FBI disrupts Flax Typhoon hacking tools used in global cyberattacks
The FBI seized seven domains used to operate Microscan and FishHub, two hacking tools linked to Chinese state-sponsored hackers known as Flax Typhoon that were used to target critical infrastructure and other organizations in the US and abroad.

Seizure notice (Source: US Department of Justice)
According to the US Department of Justice, the hackers worked for Integrity Technology Group (Integrity Tech), a China-based company that holds contracts with the Chinese government.
“The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity,” said Brett Leatherman, Assistant Director of the FBI’s Cyber Division. “By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure.”
Prosecutors say Integrity Tech built a botnet of internet-of-things devices infected with a variant of the Mirai malware. The botnet helped the company scan for vulnerabilities with Microscan, a tool it developed to run reconnaissance on victim networks and find weaknesses its clients would later exploit.
Between April and December 2022, Microscan was used to scan a power company in South Carolina, a multinational non-governmental organization, airports in Japan and Poland, and Taiwanese natural gas and power companies.
Two universities in Taiwan were scanned in August 2022 and March 2023, and the attackers broke into both networks soon after. Integrity Tech accessed the tool through c0cc[.]cc, one of the seized domains.
The second tool, FishHub, which the attackers were running as of March 2026, was used to break into networks through spear phishing. Once inside, it downloaded more malware to the victim’s network.
That malware either gave the company’s clients unauthorized remote access, or searched for specific files and sent them to servers controlled by Integrity Tech. DOJ says about 20 Taiwanese universities are confirmed victims.
Five of the seized domains were used to deliver the malware: 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com and linkedinns[.]net.
“Based on my training and experience I believe the tool was named FishHub because it facilitated phishing activity,” FBI special agent Adam James said in a seizure warrant affidavit.
A seventh domain, 98aiblog[.]com, was used by SoftEther VPN software the attackers installed at the two universities scanned with Microscan, to keep remote access to their networks.
Agencies urge organizations to patch and turn on MFA
The FBI and US and foreign partner agencies also released a joint cybersecurity advisory on the group’s activity.
“Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide, including US critical infrastructure sectors,” the advisory reads.
“These actors exploit vulnerabilities by using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while establishing persistence through VPN software and exfiltrating emails and credentials using scripts,” they added.
The agencies advise organizations to disable unused services and ports, sanitize web application inputs to prevent injection attacks, turn on MFA for all services and apply patches on time. The advisory also includes indicators of compromise linked to Integrity Tech intrusions.
Second takedown after the 2024 botnet disruption
This is the second time the Justice Department has publicly disrupted Integrity Tech’s hacking infrastructure. In September 2024, it took down the company’s Mirai botnet, which at the time controlled more than 200,000 consumer devices in the US and abroad.
“These seizures, our second disruption of Integrity Tech’s massive operations in as many years, send another clear message to cybercriminals from the PRC and elsewhere of the Department’s dedication to defending and maintaining cybersecurity in the United States and abroad,” said U.S. Attorney Troy Rivetti for the Western District of Pennsylvania.
“The United States will not allow China or its proxies to operate against United States interests with impunity in cyberspace,” said Assistant Attorney General for National Security John A. Eisenberg. “The National Security Division will continue to respond decisively and use every tool at our disposal to disrupt the Flax Typhoon threats, dismantle the infrastructure sustaining them, and protect the critical networks that power our daily lives and on which our Nation’s security depends.”