FBI disrupts Chinese hacking tools used to breach critical infrastructure
According to BleepingComputer's report, the domains supported tools allegedly developed and operated by China-based Integrity Technology Group, a company U.S.
By Dillip Chowdary • Oct 10, 2026 • Source: BleepingComputer
The FBI seized seven domains tied to Chinese state-sponsored hackers known as Flax Typhoon, dismantling the infrastructure behind two cyberattack platforms — MicroScan and FishHub — that Beijing-linked operatives used to breach critical infrastructure across the United States and multiple other countries. According to BleepingComputer's report, the domains supported tools allegedly developed and operated by China-based Integrity Technology Group, a company U.S. authorities say holds contracts with the Chinese government.
This article covers what each seized platform does, which organizations were targeted, the specific vulnerabilities attackers exploited, and what defenders should do right now. It is aimed at security teams, IT administrators, and anyone running systems connected to critical infrastructure, higher education networks, or government agencies.
What broke in FBI disrupts Chinese hacking tools used
The FBI's October 2026 domain seizures knocked out the command infrastructure for both MicroScan and FishHub, two distinct platforms that Integrity Technology Group developed and made available to China-linked threat actors. MicroScan is a Python-based vulnerability scanner containing more than 1,300 penetration-testing scripts. The FBI confirmed that the platform was used alongside a Mirai-based botnet of infected internet-connected devices to scan and probe targets, and that one of its control domains, c0cc.cc, was still active as recently as September 2026.
FishHub served a different but complementary purpose: spear-phishing attacks designed to deliver additional malware into networks that had already been compromised through scanning activity. Once implanted, that malware granted attackers unauthorized remote access, the ability to search for specific files, and the ability to exfiltrate data to servers controlled by Integrity Tech. Five FishHub-linked domains were seized — 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, and linkedinns.net — along with 98aiblog.com, which was tied to SoftEther VPN software used to maintain persistent remote access on compromised machines.
Who is exposed by FBI disrupts Chinese hacking tools used

The scope of targeting was broad. MicroScan was used against a South Carolina power company, airports in Japan and Poland, and natural gas and electricity companies in Taiwan. Investigators confirmed that two Taiwanese universities whose networks were scanned in August 2022 and March 2023 were subsequently breached. FishHub infrastructure exposed data from more than 20 organizations stored on a single linked server, including six universities in Taiwan. The FBI stopped short of confirming whether the named power companies, airports, and energy providers were successfully penetrated.
A joint advisory issued simultaneously by the FBI, CISA, NSA, and international partners identified the broader target list: U.S. government agencies, critical manufacturing, healthcare, information technology, law enforcement, educational institutions, and religious organizations, as well as entities in Southeast Asia, Africa, and North America. The advisory noted that the observed activity overlaps with campaigns tracked separately as Flax Typhoon, Ethereal Panda, and Red Juliett, though the agencies cautioned that not all activity attributed to those clusters necessarily ties back to Integrity Tech.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
What to do now about FBI disrupts Chinese hacking tools used
The joint advisory published alongside the seizures includes indicators of compromise: IP addresses, domains, malware hashes, and tool details that organizations can use to hunt for signs of intrusion. Security teams should review those indicators immediately and cross-check them against network logs, particularly for connections to the seven now-seized domains and any SoftEther VPN installations that were not internally authorized. Brett Leatherman, assistant director of the FBI's Cyber Division, stated that disrupting Integrity Tech makes it harder for China-linked hackers to target American networks, but emphasized that defenders must take their own action.
Authorities are specifically urging organizations to patch systems affected by the eight CVEs investigators found in active use, disable unnecessary internet-exposed services, and enforce multifactor authentication across all remote access points. The eight flagged vulnerabilities span a wide range of products — ProFTPD, ISC BIND, Apache Struts, ONLYOFFICE DocumentServer, Strapi, GNU Bash (Shellshock), Pulse Secure VPN, and GitLab — some dating back to 2014. Unpatched legacy systems carrying decade-old flaws remain live targets.
