FBI Seized Vulnerability Scanning and Spear Phishing Tools Used by China-Linked Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


The FBI and U.S. Justice Department have seized seven domains tied to Microscan and FishHub, two hacking tools allegedly operated by China-based Integrity Technology Group. Announced on October 8, 2026, the court-authorized action aims to cut access to systems used to scan critical infrastructure, support spear phishing, and steal files from compromised networks.

Court documents unsealed in the Western District of Pennsylvania link the activity to Flax Typhoon, a hacking group tracked by security researchers. Authorities say Integrity Technology Group has Chinese government contracts and supplied tools that helped its clients find weak systems and gain unauthorized access. The operation targets supporting infrastructure rather than establishing that every affected network is now secure.

Compromised Devices Into Scanning Infrastructure

According to the Justice Department announcement, Integrity Tech built a botnet of internet-connected devices infected with a Mirai malware variant. The company used this network, alongside other infrastructure, to run Microscan against potential targets and identify weaknesses its clients could later exploit.

It is important to note that a scan can find possible entry points into a network, but it does not prove that the network has been breached. Some of the targets for these scans included a power company in South Carolina, airports in Japan and Poland, natural gas and power companies in Taiwan, a multinational NGO, and two universities in Taiwan.

The joint cybersecurity advisory describes MicroScan as a Python-based web application containing more than 1,300 penetration testing scripts. These scripts checked websites and services for specific vulnerabilities, including weaknesses affecting Oracle WebLogic Server, WordPress, Jenkins, Apache Struts, OpenSSL, and Juniper ScreenOS. Investigators traced its use back to at least 2017.

The dashboard reproduced in the advisory shows vulnerability totals, scan status, and plugin rankings. It illustrates how operators could manage large numbers of findings through a central interface. The seized domain c0cc[.]cc provided access to Microscan, making it a direct target for disrupting that scanning workflow.

FishHub Supported Spear Phishing Attack

FishHub served a different purpose. Prosecutors allege that the tool supported spear phishing, then downloaded additional malware after attackers gained an initial foothold. That malware could give Integrity Tech clients remote network access or locate specific files and transfer them to servers controlled by the company.

Confirmed FishHub victims included approximately 20 Taiwanese universities. This is separate from the two Taiwanese universities named among Microscan scanning targets; the announcement does not establish whether those groups overlap. Keeping those figures distinct avoids confusing systems checked for weaknesses with networks confirmed as victims of FishHub activity.

Five seized domains supported malware delivery: 98aicai[.]com, 98aicode[.]com, linkedinns[.]net, outlook3650[.]com, and youtubecard[.]com.

A seventh domain, 98aiblog[.]com, was tied to SoftEther VPN software used to maintain unauthorized remote access. Together with c0cc[.]cc, these domains covered scanning access, malware delivery, and persistent connections to compromised systems.

The latest seizures follow the September 2024 court-authorized disruption of an Integrity Tech botnet containing more than 200,000 consumer devices worldwide. That earlier network included routers, IP cameras, digital video recorders, and network-attached storage devices. Attackers used those compromised devices to disguise malicious activity as ordinary internet traffic.

Cybersecurity News previously reported Flax Typhoon’s botnet exploitation of 66 vulnerabilities, providing background on the group’s use of weaknesses in routers, connected devices, and web-facing applications. The new action focuses on infrastructure supporting scanning and intrusion tools, showing why disrupting one botnet does not necessarily end the wider hacking operation

“By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure,” said Brett Leatherman, assistant director of the FBI’s Cyber Division.

His comments highlight the role of contractors that provide the tools and systems behind these attacks. The seizures aim to limit those services while giving defenders evidence to investigate possible breaches within their own networks.

The new FBI-led advisory provides indicators of compromise and details of related intrusion methods. Beyond Microscan, investigators observed password spraying against Microsoft Exchange interfaces, VPN-based persistence, and automated email theft. These findings describe the broader activity enabled by Integrity Tech and should not all be treated as confirmed FishHub features.

Defenders should compare historical DNS, proxy, firewall, and endpoint logs against the published indicators, then investigate matching activity in context.

The agencies recommend patching exposed systems, disabling unused services, requiring multifactor authentication, and reviewing cloud applications with access to sensitive data. They also urge monitoring for unexpected VPN installations, unusual account activity, and large outbound transfers.

Organizations that find signs of compromise should isolate affected hosts, preserve relevant logs, and investigate the full intrusion before removing attacker access. Domain seizures can disrupt key connections, but defenders still need to identify stolen credentials, remaining malware, and other access paths inside their networks.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post FBI Seized Vulnerability Scanning and Spear Phishing Tools Used by China-Linked Hackers appeared first on Cyber Security News.