
The US Justice Department and FBI have seized the domains of a company linked to the Flax Typhoon cyber crime group, disrupting access to two hacking tools.
The tools, Microscan and FishHub, were used to scan and compromise critical infrastructure systems and other networks in the US and around the world.
Integrity Technology Group, a China-based company with contracts with the Chinese government, is believed to be behind the activity, which has been linked with campaigns known as Flax Typhoon, Ethereal Panda and Red Juliett, amongst others.
The threat actors use a unique combination of large-scale botnets, VPN infrastructure, living off the land (LOTL) techniques, and repositories of computer network exploitation (CNE) tools.
“Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting US and foreign critical infrastructure,” said assistant director Brett Leatherman of the FBI’s Cyber Division.
“The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure.”
According to US officials, Integrity Tech developed Microscan to conduct reconnaissance, via the botnet and otherwise, of victim computer networks for vulnerabilities that its clients would later exploit.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
A Python-based web application, Microscan contains over 1,300 penetration testing scripts written to scan websites for specific vulnerabilities. The threat actors used these scripts to target services including OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts.
Targets included a US power company based in South Carolina, a multi-national NGO, Japanese and Polish airports, Taiwanese critical infrastructure companies in the natural gas and power sectors, and two Taiwanese universities.
Spear phishing campaign targeted corporate networks
Meanwhile, a second tool, FishHub, is believed to have played a part in the exploitation of computer networks through spear phishing.
After an initial network compromise, FishHub downloaded additional malware to the victim network, giving Integrity Tech’s clients unauthorized remote access. It also searched for specific files and sent them to servers controlled by the group. Confirmed victims included around 20 Taiwanese universities.
"The extensive malicious cyber activities, and services by Integrity Tech, that have been exposed today should be extremely concerning for all network defenders," said Paul Chichester, director of Operations at the UK's National Cyber Security Centre (NCSC).
"The breadth of sectors that have been targeted across the globe demonstrate the extent of the threat and all organizations should take note of this warning."
Last year, the UK government sanctioned Integrity Tech, alongside another China-based information security company, known as i-Soon, for their part in malicious cyber activity.
“These state-sponsored hackers continue to aggressively target and access networks and systems throughout the world in an effort to identify and steal files and otherwise exploit victims’ vulnerabilities,” said attorney Troy Rivetti for the Western District of Pennsylvania.
“These seizures, our second disruption of Integrity Tech’s massive operations in as many years, send another clear message to cybercriminals from the PRC and elsewhere of the department’s dedication to defending and maintaining cybersecurity in the United States and abroad.