LIVE · cybersecurity feed
Live wire
security

DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub

The U.S. Justice Department and FBI have announced the seizure of two hacking tools, Microscan and FishHub, which are linked to the Chinese government-affiliated group Flax Typhoon and the China-based firm Integrity Technology Group. The seizures, authorized by a court in the Western District of Pennsylvania, aim to disrupt access to these tools by denying hackers their domain names.

ZeroDay News ·

Source: CyberScoop

The U.S. Justice Department and FBI have announced the seizure of two hacking tools, Microscan and FishHub, which are linked to the Chinese government-affiliated group Flax Typhoon and the China-based firm Integrity Technology Group. The seizures, authorized by a court in the Western District of Pennsylvania, aim to disrupt access to these tools by denying hackers their domain names.

Microscan is described as a vulnerability scanning tool, while FishHub is a spearphishing tool designed to download malware onto compromised networks. Integrity Technology Group, which allegedly developed and operated these tools, was previously sanctioned by the U.S. government last year and was the focus of a 2024 takedown operation for its alleged involvement in a large botnet.

The announcement was accompanied by a joint advisory from the FBI, Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA). This advisory warns that Chinese government-linked cyber threat actors, facilitated by Integrity Technology Group, are employing automated scanning, large-scale botnets, and hands-on exploitation to steal sensitive data from organizations globally, including U.S. critical infrastructure.

These actors are reported to exploit vulnerabilities using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers. They establish persistence through VPN software and exfiltrate emails and credentials using custom scripts. Integrity Technology Group is also alleged to have leveraged a Mirai-variant botnet of internet-of-things devices to support Microscan's operations.

Targets of Microscan have reportedly included a power company in South Carolina, airports in Japan and Poland, and critical infrastructure companies and universities in Taiwan. Taiwanese universities have also been identified as victims of FishHub.

Chris Butera, acting executive assistant director for cybersecurity at CISA, stated that Chinese government-affiliated actors are strategically positioning themselves within critical infrastructure networks, including operational technology (OT) systems, with the intent to disrupt critical functions at a future time of their choosing.

Brett Leatherman, head of the FBI’s Cyber Division, emphasized the FBI's strategy to pursue both the threat actors and the enterprises that support them. He identified Integrity Technology Group as one such enterprise, noting its role in acquiring or developing cyber tools and hosting infrastructure for actors targeting networks worldwide.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

'AgentCorruption' Puts AWS Environments At Risk With Single Prompt

A recently disclosed vulnerability, dubbed 'AgentCorruption,' reportedly allowed attackers to compromise AWS environments through a single prompt directed at an AI chatbot. The flaw, now patched, was identified within AWS Bedrock AgentCore and could have enabled an attacker to gain control over an organization's entire fleet of AI agents.

ai

Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal

More than 100 members of Congress have urged Google and Spirit Airlines to halt a proposed $10 million deal that would transfer Spirit's internal data to Google for the purpose of training artificial intelligence models. The lawmakers expressed significant concerns that even with de-identification safeguards, the data could still expose sensitive employee information.

ransomware

Ransomware attack disrupts Japan's IDCF Cloud used by govt clients

IDC Frontier, a prominent Japanese cloud and digital infrastructure provider, has confirmed that its IDCF Cloud service was targeted in a ransomware attack. The incident, which began on October 7 at 3:40 AM local time, led to an outage at a data center cluster serving Japan's eastern region.

ransomware

Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions

Zohar Pinhasi, the owner and operator of the ransomware recovery firm MonsterCloud, has been indicted on charges of wire fraud and wire fraud conspiracy. Authorities allege that Pinhasi defrauded hundreds of clients by claiming to decrypt their data using proprietary tools without paying ransoms, while in reality, he secretly paid cybercriminals and then charged his clients significantly…

security

Italy’s Foreign Ministry Under Cyberattack as Embassy Sites Come Under Review

Italy's Ministry of Foreign Affairs confirmed on October 8, 2026, that its website was under cyberattack. The ministry stated that its protection systems successfully mitigated the incident, preventing any disruption to its services.

malware

Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones

Recent reports indicate that a new malware strain, dubbed "Midnight Mimosa," has been discovered preinstalled on certain low-cost Android smartphones. This finding suggests that some devices may be compromised with malicious software embedded directly into their firmware before they even reach consumers, posing a significant supply chain security risk.