions of the same company's hacking network, and it arrives alongside a multi-agency advisory warning that the tools were used to scan and breach critical networks worldwide.

Two Platforms, One Operation

MicroScan and FishHub served different but complementary roles in the attackers' toolkit. MicroScan was a vulnerability-scanning platform built by Integrity Tech to find security weaknesses in targeted networks. FishHub, by contrast, was used for spear-phishing campaigns and for delivering additional malware into networks that were already compromised.

Together, the platforms supported the full attack chain: identifying vulnerable systems, gaining a foothold, and then expanding access and stealing data. The FBI confirmed the tools were used in intrusions involving critical infrastructure, though it did not disclose whether every named target—including power companies, airports, and energy providers—was successfully breached.

Domains Now Show Seizure Notices

The seizures targeted the infrastructure behind both platforms. The FBI took down the c0cc.cc domain, which Integrity Tech used to access the MicroScan platform. Law enforcement confirmed that domain was online in September 2026. Five other domains used to deliver malicious payloads were also seized: 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, and linkedinns.net.

A seventh domain, 98aiblog.com, was tied to SoftEther VPN software installed on compromised systems to maintain remote access to victim networks. All seven domains now display FBI seizure notices that identify the Flax Typhoon hacking group and Integrity Technology Group.

Confirmed Breaches at Universities

The FBI's seizure affidavit ties MicroScan scanning activity directly to successful intrusions. Two Taiwanese universities had their networks scanned using MicroScan in August 2022 and March 2023, and both were subsequently breached. The scanner was deployed alongside a botnet of internet-connected devices infected with Mirai malware, which helped it probe potential targets at scale.

Other targets scanned by the platform included a South Carolina power company, airports in Japan and Poland, and Taiwanese natural gas and electricity companies. The affidavit confirms scanning led to breaches but does not specify whether the named power companies, airports, and energy providers were among those successfully compromised.

Stolen Data from 20+ Organizations

FishHub's reach extended well beyond scanning. Investigators found data and files belonging to more than 20 organizations on a server linked to the FishHub data-theft tool, including six universities in Taiwan. The malware gave attackers unauthorized remote access to victims' networks, allowing them to search for specific files and exfiltrate data to servers controlled by Integrity Tech.

The FBI also discovered a custom web application that let third parties browse stolen emails without needing direct access to the compromised accounts. That tooling suggests the operation was built not just to break in, but to make stolen data easily accessible to others within the group's orbit.

Joint Advisory Details the Tooling

In coordination with the domain seizures, the FBI, CISA, NSA, and international partners issued a joint cybersecurity advisory explaining how Chinese government-linked hackers used Integrity Tech's tools and infrastructure to compromise organizations and steal sensitive information.

The advisory says the attackers targeted U.S. government agencies, critical manufacturing, healthcare, information technology, law enforcement, educational institutions, and religious organizations, as well as organizations in Southeast Asia, Africa, and North America. The activity overlaps with operations tracked as Flax Typhoon, Ethereal Panda, and Red Juliett, though the agencies note that not all activity may necessarily be linked to Integrity Tech.

"Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure."

— Brett Leatherman, assistant director of the FBI's Cyber Division

Leatherman added that the Chinese government relies on contractors and other companies to expand the reach of their cyber operations, and that disrupting these organizations makes it harder for China-linked hackers to target American networks.

Hundreds of Exploits, Eight CVEs

According to the advisory, MicroScan is a Python-based vulnerability scanner containing more than 1,300 penetration-testing scripts used to identify security flaws in websites and services. Those scripts targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, Jenkins, and other applications.

Investigators also identified eight vulnerabilities that were commonly targeted by the hackers:

  • CVE-2015-3306: ProFTPD unauthorized file read vulnerability.
  • CVE-2015-5477: ISC BIND denial-of-service vulnerability.
  • CVE-2016-3081: Apache Struts remote code execution vulnerability.
  • CVE-2021-3199: ONLYOFFICE DocumentServer unauthorized file write vulnerability.
  • CVE-2023-22894: Strapi information disclosure vulnerability.
  • CVE-2014-6278: GNU Bash (Shellshock) remote code execution vulnerability.
  • CVE-2019-11510: Pulse Secure VPN arbitrary file read vulnerability.
  • CVE-2021-22205: GitLab remote code execution vulnerability.

The attackers also used the open-source EBurst tool to conduct password-spraying attacks against Microsoft Exchange servers, along with other tools to steal emails, collect Active Directory credentials, and exfiltrate data.

Prior Disruptions and Sanctions

This is not the first time U.S. law enforcement has moved against Integrity Tech's hacking infrastructure. In September 2024, the Justice Department disrupted an Integrity Tech-operated Mirai botnet consisting of more than 200,000 compromised consumer devices worldwide.

The UK government also sanctioned Integrity Tech in 2025, and the European Union sanctioned the company in 2026 for involvement in cyberattacks targeting Europe and its allies. Those actions show a sustained, multi-country effort to constrain the company's operations, even as its tooling continued to appear in new campaigns.

Why It Matters for Defenders

The seizures and the advisory give organizations a concrete set of indicators to check against their own networks. The joint advisory contains indicators of compromise, including IP addresses, domains, malware hashes, and details of the attackers' tools, to help organizations identify potential intrusions.

Authorities are urging organizations to review those indicators, patch vulnerable systems, disable unnecessary exposed services, and enforce multifactor authentication to protect against attacks. For security teams, the most actionable takeaway may be the list of eight CVEs and the scanning behavior tied to MicroScan—signals that can be hunted for in logs even if an organization was not named in the affidavit.

The disruption of specific domains does not necessarily end the threat. The advisory notes that not all activity may be linked to Integrity Tech, and the company's history of reappearing in new operations suggests that defenders should treat this as one chapter in a longer campaign. Organizations that rely on the targeted software—from Oracle WebLogic to GitLab—would be well served to confirm their patch levels and monitor for the scanning patterns described in the advisory.

Reporting based on original coverage from BleepingComputer.

#fbi#integrity tech#flax typhoon#state-sponsored hacking#critical infrastructure

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories