Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Brazil’s Flavio Bolsonaro wins third-place candidate’s support against Lula

    October 9, 2026

    When politicians write bad erotic fiction – POLITICO

    October 9, 2026

    Labour fends off Green party to win Holborn and St Pancras byelection | Holborn and St Pancras byelection

    October 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Brazil’s Flavio Bolsonaro wins third-place candidate’s support against Lula
    • When politicians write bad erotic fiction – POLITICO
    • Labour fends off Green party to win Holborn and St Pancras byelection | Holborn and St Pancras byelection
    • Fired OpenAI safety researchers dispute misconduct claims, warn of chilling effect
    • ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
    • Cantor Faces Senate Scrutiny Over Tether, Lutnick Ties
    • Scientists found Homo erectus 200,000 years earlier than expected
    • French Protests: What History Can Tell Us About France’s Unrest
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    FBI disrupts Chinese hacking tools used to breach critical infrastructure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 9, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide.

    The seizures targeted infrastructure supporting the two hacking platforms allegedly operated by China-based Integrity Technology Group (Integrity Tech), which U.S. authorities say has contracts with the Chinese government.

    According to the U.S. Department of Justice, the tools were used to scan for vulnerabilities and breach critical infrastructure networks in the United States and other countries.

    “Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure,” said Brett Leatherman, assistant director of the FBI’s Cyber Division.

    Leatherman said the Chinese government relies on contractors and other companies to expand the reach of their cyber operations, and that disrupting these organizations makes it harder for China-linked hackers to target American networks.

    MicroScan is a vulnerability-scanning platform developed by Integrity Tech to identify security weaknesses in targeted networks.

    According to an FBI seizure affidavit, the platform was used along with a botnet of internet-connected devices infected with Mirai malware to scan potential targets.

    These targets include a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and electricity companies, and universities.

    The affidavit also confirms that the scanning activity led to successful breaches, including at two Taiwanese universities whose networks were scanned using MicroScan in August 2022 and March 2023 and subsequently breached.

    While the FBI confirmed that the hacking tools were used in intrusions involving critical infrastructure, it did not disclose whether the specifically named power companies, airports, and energy providers were successfully breached.

    The FBI seized the c0cc.cc domain used by Integrity Tech to access the MicroScan platform, which law enforcement confirmed was online in September 2026.

    The second platform, FishHub, was used to conduct spear-phishing attacks and deliver additional malware to networks already compromised.

    The malware gave attackers unauthorized remote access to victims’ networks and allowed them to search for specific files and exfiltrate data to servers controlled by Integrity Tech.

    According to the FBI seizure affidavit, investigators found data and files belonging to more than 20 organizations on a server linked to the FishHub data-theft tool, including six universities in Taiwan.

    Law enforcement seized five domains used to deliver the malware: 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, and linkedinns.net.

    A seventh seized domain, 98aiblog.com, was tied to the SoftEther VPN software installed on compromised systems to maintain remote access to victim networks.

    The seized domains now display FBI seizure notices identifying the Flax Typhoon hacking group and Integrity Technology Group.

    Flax Typhoon infrastructure seized by the DOJ
    Flax Typhoon infrastructure seized by the DOJ
    Source: BleepingComputer

    In coordination with the domain seizures, the FBI, CISA, NSA, and international partners issued a joint cybersecurity advisory explaining how Chinese government-linked hackers used Integrity Tech’s tools and infrastructure to compromise organizations and steal sensitive information.

    The advisory says the attackers targeted U.S. government agencies, critical manufacturing, healthcare, information technology, law enforcement, educational institutions, and religious organizations, as well as organizations in Southeast Asia, Africa, and North America.

    The activity overlaps with operations tracked as Flax Typhoon, Ethereal Panda, and Red Juliett, although the agencies say that not all activity may necessarily be linked to Integrity Tech.

    According to the advisory, MicroScan is a Python-based vulnerability scanner containing more than 1,300 penetration-testing scripts used to identify security flaws in websites and services.

    These scripts targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, Jenkins, and other applications.

    Investigators also identified eight vulnerabilities that were commonly targeted by the hackers:

    • CVE-2015-3306: ProFTPD unauthorized file read vulnerability.
    • CVE-2015-5477: ISC BIND denial-of-service vulnerability.
    • CVE-2016-3081: Apache Struts remote code execution vulnerability.
    • CVE-2021-3199: ONLYOFFICE DocumentServer unauthorized file write vulnerability.
    • CVE-2023-22894: Strapi information disclosure vulnerability.
    • CVE-2014-6278: GNU Bash (Shellshock) remote code execution vulnerability.
    • CVE-2019-11510: Pulse Secure VPN arbitrary file read vulnerability.
    • CVE-2021-22205: GitLab remote code execution vulnerability.

    The attackers also used the open-source EBurst tool to conduct password-spraying attacks against Microsoft Exchange servers, along with other tools to steal emails, collect Active Directory credentials, and exfiltrate data.

    The FBI also discovered a custom web application that let third parties browse stolen emails without needing direct access to the compromised accounts.

    The joint advisory contains indicators of compromise, including IP addresses, domains, malware hashes, and details of the attackers’ tools, to help organizations identify potential intrusions.

    Authorities are urging organizations to review the indicators, patch vulnerable systems, disable unnecessary exposed services, and enforce multifactor authentication to protect against attacks.

    This is not the first time US law enforcement disrupted Integrity Tech’s hacking infrastructure.

    In September 2024, the Justice Department disrupted an Integrity Tech-operated Mirai botnet consisting of more than 200,000 compromised consumer devices worldwide.

    The UK government also sanctioned Integrity Tech in 2025, and the European Union sanctioned the company in 2026 for involvement in cyberattacks targeting Europe and its allies.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    breach Chinese critical Disrupts FBI hacking infrastructure Tools
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

    Oracle Health Data Breach Tally Climbs to Nearly 20 Million

    SonicWall and Splunk Patch Critical Vulnerabilities

    Venezuelan Cartel’s Malware Honcho Nabbed for ATM Jackpotting

    Ransomware attack disrupts Japan’s IDCF Cloud used by govt clients

    FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Brazil’s Flavio Bolsonaro wins third-place candidate’s support against Lula

    October 9, 2026

    When politicians write bad erotic fiction – POLITICO

    October 9, 2026

    Labour fends off Green party to win Holborn and St Pancras byelection | Holborn and St Pancras byelection

    October 9, 2026

    Fired OpenAI safety researchers dispute misconduct claims, warn of chilling effect

    October 9, 2026
    Latest Posts

    Wisconsin’s partisan primary election is Tuesday. Learn more about who’s on your ballot.

    August 10, 2026

    Gabon ends fisheries partnership agreement with EU

    August 10, 2026

    Science backs calls for limiting screens in schools

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Brazil’s Flavio Bolsonaro wins third-place candidate’s support against Lula

    October 9, 2026

    When politicians write bad erotic fiction – POLITICO

    October 9, 2026

    Labour fends off Green party to win Holborn and St Pancras byelection | Holborn and St Pancras byelection

    October 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.