How the FBI disrupts Chinese hacking tools used issue works
MicroScan's 1,300-plus scripts targeted widely deployed software including Oracle WebLogic, Apache Struts, WordPress, and Jenkins. Attackers paired that scanning capability with EBurst, an open-source tool, to run password-spraying attacks against Microsoft Exchange servers. After gaining initial access, the group used additional tooling to steal emails, harvest Active Directory credentials, and stage data for exfiltration. Investigators also found a custom-built web application that allowed third-party clients to browse stolen emails without needing direct access to the compromised accounts — a feature that points to Integrity Tech operating something closer to a commercial intrusion-as-a-service offering than a traditional state intelligence unit.
FishHub's malware component extended the access established through initial scanning by creating persistent remote footholds. Once installed, it let operators search victim file systems for targeted data and route it back to Integrity Tech-controlled servers. The SoftEther VPN component, distributed through 98aiblog.com, gave attackers a secondary persistence mechanism that would survive the removal of other malware. The layered architecture — scanner, phishing delivery, remote access, VPN persistence, and a browse-stolen-mail portal — reflects a mature, division-of-labor operation rather than opportunistic hacking.
What is still unknown about FBI disrupts Chinese hacking tools used
The FBI confirmed that MicroScan scans led to confirmed breaches at the two Taiwanese universities but explicitly declined to state whether the other specifically named targets — the South Carolina power company, the Japanese and Polish airports, or the Taiwanese gas and electricity providers — were successfully penetrated. The extent of data actually exfiltrated from the more than 20 organizations whose files appeared on the FishHub server also remains undisclosed; the advisory confirmed the server existed and data was present, but did not detail volumes, sensitivity levels, or whether victims have been individually notified.
It is also unclear how many distinct threat actors had access to Integrity Tech's platforms. The advisory noted that not all Flax Typhoon, Ethereal Panda, and Red Juliett activity necessarily links back to Integrity Tech, suggesting the infrastructure may have served multiple client groups. This is not the first disruption of Integrity Tech: in September 2024, the Justice Department dismantled an Integrity Tech-operated Mirai botnet of more than 200,000 compromised consumer devices. The UK sanctioned Integrity Tech in 2025, and the European Union sanctioned the company in 2026 for cyberattacks targeting Europe and its allies. Whether those prior actions slowed the group's tempo before this month's seizures has not been addressed.
Developer Action Items
- ☐ Inventory whether Python runs in prod, CI, staging, or on laptops before you debate severity.
- ☐ Confirm the vendor's fixed build for Python from BleepingComputer, then schedule the patch window.
- ☐ If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
- ☐ Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.
- ☐ Treat unexpected emails that mention Python (shipping, invoices, password resets) as phishing until verified.
FBI disrupts Chinese hacking tools used FAQ
What are MicroScan and FishHub?
MicroScan is a Python-based vulnerability scanner with more than 1,300 penetration-testing scripts developed by Integrity Technology Group. FishHub is a spear-phishing and data-theft platform used to deliver malware and exfiltrate files from already-compromised networks.
Which domains did the FBI seize?
The seven seized domains are c0cc.cc (MicroScan), 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, linkedinns.net (all FishHub), and 98aiblog.com (SoftEther VPN persistence).
Which CVEs are actively being exploited in these attacks?
Eight CVEs were flagged: CVE-2015-3306 (ProFTPD), CVE-2015-5477 (ISC BIND), CVE-2016-3081 (Apache Struts RCE), CVE-2021-3199 (ONLYOFFICE), CVE-2023-22894 (Strapi), CVE-2014-6278 (Shellshock), CVE-2019-11510 (Pulse Secure VPN), and CVE-2021-22205 (GitLab RCE).
Who is Integrity Technology Group?
Integrity Technology Group is a China-based company that U.S. authorities say holds contracts with the Chinese government and developed MicroScan and FishHub for use by China-linked threat actors. The UK sanctioned it in 2025 and the EU sanctioned it in 2026.
What should organizations do right now?
Review the indicators of compromise in the joint FBI-CISA-NSA advisory, patch the eight flagged CVEs, remove unauthorized SoftEther VPN installations, disable unnecessary internet-exposed services, and enforce multifactor authentication on all remote access systems.
Sources
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
Read →
Liquid AI's d1 is available on AI Gateway
Read →
HomeKit Weekly: Onvis releases a Matter over Thread outdoor smart plug with energy…
Read →
Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
Read →
Today's Tech Pulse briefing
Full briefing →
Advertisement