DOJ, FBI Seize Chinese State-Linked Hacking Tools Targeting Critical Infrastructure

flax-typhoon-china-hacking-tools.jpg

The Justice Department and FBI have ripped seven internet domains away from a Chinese state-linked hacking operation accused of targeting critical infrastructure in the United States and abroad.

The court-authorized seizures disabled infrastructure supporting two tools known as “Microscan” and “FishHub.”

Federal investigators say the tools were operated by Integrity Technology Group, a Beijing-based company with contracts tied to the Chinese government and links to the hacking group tracked as Flax Typhoon.

The immediate scope of the takedown is captured in a current breakdown of the federal action:

The U.S. just seized domains used by a Chinese government contractor to scan and break into critical networks.

On October 8, 2026, the DOJ and FBI announced court-authorized seizures in the Western District of Pennsylvania. The domains supported two tools run by Beijing-based… https://t.co/X2xZrrviIj pic.twitter.com/hJqXZn9jn0

— UnveiledChina (@Unveiled_ChinaX) October 9, 2026

This was not a case of hackers merely probing random websites.

The Justice Department says the court-authorized operation seized seven domains supporting two different pieces of attack infrastructure. Microscan was built to identify vulnerabilities across victim networks so they could later be exploited.

Its targets included a South Carolina power company, airports in Japan and Poland, Taiwanese natural-gas and electric infrastructure, two Taiwanese universities and a multinational nongovernmental organization. Investigators say Integrity Tech used internet-connected devices infected with a version of Mirai malware to power the scanning.

FishHub played a separate role in spear-phishing operations: after an intrusion, it could download malware that gave remote access, search for selected files and send stolen material to company-controlled servers. Approximately 20 Taiwanese universities were confirmed FishHub victims.

DOJ called this the second public disruption of Integrity Tech infrastructure and paired the seizures with a joint cybersecurity advisory so defenders can hunt for the group’s activity.

The technical picture includes reconnaissance, malicious email delivery, persistence and data theft rather than one isolated exploit:

FBI/DOJ seized 7 domains for Flax Typhoon–linked MicroScan + FishHub (Integrity Tech). Joint advisory: scanning, spear-phish, SoftEther persistence, email theft vs CI and others. CISA KEV adds 5 CVEs (due Oct 11). https://t.co/eMFD3SJSsY

— RichTechGuy (@richtechguy) October 9, 2026

The government seized one domain used to access Microscan and five domains that helped deliver FishHub malware. A seventh domain was also included in the operation, bringing the total to seven.

The names themselves reveal part of the trap.

Several FishHub domains were designed to resemble trusted services, including names that imitated Outlook, YouTube and LinkedIn. That is classic spear-phishing territory: make the malicious route look familiar enough that a target clicks before noticing the deception.

Assistant Attorney General for National Security John Eisenberg said the United States would not allow China or its proxies to operate against American interests with impunity in cyberspace.

FBI Cyber Division Assistant Director Brett Leatherman said companies like Integrity Tech expand the reach and scale of Beijing’s cyber operations by giving China-linked actors the tools to scan and penetrate American networks.

That contractor structure gives the Chinese Communist Party distance and deniability while still placing powerful capabilities in the hands of operators serving Beijing’s interests.

The latest seizure also exposes a deeper pattern.

This is the second public U.S. disruption of Integrity Tech’s infrastructure in roughly two years.

In September 2024, the Justice Department and FBI dismantled a Flax Typhoon botnet built from more than 200,000 compromised consumer devices around the world. Routers, cameras, video recorders and network-storage devices were quietly turned into tools for further intrusion.

The current case also carries an important legal limit: the seizure documents describe federal allegations, not a final judgment of liability.

DOJ's Oct. 8 announcement describes court-authorized seizures and alleged use of MicroScan and FishHub; it is not a final liability finding. Our Oct. 9 edition lays out the record and its limits: https://t.co/f7p3mZkAAi pic.twitter.com/6Rala9sHRW

— FPC&Sports (@THECrazyKowboy) October 9, 2026

The FBI reported that roughly half of the more than 200,000 devices controlled by the earlier Flax Typhoon botnet were located in the United States. The compromised equipment included routers, internet cameras, video recorders and network-storage devices whose owners often had no idea their hardware was being used.

Targets included government agencies, universities, corporations, telecommunications providers and media organizations in the United States and overseas. The Bureau publicly identified Integrity Tech as the company behind that operation and described it as a Chinese government contractor working at Beijing’s direction.

FBI leaders also warned that Chinese state-sponsored actors would keep rebuilding access through proxies and disposable infrastructure after a takedown. The warning matters now because the latest domains are tied to the same company, showing how a contractor can lose one large botnet and still return with specialized scanning and phishing systems.

That warning proved well founded.

Two years after the botnet takedown, federal agents were back in court seizing another set of domains tied to the same company.

The current action exposes the infected-device network as well as specialized tools used for scanning and spear phishing.

The current action does not mean the threat is gone. China-linked operators can move to new infrastructure, change domains and adapt their malware.

But every seizure burns access, exposes methods and forces the attackers to rebuild under greater scrutiny.

It also gives American network defenders concrete indicators they can use to hunt for compromise.

The FBI and partner agencies released a joint cybersecurity advisory alongside the operation so companies and public institutions can identify signs associated with Integrity Tech activity.

That is the right combination: disrupt the infrastructure, publish the technical evidence and warn potential targets before the next intrusion succeeds.

Beijing has spent years treating American networks as open terrain for espionage and preparation.

The latest seizures send a different message. Chinese government contractors may hide behind commercial names and disposable domains, but the United States can still find their tools, expose their customers and take their infrastructure offline.


What are your thoughts?

NATIONAL POLL: Do You Still Have Trump's Back 100%? vote now

TAP HERE TO ADD YOUR VOTE

This is a Guest Post from our friends over at 100 Percent Fed Up. View the original article here.

Continue reading...

[ H/T WLT Report ]

Comments

There are no comments to display
Back
Top