FBI seizes domains used by Chinese state-linked hackers in critical infrastructure attacks

Operation targets hacking tools MicroScan and FishHub, allegedly operated by Integrity Technology Group

By LineZotpaper
Published
Read Time3 min
The FBI has seized seven internet domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, that were used in attacks breaching critical infrastructure and other organizations worldwide, the U.S. Department of Justice announced Wednesday.

The seizures targeted infrastructure supporting the two hacking platforms allegedly operated by China-based Integrity Technology Group (Integrity Tech), which U.S. authorities say has contracts with the Chinese government.

According to the U.S. Department of Justice, the tools were used to scan for vulnerabilities and breach critical infrastructure networks in the United States and other countries.

"Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure," said Brett Leatherman, assistant director of the FBI's Cyber Division.

Leatherman said the Chinese government relies on contractors and other companies to expand the reach of their cyber operations, and that disrupting these organizations makes it harder for China-linked hackers to target American networks.

MicroScan is a vulnerability-scanning platform developed by Integrity Tech to identify security weaknesses in targeted networks. According to an FBI seizure affidavit, the platform was used along with a botnet of internet-connected devices infected with Mirai malware to scan potential targets. These targets included a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and electricity companies, and universities.

The affidavit also confirms that the scanning activity led to successful breaches, including at two Taiwanese universities whose networks were scanned using MicroScan in August 2022 and March 2023 and subsequently breached. While the FBI confirmed that the hacking tools were used in intrusions involving critical infrastructure, it did not disclose whether the specifically named power companies, airports, and energy providers were successfully breached.

The FBI seized the c0cc.cc domain used by Integrity Tech to access the MicroScan platform, which law enforcement confirmed was online in September 2026.

The second platform, FishHub, was used to conduct spear-phishing attacks and deliver additional malware to networks already compromised. The malware gave attackers unauthorized remote access to victims' networks and allowed them to search for specific files and exfiltrate data to servers controlled by Integrity Tech.

According to the FBI seizure affidavit, investigators found data and files belonging to more than 20 organizations on a server linked to the FishHub data-theft tool, including six universities in Taiwan. Law enforcement seized five domains used to deliver the malware: 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, and linkedinns.net. A seventh seized domain, 98aiblog.com, was tied to the SoftEther VPN software installed on compromised systems to maintain remote access to victim networks.

The seized domains now display FBI seizure notices identifying the Flax Typhoon hacking group and Integrity Technology Group.

§

Analysis

Why This Matters

  • The operation directly disrupts hacking tools used to target critical infrastructure, including a power company, airports, and energy providers.
  • It highlights the role of Chinese private contractors in enabling state-sponsored cyber operations.
  • The seizures may deter other companies from contracting with actors involved in such operations, but the impact is limited if replacement infrastructure is quickly deployed.

Background

China-based Integrity Technology Group has been accused by U.S. authorities of providing hacking tools to state-linked threat actors, including the group known as Flax Typhoon. The company reportedly has contracts with the Chinese government. This operation is part of ongoing efforts by the FBI and the Department of Justice to disrupt cyber operations targeting U.S. and allied critical infrastructure. Similar seizures have occurred in the past against other state-linked hacking groups.

Key Perspectives

U.S. law enforcement: The FBI and DOJ view the seizure as a significant disruption to China-linked cyber operations, emphasizing that targeting contractors makes it harder for state-sponsored hackers to operate. China's government and Integrity Tech: Chinese officials typically deny allegations of state-sponsored hacking, and Integrity Tech has not publicly commented. The company may characterize the tools as legitimate security products used for defensive purposes. National security analysts: Experts note that while seizures disrupt operations temporarily, sophisticated state-linked actors often have redundant infrastructure and can quickly adapt. The long-term impact depends on whether the operation leads to indictments or sanctions.

What to Watch

  • Whether U.S. authorities announce charges or sanctions against Integrity Technology Group or its executives.
  • Whether affected organizations, such as the South Carolina power company, confirm or deny breaches.
  • Any response from the Chinese government, including accusations of U.S. cyber aggression or calls for evidence.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.

How we workSubscribe