Securityaffairs

US Disrupts China-Linked Integrity Tech ‘s Cyber Espionage Tools


US Disrupts China-Linked Integrity Tech ‘s Cyber Espionage Tools

Pierluigi Paganini
October 09, 2026

DOJ and FBI seized China-linked hacking tools Microscan and FishHub, linked to Integrity Tech and attacks on critical infrastructure worldwide.

The Justice Department and FBI took down two hacking tools this week, Microscan and FishHub, both built and run by a Beijing-based company with direct government contracts. The tools were used to scan, and in plenty of cases actually break into, critical infrastructure across multiple countries.

“Today the Justice Department and FBI announced court-authorized seizures to deny malicious cyber actors access to two hacking tools, “Microscan” and “FishHub,” used to scan and, in some cases, hack, U.S. and foreign critical infrastructure systems and other networks.” DoJ states. “As alleged in court documents unsealed in the Western District of Pennsylvania, malicious cyber actors working for Integrity Technology Group (Integrity Tech), a company based in the People’s Republic of China (PRC), operated and used the tools. Integrity Tech has contracts with the PRC government.”

The company behind the tools is Integrity Technology Group. Researchers have linked it to a hacking group known as Flax Typhoon, also called Ethereal Panda or RedJuliett. This is not the first time U.S. authorities have targeted the company. Assistant U.S. Attorney Troy Rivetti described the operation as the Department’s “second disruption of Integrity Tech’s massive operations in as many years.” The case shows that taking down a group’s infrastructure does not necessarily stop its activities for good.

Integrity Tech built and ran a botnet made up of infected Internet of Things (IoT) devices running a version of the Mirai malware. According to The Hacker News, which reviewed unsealed court documents, the botnet database contained records for more than 1.2 million infected devices in June 2024. More than 385,000 were located in the United States. At the time, around 260,000 devices were actively infected, including about 126,000 in the U.S.

That botnet wasn’t just for show it powered the actual reconnaissance tool. Microscan, accessed through the now-seized domain c0cc.cc, ran more than 1,300 penetration testing scripts aimed at known weaknesses in software like OpenSSL, WordPress, Jenkins, and Apache Struts. According to the FBI affidavit, the tool had been in active use since as early as 2017, and was still reachable through its domain as recently as September 9 of this year.

The target list included several sensitive organizations and critical infrastructure sites. Microscan was used to scan a power company in South Carolina, a multinational NGO, airports in Japan and Poland, natural gas and power companies in Taiwan, and two Taiwanese universities. FishHub used spear-phishing emails instead. Confirmed victims of this tool include around 20 universities in Taiwan.

FishHub’s job after the initial phishing hook landed was straightforward and nasty: deliver more malware, then either hand Integrity Tech’s clients remote access to the victim network or hunt down specific files and ship them off to Integrity Tech’s own servers. Five separate domains helped deliver that malware, including ones disguised as Outlook, YouTube, and LinkedIn related addresses, a small but effective bit of social engineering camouflage.

“Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division. “The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure.”

That’s the real point of this takedown. Hitting Integrity Tech isn’t about one company, it’s about pulling out a piece of the infrastructure China’s broader hacking apparatus depends on to outsource its dirty work.

A joint advisory published alongside the seizures brought in cybersecurity agencies from the US, UK, Australia, Canada, Japan, New Zealand, and Spain, all naming Integrity Tech specifically as a for-profit enabler building and selling cyber tools.

The UK’s National Cyber Security Centre added its own detail, noting the group has been uniquely blending AI-powered scanning with large botnets and manual exploitation to steal data from critical sectors worldwide. Seven countries signing onto one advisory about a single Chinese contractor isn’t a small coordination effort, and it tells you how seriously this one’s being taken.

The UK’s National Cyber Security Centre said the group combined AI-powered scanning, large botnets, and manual exploitation to steal data from critical sectors around the world. Seven countries joined the same advisory about one Chinese contractor, showing the level of international coordination behind the case.

The action came in the same week that the U.S. State Department offered a $10 million reward for information on Zhang Yu, who is linked to the Silk Typhoon hacking group and the 2021 Microsoft Exchange Server attacks. Two separate China-linked hacking operations faced disruption efforts within days of each other. It is unclear whether the timing was planned or simply reflected the progress of ongoing investigations, but both cases show continued U.S. efforts to target Chinese cyber operations.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, China)







Source link