The FBI has seized seven domains tied to two hacking platforms allegedly built and operated by China-based Integrity Technology Group, disrupting tools used by the state-sponsored group known as Flax Typhoon to scan for vulnerabilities and breach critical infrastructure networks worldwide.

According to the Department of Justice, Integrity Tech, which U.S. authorities say holds contracts with the Chinese government, provided China-linked threat actors with MicroScan and FishHub, two platforms used for widespread vulnerability scanning and, in some cases, successful intrusions against U.S. and foreign critical infrastructure.

MicroScan: Mass Scanning at Scale

MicroScan is a Python-based vulnerability scanner containing more than 1,300 penetration-testing scripts targeting widely used software including Oracle WebLogic, Apache Struts, WordPress, and Jenkins. Per an FBI seizure affidavit, the platform was paired with a Mirai-based botnet of compromised internet-connected devices to scan potential targets, which included a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and electricity companies, and multiple universities.

The affidavit confirms the scanning led to actual breaches, including at two Taiwanese universities compromised after MicroScan scans in August 2022 and March 2023. The FBI did not disclose whether the named power companies, airports, or energy providers were successfully breached, only that the tools were used in intrusions involving critical infrastructure. The FBI seized the c0cc.cc domain used to access MicroScan, which was still online as of September 2026.

FishHub: Data Theft and Remote Access

The second platform, FishHub, was used for spear-phishing and to deliver additional malware onto already-compromised networks, granting attackers remote access and the ability to search for and exfiltrate specific files to Integrity Tech-controlled servers. Investigators found stolen data and files from more than 20 organizations, including six Taiwanese universities, on a server linked to FishHub.

Law enforcement seized five domains used to deliver FishHub malware (98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, and linkedinns.net) along with a seventh domain, 98aiblog.com, tied to SoftEther VPN software installed to maintain persistent remote access on victim networks. All seized domains now display FBI seizure notices naming Flax Typhoon and Integrity Technology Group.

Joint Advisory and Broader Targeting

The FBI, CISA, NSA, and international partners issued a joint advisory alongside the seizures detailing how the tools and infrastructure were used to compromise U.S. government agencies, critical manufacturing, healthcare, IT, law enforcement, educational, and religious organizations, as well as targets in Southeast Asia, Africa, and North America. The activity overlaps with operations tracked as Flax Typhoon, Ethereal Panda, and Red Juliett, though agencies caution not all activity may be directly linked to Integrity Tech. The FBI’s Cyber Division said disrupting contractor-run infrastructure like this makes it harder for Chinese state-linked actors to extend their reach into American networks.