# FBI Disrupts Flax Typhoon Hacking Tools Targeting Critical Infra

> The FBI seized domains linked to Chinese state-sponsored Flax Typhoon, disrupting MicroScan and FishHub tools used to breach critical infrastructure worldwide.

- Published: 2026-10-09T03:40:53.000Z
- Severity: high
- Category: Threat Intel
- Tags: Integrity Technology Group, Critical Infrastructure, Flax Typhoon, MicroScan, FishHub
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/
- Canonical: https://runtimerebel.com/blog/fbi-disrupts-flax-typhoon-hacking-tools-targeting-critical-infra

## Key points

- Chinese state-sponsored hackers used MicroScan and FishHub tools to breach critical infrastructure and other organizations globally.
- Affected systems include U.S. government, critical manufacturing, healthcare, IT, and educational institutions worldwide.
- Organizations must review IoCs, patch vulnerable systems, and enforce multifactor authentication immediately.

## FBI Disrupts Chinese State-Sponsored Hacking Tools Targeting Critical Infrastructure

TheFederal Bureau of Investigation (FBI) has successfully disrupted operations by Chinese state-sponsored hackers, identified as [Flax Typhoon](https://en.wikipedia.org/wiki/APT40) (also tracked as Ethereal Panda and Red Juliett), by seizing seven domains associated with two key hacking platforms: MicroScan and FishHub. These tools, developed and operated by the China-based Integrity Technology Group (Integrity Tech), have been instrumental in widespread [vulnerability](/glossary#vulnerability) scanning and intrusions targeting critical infrastructure and other organizations across the United States and globally, as reported by [BleepingComputer](https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/).

The disruption highlights the Chinese government's reliance on contractors like Integrity Tech to expand its cyber espionage capabilities. The seized infrastructure was directly used to facilitate attacks that have compromised various sectors, emphasizing the urgent need for defenders to bolster their defenses against sophisticated state-backed threats.

## Technical Analysis of Flax Typhoon Critical Infrastructure Attacks

Integrity Technology Group, described by U.S. authorities as a contractor for the Chinese government, provided advanced capabilities to China-linked threat actors. The tools and infrastructure seized by the FBI were used for [reconnaissance](/glossary#reconnaissance), [initial access](/glossary#initial-access), and [data exfiltration](/glossary#data-exfiltration), demonstrating a multi-stage attack methodology.

### MicroScan Vulnerability Scanning Analysis

MicroScan is a Python-based vulnerability-scanning platform developed by Integrity Tech. It features over 1,300 penetration-testing scripts designed to identify security weaknesses in websites and services. According to an FBI seizure affidavit, MicroScan was deployed alongside a [botnet](/glossary#botnet) comprised of internet-connected devices infected with Mirai [malware](/glossary#malware) to scan potential targets. Targeted entities included a power company in South Carolina, airports in Japan and Poland, natural gas and electricity companies in Taiwan, and various universities.

Investigations confirmed that MicroScan's scanning activities led to successful breaches, notably at two Taiwanese universities whose networks were scanned in August 2022 and March 2023, followed by successful intrusions. While the FBI confirmed intrusions involving critical infrastructure, it did not specify if the named power companies, airports, or energy providers were successfully breached. The platform targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, and Jenkins. The attackers commonly exploited at least eight specific vulnerabilities, though their [CVE](/glossary#cve) [IDs](/glossary#ids) were not disclosed in the public information.

### FishHub for Spear-[Phishing](/glossary#phishing) and Data Exfiltration

FishHub served as the second primary platform, employed for conducting spear-phishing attacks and delivering additional malware to already compromised networks. This malware granted attackers unauthorized remote access, enabling them to search for specific files and exfiltrate sensitive data to Integrity Tech-controlled servers. An FBI seizure affidavit revealed that data and files belonging to over 20 organizations, including six universities in Taiwan, were discovered on a server linked to the FishHub data-theft tool.

Beyond these core platforms, the attackers utilized other tools such as the open-source EBurst for password-spraying attacks against Microsoft Exchange servers, as well as tools for stealing emails, collecting Active Directory credentials, and facilitating data exfiltration. A custom web application was also discovered, which allowed third parties to browse stolen emails without requiring direct access to the compromised accounts. [Persistence](/glossary#persistence) was often maintained through SoftEther [VPN](/glossary#vpn) software installed on victim systems.

**Affected Sectors and Domain Seizures:**

The joint cybersecurity advisory issued by the FBI, [CISA](/glossary#cybersecurity-and-infrastructure-security-agency-cisa), NSA, and international partners indicates that these operations targeted a broad spectrum of organizations, including U.S. government agencies, critical manufacturing, healthcare, information technology, law enforcement, educational institutions, and religious organizations, alongside entities in Southeast Asia, Africa, and North America.

The FBI successfully seized seven domains associated with these operations:
*   `c0cc.cc` (for MicroScan platform access)
*   `98aicai.com`, `98aicode.com`, `outlook3650.com`, `youtubecard.com`, `linkedinns.net` (for FishHub malware delivery)
*   `98aiblog.com` (linked to SoftEther VPN for remote access)

This disruption is not the first action against Integrity Tech; the Justice Department previously disrupted an Integrity Tech-operated Mirai botnet in September 2024, and the UK and EU sanctioned the company in 2025 and 2026, respectively, for its involvement in cyberattacks.

## Recommendations for Mitigating Chinese State-Sponsored Hacking Tools

Organizations must take immediate action to protect against these persistent and sophisticated threats. The joint advisory provides critical indicators of compromise (IoCs), including IP addresses, domains, and malware hashes, which should be integrated into detection systems.

Key recommendations for defenders include:

*   **Review Indicators of Compromise (IoCs):** Thoroughly examine network logs and security telemetry for any IoCs provided in the joint cybersecurity advisory to identify potential intrusions.
*   **[Patch](/glossary#patch) Vulnerable Systems:** Prioritize patching known vulnerabilities, especially in widely used software like Oracle WebLogic, Apache Struts, WordPress, and Jenkins, which were specifically targeted by these threat actors.
*   **Disable Unnecessary Exposed Services:** Reduce the [attack surface](/glossary#attack-surface) by disabling any services that are not essential and exposed to the internet.
*   **Enforce Multifactor Authentication ([MFA](/glossary#mfa)):** Implement and enforce MFA across all systems, particularly for remote access, email, and administrative accounts, to significantly reduce the risk of credential compromise through [password spraying](/glossary#password-spraying) and phishing attacks.

**Related:** [China-Linked Hackers Run Portal for Stolen Email Access](/blog/china-linked-hackers-run-portal-for-stolen-email-access), [Gunra Ransomware Exploits Fortinet Flaws and Bypasses MFA](/blog/gunra-ransomware-exploits-fortinet-flaws-and-bypasses-mfa)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/fbi-disrupts-flax-typhoon-hacking-tools-targeting-critical-infra
