The U.S. Justice Department and FBI have announced the seizure of two hacking tools, Microscan and FishHub, which are linked to the Chinese government-affiliated group Flax Typhoon and the China-based firm Integrity Technology Group. The seizures, authorized by a court in the Western District of Pennsylvania, aim to disrupt access to these tools by denying hackers their domain names.
Microscan is described as a vulnerability scanning tool, while FishHub is a spearphishing tool designed to download malware onto compromised networks. Integrity Technology Group, which allegedly developed and operated these tools, was previously sanctioned by the U.S. government last year and was the focus of a 2024 takedown operation for its alleged involvement in a large botnet.
The announcement was accompanied by a joint advisory from the FBI, Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA). This advisory warns that Chinese government-linked cyber threat actors, facilitated by Integrity Technology Group, are employing automated scanning, large-scale botnets, and hands-on exploitation to steal sensitive data from organizations globally, including U.S. critical infrastructure.
These actors are reported to exploit vulnerabilities using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers. They establish persistence through VPN software and exfiltrate emails and credentials using custom scripts. Integrity Technology Group is also alleged to have leveraged a Mirai-variant botnet of internet-of-things devices to support Microscan's operations.
Targets of Microscan have reportedly included a power company in South Carolina, airports in Japan and Poland, and critical infrastructure companies and universities in Taiwan. Taiwanese universities have also been identified as victims of FishHub.
Chris Butera, acting executive assistant director for cybersecurity at CISA, stated that Chinese government-affiliated actors are strategically positioning themselves within critical infrastructure networks, including operational technology (OT) systems, with the intent to disrupt critical functions at a future time of their choosing.
Brett Leatherman, head of the FBI’s Cyber Division, emphasized the FBI's strategy to pursue both the threat actors and the enterprises that support them. He identified Integrity Technology Group as one such enterprise, noting its role in acquiring or developing cyber tools and hosting infrastructure for actors targeting networks worldwide.






