SecurityWeek

US Disrupts Chinese State-Sponsored Hacking Tools


The United States on Thursday announced the disruption of two hacking tools used by Chinese state-sponsored threat actors in attacks against US and foreign critical infrastructure.

Built by Integrity Technology Group (Integrity Tech), MicroScan has been used for vulnerability scanning, while FishHub has enabled network intrusions via spear phishing.

Integrity Tech, the US says, used a Mirai malware variant to build an IoT botnet that facilitated MicroScan’s use for reconnaissance against victims’ networks, including a US power company, NGOs, Japanese and Polish airports, and Taiwanese critical infrastructure entities and universities.

FishHub enabled Integrity Tech’s clients to access victim networks remotely, search for specific files, and exfiltrate them. The tool has been used in attacks against at least 20 universities in Taiwan.

The US seized the domains the threat actors were using to access MicroScan and FishHub, including c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net.

In 2024, the US disrupted Integrity Tech’s Raptor Train botnet, and in 2025 sanctioned it for providing cybersecurity products to Chinese state-sponsored APTs such as Flax Typhoon. The European Union sanctioned the company in March 2026.

Advertisement. Scroll to continue reading.

A new joint advisory (PDF) from government agencies in the US, UK, Australia, Canada, Japan, New Zealand, and Spain shows that MicroScan has been active since at least 2017, targeting Apache Struts, Juniper ScreenOS, Jenkins, OpenSSL, Oracle, Rejetto HFS, WebLogic Server, WordPress, and other services.

“This Python-based web application contains over 1,300 penetration testing scripts written to scan websites for specific vulnerabilities,” the advisory reads.

The tool was mainly associated with Flax Typhoon (also known as Ethereal Panda, Red Juliett, Storm-0919, and UNC5007) activity, but Integrity Tech is believed to have been working with other Chinese APTs as well.

Flax Typhoon was also seen using BBScan, dirsearch, Fscan, ksubdomain, masscan, Nmap, OneForAll, ShuiZe, and WPScan for reconnaissance, and command-line exploit utilities and the EBurst Microsoft Exchange password spraying tool for initial access.

The threat actors deployed VPN tools such as SoftEther for persistence and downloaded databases or manually extracted data from victims’ email addresses. They also used the PHP script Curlc4.txt and command-line utility office-cli for email exfiltration, and DC.ex to extract sensitive data from Active Directory.

“The threat actors collect account credentials and exfiltrate victim email data from on-premises systems and cloud-based services. Observed victims of email data theft included government organizations, law enforcement agencies, healthcare systems, and religious institutions located in Southeast Asia. In some instances, the threat actors restricted access to the exfiltrated data to only IP addresses from Xiamen, China,” the advisory reads.

Related: US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward

Related: Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks



Source link