Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Endangered angelshark is still traded in Brazil despite import ban

    October 10, 2026

    Trump says Ukraine needs a new president who will agree to end the war | Russia-Ukraine war News

    October 10, 2026

    Trump’s shock Russia deal highlights mounting pressure to curb fuel prices

    October 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Endangered angelshark is still traded in Brazil despite import ban
    • Trump says Ukraine needs a new president who will agree to end the war | Russia-Ukraine war News
    • Trump’s shock Russia deal highlights mounting pressure to curb fuel prices
    • 3 days to Disrupt 2026: Meet the startups before they hit mainstream
    • US Disrupts Chinese State-Sponsored Hacking Tools
    • BTCPay Tor access becomes opt-in at the next Docker update
    • Scientists may have found a shortcut to fusion energy
    • Guest opinion: Wisconsin should stop erasing ‘street time’ after prison
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    US Disrupts Chinese State-Sponsored Hacking Tools

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 10, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The United States on Thursday announced the disruption of two hacking tools used by Chinese state-sponsored threat actors in attacks against US and foreign critical infrastructure.

    Built by Integrity Technology Group (Integrity Tech), MicroScan has been used for vulnerability scanning, while FishHub has enabled network intrusions via spear phishing.

    Integrity Tech, the US says, used a Mirai malware variant to build an IoT botnet that facilitated MicroScan’s use for reconnaissance against victims’ networks, including a US power company, NGOs, Japanese and Polish airports, and Taiwanese critical infrastructure entities and universities.

    FishHub enabled Integrity Tech’s clients to access victim networks remotely, search for specific files, and exfiltrate them. The tool has been used in attacks against at least 20 universities in Taiwan.

    The US seized the domains the threat actors were using to access MicroScan and FishHub, including c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net.

    In 2024, the US disrupted Integrity Tech’s Raptor Train botnet, and in 2025 sanctioned it for providing cybersecurity products to Chinese state-sponsored APTs such as Flax Typhoon. The European Union sanctioned the company in March 2026.

    Advertisement. Scroll to continue reading.

    A new joint advisory (PDF) from government agencies in the US, UK, Australia, Canada, Japan, New Zealand, and Spain shows that MicroScan has been active since at least 2017, targeting Apache Struts, Juniper ScreenOS, Jenkins, OpenSSL, Oracle, Rejetto HFS, WebLogic Server, WordPress, and other services.

    “This Python-based web application contains over 1,300 penetration testing scripts written to scan websites for specific vulnerabilities,” the advisory reads.

    The tool was mainly associated with Flax Typhoon (also known as Ethereal Panda, Red Juliett, Storm-0919, and UNC5007) activity, but Integrity Tech is believed to have been working with other Chinese APTs as well.

    Flax Typhoon was also seen using BBScan, dirsearch, Fscan, ksubdomain, masscan, Nmap, OneForAll, ShuiZe, and WPScan for reconnaissance, and command-line exploit utilities and the EBurst Microsoft Exchange password spraying tool for initial access.

    The threat actors deployed VPN tools such as SoftEther for persistence and downloaded databases or manually extracted data from victims’ email addresses. They also used the PHP script Curlc4.txt and command-line utility office-cli for email exfiltration, and DC.ex to extract sensitive data from Active Directory.

    “The threat actors collect account credentials and exfiltrate victim email data from on-premises systems and cloud-based services. Observed victims of email data theft included government organizations, law enforcement agencies, healthcare systems, and religious institutions located in Southeast Asia. In some instances, the threat actors restricted access to the exfiltrated data to only IP addresses from Xiamen, China,” the advisory reads.

    Related: US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward

    Related: Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

    Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

    Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

    Chinese Disrupts hacking statesponsored Tools
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison

    ARTEX AI, Claude agents used in cyberattacks on South Korean banks

    Cyber exec arrested in case allegedly tied to ShinyHunters hackers

    Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws

    Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management

    The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn’t

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Endangered angelshark is still traded in Brazil despite import ban

    October 10, 2026

    Trump says Ukraine needs a new president who will agree to end the war | Russia-Ukraine war News

    October 10, 2026

    Trump’s shock Russia deal highlights mounting pressure to curb fuel prices

    October 10, 2026

    3 days to Disrupt 2026: Meet the startups before they hit mainstream

    October 10, 2026
    Latest Posts

    Trump media group racks up losses and pushes into nuclear fusion

    August 10, 2026

    Live: Russian missiles strike Kyiv, triggering fires in city centre

    August 10, 2026

    Dragon roars with record power in Faroe Islands: Minesto hits new tidal energy output milestone

    August 11, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Endangered angelshark is still traded in Brazil despite import ban

    October 10, 2026

    Trump says Ukraine needs a new president who will agree to end the war | Russia-Ukraine war News

    October 10, 2026

    Trump’s shock Russia deal highlights mounting pressure to curb fuel prices

    October 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.