Skip to main content
Threat IntelligenceEmerging Threats

US Seizes Flax Typhoon Hacking Tools in Cyber Crackdown

Federal law enforcement office with tech and cybersecurity elements, blurred computer equipment in foreground.
“Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide, including U.S. critical infrastructure sectors,” the joint advisory from the FBI, CISA and NSA warned Thursday.

The Justice Department and the FBI said Thursday they seized domain names tied to two hacking tools — Microscan, a vulnerability-scanning tool, and FishHub, a spearphishing tool — that U.S. agencies link to the China-based Integrity Technology Group and the China-linked group known as Flax Typhoon. The seizures, authorized by a court in the Western District of Pennsylvania, were unsealed the same day and paired with a multi-agency advisory aimed at denying access to the tools and warning of the techniques associated with them.

Court-authorized domain seizures in the Western District of Pennsylvania

Federal authorities obtained court authorization in the Western District of Pennsylvania to seize domain names that hosted Microscan and FishHub. The Justice Department and FBI unsealed documents tied to the operation Thursday and characterized the domain-name seizures as a measure to deny hackers access to the two tools developed by Integrity Technology Group.

Microscan and a Mirai-variant IoT botnet

Law enforcement said Microscan is a vulnerability-scanning tool that had been facilitated by a Mirai-variant botnet composed of internet-of-things (IoT) devices. According to the FBI and DOJ, Microscan’s scans and follow-on activity targeted a range of organizations, including a power company in South Carolina, airports in Japan and Poland, critical infrastructure companies, and universities in Taiwan.

FishHub: spearphishing followed by malware download

FishHub, the second tool the agencies seized, operates as a spearphishing platform that, after gaining access to victim networks, downloads additional malware. The FBI and DOJ specifically cite Taiwanese universities among FishHub’s victims. The agencies describe FishHub as part of the campaign of tools and infrastructure that Integrity Technology Group acquired or developed to support targeted operations.

Joint advisory from the FBI, CISA and NSA: techniques and persistence

The advisory released alongside the seizures lays out a set of tactics U.S. agencies attribute to Chinese government-linked actors enabled by Integrity Technology Group. Its language describes a combined toolkit: automated scanning tools, large-scale botnets, and “hands-on exploitation techniques.” The advisory adds that actors use scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers; they establish persistence through VPN software and exfiltrate emails and credentials using scripts.

The advisory frames the activity as affecting organizations globally and explicitly includes U.S. critical infrastructure sectors in its scope. Chris Butera, acting executive assistant director for cybersecurity at CISA, warned that “Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing.” Brett Leatherman, head of the FBI’s Cyber Division, said the FBI pursues both “the actors who threaten critical infrastructure and the enterprises that support them,” and identified Integrity Technology Group as “a China-based company with ties to the Chinese government” that hosts infrastructure and develops tools for actors targeting networks worldwide.

What this means for security teams, CISA and DOJ, and Taiwanese universities

  • Security teams: The seizures and advisory highlight the combination of automated scanning plus botnet-enabled scale and follow-on exploitation. Teams that operate or defend Microsoft Exchange servers, VPN endpoints, and email systems are direct targets of the techniques the advisory details, and should treat cross-site scripting, password spraying, and scripted credential exfiltration as specific operational threats described by U.S. agencies.
  • CISA and DOJ: Those agencies have paired law-enforcement disruption (domain seizures and court-authorized actions) with public technical guidance. The coordinated approach — legal action in the Western District of Pennsylvania while issuing a multi-agency advisory — signals an intent to combine disruption with public warnings to blunt immediate access to tools and raise awareness of the tactics in use.
  • Taiwanese universities: Named as victims of both Microscan and FishHub, these institutions exemplify how academic networks and research environments can be targeted by combined scanning, phishing, and botnet-enabled campaigns. The advisory’s focus on exfiltrated emails and credentials points to the specific loss vectors these victims have experienced.

The announcements also situate the Integrity Technology Group in a longer U.S. response timeline: the company was sanctioned “last year” and was the focus of a U.S. takedown operation in 2024 that linked it to a massive botnet. Those prior actions, and Thursday’s court-authorized seizures and joint advisory, form a sequence of disruption, designation and public technical warning aimed at degrading access to tools that U.S. agencies say enable the same spectrum of scanning, exploitation and exfiltration described in their advisory.

The government’s move to seize the domains and publicly name the tools crystallizes a strategy: defeat the infrastructure that enables mass scanning and phishing at scale, and publicly document the techniques operators use so defenders can react. Whether this combination of legal and advisory pressure reduces future activity tied to Microscan, FishHub, and the Integrity Technology Group will be one of the concrete outcomes to watch after Thursday’s announcements.

Read the original CyberScoop report