The seizures targeted infrastructure supporting the two hacking platforms allegedly operated by China-based Integrity Technology Group (Integrity Tech), which U.S. authorities say has contracts with the Chinese government.
According to the U.S. Department of Justice, the tools were used to scan for vulnerabilities and breach critical infrastructure networks in the United States and other countries.
"Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure," said Brett Leatherman, assistant director of the FBI's Cyber Division.
Leatherman said the Chinese government relies on contractors and other companies to expand the reach of their cyber operations, and that disrupting these organizations makes it harder for China-linked hackers to target American networks.
MicroScan is a vulnerability-scanning platform developed by Integrity Tech to identify security weaknesses in targeted networks. According to an FBI seizure affidavit, the platform was used along with a botnet of internet-connected devices infected with Mirai malware to scan potential targets. These targets included a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and electricity companies, and universities.
The affidavit also confirms that the scanning activity led to successful breaches, including at two Taiwanese universities whose networks were scanned using MicroScan in August 2022 and March 2023 and subsequently breached. While the FBI confirmed that the hacking tools were used in intrusions involving critical infrastructure, it did not disclose whether the specifically named power companies, airports, and energy providers were successfully breached.
The FBI seized the c0cc.cc domain used by Integrity Tech to access the MicroScan platform, which law enforcement confirmed was online in September 2026.
The second platform, FishHub, was used to conduct spear-phishing attacks and deliver additional malware to networks already compromised. The malware gave attackers unauthorized remote access to victims' networks and allowed them to search for specific files and exfiltrate data to servers controlled by Integrity Tech.
According to the FBI seizure affidavit, investigators found data and files belonging to more than 20 organizations on a server linked to the FishHub data-theft tool, including six universities in Taiwan. Law enforcement seized five domains used to deliver the malware: 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, and linkedinns.net. A seventh seized domain, 98aiblog.com, was tied to the SoftEther VPN software installed on compromised systems to maintain remote access to victim networks.
The seized domains now display FBI seizure notices identifying the Flax Typhoon hacking group and Integrity Technology Group.