Key points
- US authorities seized seven domains supporting Integrity Technology Group’s MicroScan and FishHub hacking tools, as detailed in court documents unsealed in the Western District of Pennsylvania.
- A joint advisory from the FBI, CISA, the NSA, the ASD’s Australian Cyber Security Centre and partner agencies linked the Chinese firm to activity tracked as Flax Typhoon, Ethereal Panda and Red Juliett.
- Although Australia was not named among the victim locations, the ASD says the vulnerabilities and techniques outlined are applicable to Australian entities and urges organisations to mitigate the threat.
The Australian Signals Directorate (ASD) has added its name to a joint warning about China’s Integrity Technology Group, with US authorities seizing infrastructure supporting two of the Chinese firm’s hacking tools.
The US Justice Department and Federal Bureau of Investigation said they seized seven domains supporting MicroScan, a vulnerability scanner, and FishHub, a spear phishing tool, court documents unsealed in the Western District of Pennsylvania show.
Integrity Technology Group holds contracts with the Chinese government, the DoJ alleged.
The domain seizures coincided with a joint advisory from the FBI, CISA, the NSA and the ASD’s Australian Cyber Security Centre, alongside agencies from the UK, Canada, Japan, New Zealand and Spain.
It said the actors Integrity Technology Group enables use techniques consistent with activity tracked as Flax Typhoon, Ethereal Panda and Red Juliett.
Australia, however, did not appear among the victim locations the advisory named.
Instead, it listed US critical infrastructure sectors including government, critical manufacturing, healthcare and IT, plus organisations in Southeast Asia, Africa and North America.
An ASD spokesperson told iTnews that the Australian government is concerned by the persistent and enduring campaign of malicious cyber activity carried out globally by state and non-state cyber actors.
“While Australia is not specifically named, the vulnerabilities, tactics, techniques and procedures outlined in this advisory are applicable to Australian entities,” the spokesperson said.
“Therefore, we encourage organisations to mitigate the threat,” the spokesperson added.
Built portal for easy access to purloined emails
The actors maintained a custom web application that provided “third-party access to stolen email content”, the advisory said.
Users of the application could view a given account’s email by passing arguments in a URL.
The FBI recovered an archived email database taken from government organisations, law enforcement agencies, healthcare systems and religious institutions in Southeast Asia.
In some cases, access to the stolen data was restricted to IP addresses in Xiamen, China.
Turning to the seizures, Integrity Technology Group accessed MicroScan through c0cc.cc, one of the seized domains, the Justice Department said.
MicroScan itself held more than 1300 penetration testing scripts targeting products including Oracle WebLogic, Jenkins, Apache Struts and Juniper ScreenOS, the advisory said.
The scanner has been in use since 2017, the advisory added.
Confirmed FishHub victims included about 20 Taiwanese universities.
A further domain was tied to unauthorised remote administration software that connected several victims’ networks to an Integrity Technology Group server.
The seizures announced were the US authorities’ second public technical disruption of Integrity Technology Group.
In September 2024, a court-authorised operation took down the company’s Mirai botnet of more than 200,000 consumer devices.
The US Treasury then sanctioned Integrity Technology Group in January 2025.
Much of the reconnaissance tooling is off-the-shelf, including open source scanners such as Fscan, masscan and dirsearch, which the advisory said suggests the actors tend to look for more vulnerable targets.
The threat actors also used a tool called DC.exe to perform DCSync, abusing Active Directory replication to copy credentials and trust relationships from domain controllers.
The agencies recommend multifactor authentication for webmail, VPNs and critical systems, monitoring cloud accounts for connected applications, watching for unexpected Active Directory replication, and replacing end-of-life products.

