Skip to main content
Threat IntelligenceEmerging Threats

FBI Disrupts Flax Typhoon Tools Used in US Critical Infrastructure Intrusions

Rows of computer equipment racks and servers in a generic server room or network operations center.

"Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure," said Assistant Director Brett Leatherman of the FBI's Cyber Division.

Domains seized and the immediate disruption

The U.S. Federal Bureau of Investigation and Department of Justice announced they seized seven domains and blocked access to platforms tied to malicious tools used by a China-linked advanced persistent threat tracked as Flax Typhoon (also known as Ethereal Panda and RedJuliett). The seized domains, listed by the agencies, are:

  • c0cc[.]cc
  • 98aiblog[.]com
  • 98aicai[.]com
  • 98aicode[.]com
  • outlook3650[.]com
  • youtubecard[.]com
  • linkedinns[.]net

The FBI affidavit cited that the Python-based tool Microscan was accessible via c0cc[.]cc as recently as September 9, 2026, and that other infrastructure and platforms were blocked as part of the disruption.

Integrity Technology Group, Flax Typhoon, and the botnet record

Court filings and agency statements link Flax Typhoon activity to Integrity Technology Group, a Beijing-based company that contracts with the Chinese government. The group has previously been associated with a botnet dubbed Raptor Train, composed of thousands of compromised small office/home office (SOHO) and IoT devices; that botnet was taken down following a U.S. court-authorized operation in September 2024.

According to the FBI, a database server hosted at 202.182.109[.]151 contained records for more than 1.2 million infected devices as of June 5, 2024, including over 385,000 unique U.S. victim devices. On that same date, more than 260,000 devices — approximately 126,000 of them in the United States — were actively infected. Court documents allege Integrity Tech created and operated the IoT botnet using a variant of the Mirai malware and controlled it with an application named Sparrow.

Microscan, FishHub and technical tradecraft described

Agencies described two principal tools tied to Integrity Tech's operations. Microscan, a Python-based web tool originally hosted on 198.13.53[.]226, reportedly contains over 1,300 penetration-testing scripts to scan for specific vulnerabilities — including OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts. The scanner was used alongside open-source tools mentioned by the FBI, including BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe, and wpscan.

FishHub is alleged to have enabled spear-phishing attacks and deployment of follow-on payloads; the Department of Justice said it "provided Integrity Tech's clients with unauthorized remote access to the victim network or searched for specific files and sent them to servers controlled by Integrity Tech." Confirmed FishHub victims included 20 Taiwanese universities.

Other techniques and tooling named by the agencies include installation of SoftEther VPN clients for persistence, use of EBurst (an open-source Python brute-force tool) to target Microsoft 365 accounts, and a command-line utility known as office-cli to access mailbox data. The threat actors have also used Python- and Go-based command line utilities and cross-site scripting (XSS) attacks for credential harvesting since at least mid-January 2021, according to the advisory.

Impacted victims and allied advisory

The FBI and DoJ identified targeted victims across multiple countries and sectors: a U.S. power company in South Carolina, a multi-national non-governmental organization, airports in Japan and Poland, Taiwanese companies in the natural gas and power sectors, and two Taiwanese universities. The agencies noted widespread use of automated scanning, large-scale botnets, and manual exploitation techniques to compromise and steal confidential data.

In tandem with the enforcement action, cybersecurity and intelligence agencies from the U.S., the U.K., Australia, Canada, Japan, New Zealand, and Spain issued a joint advisory calling out Integrity Technology Group for acquiring or building cyber tools for use and sale and for compromising networks — characterizing the company as an enabler of malicious cyber actors worldwide. The U.K. National Cyber Security Centre stated that malicious actors enabled by Integrity Tech are "uniquely using AI tools, such as automated scanning, alongside large-scale botnets and manual exploitation techniques."

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: the FBI affidavit ties active infrastructure (domains and IPs) to tools — Microscan and FishHub — and lists specific indicators and toolsets (e.g., c0cc[.]cc, 198.13.53[.]226, 202.182.109[.]151, Microscan’s 1,300+ scripts, and use of SoftEther, EBurst, and office-cli). Teams will weigh those artifacts when hunting for compromise and prioritizing remediation.
  • Policymakers and regulators: U.S. and allied agencies framed Integrity Tech as a for-profit enabler used by state-linked actors, a point that features in the joint advisory and in public statements by the FBI and DoJ; regulators may use the disruption and the advisory as evidence in policy discussions about third-party cyber contractor risk.
  • Affected enterprises and procurement leaders: organizations in critical infrastructure sectors and higher education — both named among confirmed victims — will note that scanning and phishing tools were applied at scale and that compromise paths included cloud mailboxes and persistent VPN clients, factors relevant to vendor risk assessments and incident response planning.

The disruption removes key domains and interrupts tooling the FBI says were still accessible in September 2026, but the affidavit’s device records — over 1.2 million infections logged on a server as of June 2024 — underscore a persistent scale problem: tools and botnets can be taken down, yet the footprint of compromise and the commercial sale of capabilities remain central questions for investigators and the organizations they protect.

Original story