“Based on my training and experience I believe the tool was named FishHub because it facilitated phishing activity,” FBI special agent Adam James wrote in a seizure-warrant affidavit unsealed Thursday.
Seven court-authorized domain seizures and FishHub delivery
The FBI announced it seized seven web domains linked to a suite of hacking tools allegedly operated by Integrity Technology Group. Five of those domains — 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net — “delivered the FishHub malware as recently as March,” the seizure documents state. Those infections reached roughly 20 Taiwanese universities, according to the same filings.
Another seized domain, c0cc[.]cc, is identified in the court papers as the access point for Microscan, a vulnerability-scanning tool that the government says Integrity Tech used to map targets’ networks. The warrant affidavit describes FishHub’s behavior: after downloading a file onto victims’ computers, that file contacted the five domains to retrieve additional malicious programs, created file listings, searched for specific files, compressed documents, and exfiltrated selected files to attacker-controlled servers — actions that gave remote access to compromised networks.
Allegations tying Integrity Technology Group to Flax Typhoon and the PRC
Court documents unsealed Thursday allege Integrity Technology Group had contracts with the PRC government and long link the firm to a Beijing-backed cybercrew known to U.S. authorities as Flax Typhoon. The federal filings allege Integrity Tech developed a Mirai-based botnet, the Microscan vulnerability scanner, and the post-compromise tool FishHub; prosecutors say Flax Typhoon used those tools to hide its IP addresses and geographic origin while launching intrusions.
The court papers describe Flax Typhoon conducting “successful computer intrusions against multiple victim entities which had been scanned using the Microscan tool.” The seizures are described as the latest in a long series of U.S. law-enforcement efforts to disrupt that crew and dismantle its botnet infrastructure.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageHow Microscan, FishHub and botnets were used against critical networks
The government’s security alert and court filings detail a pattern: actors enabled by Integrity Tech used botnets, malware, and other intrusion tools to scan networks for vulnerabilities and steal sensitive data. The advisory identifies a set of tactics including scanning tools, cross-site scripting attacks, password spraying on Microsoft Exchange servers, establishing persistence via VPN software, and exfiltrating emails and credentials using scripts.
Specific incidents named in the filings include compromises of a university in Hsinchu, Taiwan, in March 2023 and a separate university in Puli Township, Taiwan, in August 2022. The documents allege that on or about April 26, 2022, and December 29, 2022, Flax Typhoon actors used Microscan to scan the networks of a U.S. power company based in South Carolina, a multi-national non-governmental organization, Japanese and Polish airports, and at least two Taiwanese critical-infrastructure companies in the natural gas and power sectors.
CISA’s Known Exploited Vulnerabilities additions and the international advisory
In response to the activity described in the advisory, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five specific vulnerabilities to its Known Exploited Vulnerabilities Catalog: CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, and CVE-2023-22894. The FBI and six other countries — the U.K., Australia, Canada, Japan, New Zealand, and Spain — also issued a joint warning that Chinese government-linked attackers enabled by Integrity Tech were using these tools to target organizations worldwide and to steal sensitive data, including from U.S. critical infrastructure networks.
The advisory echoed earlier multinational warnings. In April, a 10-country joint advisory said several Chinese “Typhoon” groups use botnets “strategically, and at scale,” and it named Chinese infosec companies, including Integrity Tech, as builders and maintainers of some covert networks such as the so-called Raptor Train. In February, OT security provider Dragos said the overlapping group focused on gaining long-term access to OT engineering workstations and exfiltrating operational files from manufacturing, defense, automotive, electric power, oil and gas, and government organizations across the U.S., Europe, and Asia-Pacific.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams — The seizures and the CISA listings provide concrete artifacts: domain names, tool names (Microscan and FishHub), and five CVE identifiers that defenders can hunt for and block. The advisory’s list of techniques — scanning, XSS, password spraying, VPN persistence, script-based exfiltration — narrows the behaviors to monitor in logs and network telemetry.
- Policymakers and regulators — The court filings alleging contracts between Integrity Tech and the PRC government, together with a coordinated international advisory, create a record that law-enforcement and intergovernmental partners can use to justify further legal and diplomatic action and to prioritize cross-border takedowns or sanctions.
- Affected enterprises — Names and dates in the filings (for example, scans of a South Carolina power company on April 26 and December 29, 2022, and multiple Taiwanese university compromises) give incident responders and threat-hunting teams specific leads to examine for residual compromise and data exfiltration timelines.
The seizures and the public advisories lay out a detailed chain of tools, domains, and exploited flaws. The court documents allege links between those tools and a private firm with PRC government contracts; CISA’s CVE listings and a multinational warning translate that allegation into operational countermeasures. Whether those disruptions permanently degrade the toolset described in the filings, or simply force its operators to rebuild, is a concrete question now left to investigators and defenders.




