FBI Disrupts Chinese State-Sponsored Hacking Tools Targeting Critical Infrastructure
TheFederal Bureau of Investigation (FBI) has successfully disrupted operations by Chinese state-sponsored hackers, identified as Flax Typhoon (also tracked as Ethereal Panda and Red Juliett), by seizing seven domains associated with two key hacking platforms: MicroScan and FishHub. These tools, developed and operated by the China-based Integrity Technology Group (Integrity Tech), have been instrumental in widespread vulnerability scanning and intrusions targeting critical infrastructure and other organizations across the United States and globally, as reported by BleepingComputer.
The disruption highlights the Chinese government’s reliance on contractors like Integrity Tech to expand its cyber espionage capabilities. The seized infrastructure was directly used to facilitate attacks that have compromised various sectors, emphasizing the urgent need for defenders to bolster their defenses against sophisticated state-backed threats.
Technical Analysis of Flax Typhoon Critical Infrastructure Attacks
Integrity Technology Group, described by U.S. authorities as a contractor for the Chinese government, provided advanced capabilities to China-linked threat actors. The tools and infrastructure seized by the FBI were used for reconnaissance, initial access, and data exfiltration, demonstrating a multi-stage attack methodology.
MicroScan Vulnerability Scanning Analysis
MicroScan is a Python-based vulnerability-scanning platform developed by Integrity Tech. It features over 1,300 penetration-testing scripts designed to identify security weaknesses in websites and services. According to an FBI seizure affidavit, MicroScan was deployed alongside a botnet comprised of internet-connected devices infected with Mirai malware to scan potential targets. Targeted entities included a power company in South Carolina, airports in Japan and Poland, natural gas and electricity companies in Taiwan, and various universities.
Investigations confirmed that MicroScan’s scanning activities led to successful breaches, notably at two Taiwanese universities whose networks were scanned in August 2022 and March 2023, followed by successful intrusions. While the FBI confirmed intrusions involving critical infrastructure, it did not specify if the named power companies, airports, or energy providers were successfully breached. The platform targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, and Jenkins. The attackers commonly exploited at least eight specific vulnerabilities, though their CVE IDs were not disclosed in the public information.
FishHub for Spear-Phishing and Data Exfiltration
FishHub served as the second primary platform, employed for conducting spear-phishing attacks and delivering additional malware to already compromised networks. This malware granted attackers unauthorized remote access, enabling them to search for specific files and exfiltrate sensitive data to Integrity Tech-controlled servers. An FBI seizure affidavit revealed that data and files belonging to over 20 organizations, including six universities in Taiwan, were discovered on a server linked to the FishHub data-theft tool.
Beyond these core platforms, the attackers utilized other tools such as the open-source EBurst for password-spraying attacks against Microsoft Exchange servers, as well as tools for stealing emails, collecting Active Directory credentials, and facilitating data exfiltration. A custom web application was also discovered, which allowed third parties to browse stolen emails without requiring direct access to the compromised accounts. Persistence was often maintained through SoftEther VPN software installed on victim systems.
Affected Sectors and Domain Seizures:
The joint cybersecurity advisory issued by the FBI, CISA, NSA, and international partners indicates that these operations targeted a broad spectrum of organizations, including U.S. government agencies, critical manufacturing, healthcare, information technology, law enforcement, educational institutions, and religious organizations, alongside entities in Southeast Asia, Africa, and North America.
The FBI successfully seized seven domains associated with these operations:
c0cc.cc(for MicroScan platform access)98aicai.com,98aicode.com,outlook3650.com,youtubecard.com,linkedinns.net(for FishHub malware delivery)98aiblog.com(linked to SoftEther VPN for remote access)
This disruption is not the first action against Integrity Tech; the Justice Department previously disrupted an Integrity Tech-operated Mirai botnet in September 2024, and the UK and EU sanctioned the company in 2025 and 2026, respectively, for its involvement in cyberattacks.
Recommendations for Mitigating Chinese State-Sponsored Hacking Tools
Organizations must take immediate action to protect against these persistent and sophisticated threats. The joint advisory provides critical indicators of compromise (IoCs), including IP addresses, domains, and malware hashes, which should be integrated into detection systems.
Key recommendations for defenders include:
- Review Indicators of Compromise (IoCs): Thoroughly examine network logs and security telemetry for any IoCs provided in the joint cybersecurity advisory to identify potential intrusions.
- Patch Vulnerable Systems: Prioritize patching known vulnerabilities, especially in widely used software like Oracle WebLogic, Apache Struts, WordPress, and Jenkins, which were specifically targeted by these threat actors.
- Disable Unnecessary Exposed Services: Reduce the attack surface by disabling any services that are not essential and exposed to the internet.
- Enforce Multifactor Authentication (MFA): Implement and enforce MFA across all systems, particularly for remote access, email, and administrative accounts, to significantly reduce the risk of credential compromise through password spraying and phishing attacks.
Related: China-Linked Hackers Run Portal for Stolen Email Access, Gunra Ransomware Exploits Fortinet Flaws and Bypasses MFA