A coalition of cybersecurity agencies has seized websites and tools tied to Integrity Technology Group, a Beijing-based firm that U.S. officials say provided Chinese state-backed hackers with capabilities to scan for vulnerabilities and breach critical infrastructure organizations around the world.
The Justice Department seized domains underpinning two tools, called Microscan and FishHub, that Integrity Tech built to support the long-running Flax Typhoon campaign. FBI Assistant Director Brett Leatherman said the company supplied China-linked threat actors with capabilities used for widespread vulnerability scanning and, in some cases, intrusions against U.S. and foreign critical infrastructure.
What the tools did
Microscan, in use since 2017, ran automated penetration-testing scripts to scan websites for specific vulnerabilities. Victims reportedly included a South Carolina power company, airports in Japan and Poland, and Taiwanese natural gas and power companies. FishHub accelerated phishing operations and let hackers deploy malware onto victim networks after a breach, with its remote access used specifically against roughly 20 Taiwanese universities.
A 58-page joint advisory, drawn from multiple FBI incident response investigations, details other Integrity Tech-linked tools, including EBurst, used for password spraying and guessing against Microsoft Exchange accounts. Investigators said they recovered an archived email database used to target government, law enforcement, healthcare and religious organizations across Southeast Asia, with stolen data in some cases restricted to viewing only from IP addresses in Xiamen, China.
Targeting edge devices
CISA and the NSA said Integrity Tech typically focused on edge devices that receive little security monitoring, allowing attackers to maintain long-term, covert access. CISA’s acting executive assistant director for cybersecurity, Chris Butera, said Chinese government hackers continue positioning themselves inside critical infrastructure networks, including operational technology systems, to enable future disruption.
Australia, Japan, the UK, Spain, New Zealand and Canada all contributed to the advisory. The UK National Cyber Security Centre’s Paul Chichester said the breadth of targeted sectors demonstrates the scale of the threat.
A familiar target
This marks the latest U.S. action against Integrity Tech. In September 2024, the DOJ dismantled a Mirai-based botnet tied to the company that comprised more than 260,000 devices, taking control of Flax Typhoon’s infrastructure. Microsoft first publicly identified Flax Typhoon in 2023 and has tracked victims across Taiwan, Southeast Asia, North America and Africa. Integrity Tech, founded in 2010 by Cai Jingjing, is also known in China for building government-funded cyber ranges used to simulate real-world networks and systems.
