Skip to main content
Threat IntelligenceEmerging Threats

FBI Seizes Chinese Hacking Tools Used to Breach Critical Infrastructure

Law enforcement agent examines computer screen with network diagram and globe in background.

"Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure," said Brett Leatherman, assistant director of the FBI's Cyber Division.

FBI seizure: seven domains and visible takedowns

The FBI has seized seven domains used by a China-linked group tracked as Flax Typhoon to operate two distinct hacking platforms, MicroScan and FishHub. Law enforcement described the seized infrastructure as supporting platforms allegedly operated by China-based Integrity Technology Group, which U.S. authorities say has contracts with the Chinese government. The domains now display FBI seizure notices identifying Flax Typhoon and Integrity Technology Group.

The domains seized include:

  • c0cc.cc — the domain the FBI says Integrity Tech used to access the MicroScan platform (confirmed online in September 2026)
  • 98aicai.com
  • 98aicode.com
  • outlook3650.com
  • youtubecard.com
  • linkedinns.net
  • 98aiblog.com — tied to SoftEther VPN software installed on compromised systems

MicroScan, Mirai, and the scanning that preceded intrusions

MicroScan is described by investigators as a Python-based vulnerability-scanning platform developed by Integrity Tech. According to the FBI seizure affidavit, MicroScan contains more than 1,300 penetration-testing scripts used to identify security flaws in websites and services, and it was used alongside a Mirai botnet of internet-connected devices infected with Mirai malware to scan potential targets.

Targets listed in the affidavit that were scanned by MicroScan include a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and electricity companies, and universities. The affidavit confirms that MicroScan scanning activity led to successful breaches, including at two Taiwanese universities whose networks were scanned in August 2022 and March 2023 and subsequently breached. The FBI said it had confirmed the tools were used in intrusions involving critical infrastructure, but did not disclose whether the specifically named power companies, airports, and energy providers were successfully breached.

Investigators identified eight vulnerabilities the attackers commonly targeted; the advisory lists them explicitly:

  • CVE-2015-3306: ProFTPD unauthorized file read
  • CVE-2015-5477: ISC BIND denial-of-service
  • CVE-2016-3081: Apache Struts remote code execution
  • CVE-2021-3199: ONLYOFFICE DocumentServer unauthorized file write
  • CVE-2023-22894: Strapi information disclosure
  • CVE-2014-6278: GNU Bash (Shellshock) remote code execution
  • CVE-2019-11510: Pulse Secure VPN arbitrary file read
  • CVE-2021-22205: GitLab remote code execution

FishHub, spear-phishing, SoftEther, and data theft

The second platform, FishHub, was used to conduct spear-phishing campaigns and to deliver malware into already compromised networks. The FBI affidavit states that the malware provided attackers with unauthorized remote access, allowed them to search for specific files, and exfiltrate data to servers controlled by Integrity Tech.

Investigators found data and files belonging to more than 20 organizations on a server linked to FishHub, including six universities in Taiwan. Law enforcement identified five domains used to deliver the malware — 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, and linkedinns.net — and a seventh domain, 98aiblog.com, associated with SoftEther VPN installations that helped maintain remote access on compromised systems.

Joint advisory, tools used, and concrete mitigations

In coordination with the domain seizures, the FBI, CISA, NSA, and international partners issued a joint cybersecurity advisory explaining how Chinese government-linked hackers used Integrity Tech's tools and infrastructure. The advisory names sectors targeted by the activity — U.S. government agencies, critical manufacturing, healthcare, information technology, law enforcement, educational institutions, and religious organizations — and also notes operations against organizations in Southeast Asia, Africa, and North America.

The advisory says the activity overlaps with operations tracked as Flax Typhoon, Ethereal Panda, and Red Juliett, while cautioning that not all operations may be linked to Integrity Tech. It also catalogs additional tactics: the use of the open-source EBurst tool for password-spraying against Microsoft Exchange servers, other tools to steal emails and collect Active Directory credentials, and a custom web application that allowed third parties to browse stolen emails without direct access to compromised accounts.

Authorities included indicators of compromise — IP addresses, domains, malware hashes, and tool details — and urged organizations to review those indicators, patch vulnerable systems, disable unnecessary exposed services, and enforce multifactor authentication.

What this means for technologists, policymakers, and affected organizations

  • Technologists and security teams: The advisory provides actionable IoCs and specific CVEs to prioritize. Teams are being urged to patch the named vulnerabilities, harden exposed services, search for SoftEther VPN implants, and enforce multifactor authentication to mitigate credential theft and remote access abuses.
  • Policymakers and regulators: U.S. law enforcement's action joins prior steps against Integrity Tech — including a September 2024 disruption of an Integrity Tech-operated Mirai botnet of more than 200,000 devices, a UK government sanction in 2025, and a European Union sanction in 2026 — underscoring a pattern of coordinated legal and diplomatic measures referenced in the advisory.
  • Affected enterprises and procurement leaders: The affidavit and advisory highlight the risks of contractor-developed offensive tooling. Organizations that match the targeted sectors — especially utilities, airports, universities, and government agencies named in the advisory — will need to reconcile incident response findings with the domains and IoCs published by the agencies.

The seizures and advisory make explicit what the affidavit states: contractor-operated tools and outsourced infrastructure can amplify the reach of state-linked cyber operations. For defenders the immediate work is concrete — apply the patches, inspect for the listed IoCs, and lock down authentication paths; for investigators and policymakers the action is also tactical and strategic, a reminder that disrupting infrastructure — from Mirai botnets to command-and-control domains — remains part of the response playbook.

Original story