The FBI and U.S. Justice Department have seized seven internet domains tied to two hacking tools used in a China-linked campaign against critical infrastructure, cutting off key infrastructure behind a threat operation the private sector tracks as Flax Typhoon.
According to the Justice Department, the tools — Microscan and FishHub — were operated by people working for Beijing-based Integrity Technology Group, a cybersecurity company the U.S. says has contracts with the Chinese government. The seizure matters because the tools were not aimed at one narrow target. Authorities say they were used to scan, phish, and in some cases compromise power, aviation, education, and other networks in multiple countries.
What the FBI took offline
Microscan was used for reconnaissance. Investigators say Integrity Tech combined the scanner with a botnet made from internet-connected devices infected with a Mirai variant, letting operators probe networks from infrastructure that could look unrelated to the real attacker.
Targets identified in court filings included a South Carolina power company, Japanese and Polish airports, Taiwanese natural-gas and electric-power companies, a multinational nonprofit organization, and two Taiwanese universities. The allegation is not that every scanned target was successfully breached; scanning and confirmed intrusion are separate facts. In an October 8 post, FBI Cyber Division said the seized infrastructure had been used to scan and, in some cases, infiltrate U.S. critical infrastructure.
FishHub played a different role. Authorities say it supported spear-phishing activity and could deliver follow-on malware after an initial compromise. That malware could provide remote access, search victim systems for selected files, and send those files to attacker-controlled servers. The Justice Department says roughly 20 Taiwanese universities were confirmed FishHub victims.
Why this is bigger than seven domains
The important technical idea is dependency. A hacking platform can be sophisticated, but it still needs infrastructure for authentication, command-and-control, malware delivery, routing, or persistence. If law enforcement can identify those dependencies and obtain court authority to seize them, it can break a platform without first arresting every operator behind it.
This is the second public U.S. disruption of Integrity Tech infrastructure in two years. In 2024, federal authorities dismantled a botnet linked to the same company that included more than 200,000 consumer devices. The latest operation goes after the scanning and phishing systems that can turn reconnaissance into access.
The broader pattern is increasingly familiar: compromise routers, cameras, servers, or other internet-facing equipment; use those systems as a proxy layer; scan for more weaknesses; then move into higher-value targets. That is why basic network hygiene still matters. BitcoinVersus has previously covered how a missed security patch can become an entry point, how packet capture helps engineers inspect suspicious traffic, and how VLAN segmentation can limit lateral movement.
What defenders should take from it
- Patch internet-facing systems quickly, especially known exploited vulnerabilities.
- Reduce unnecessary exposed services, management interfaces, and remote-access paths.
- Use multifactor authentication wherever possible, especially on administrative accounts.
- Watch for unusual VPN software, remote-access tools, credential spraying, and outbound connections that do not match normal business traffic.
- Assume a compromised edge device can become infrastructure for attacks against someone else, not just a problem confined to the device owner.
The Associated Press reported that officials described the latest action as rendering the two tools inoperable while warning that authorities will keep watching for attempts to rebuild the infrastructure. That caveat matters. Domain seizures can remove capabilities quickly, but they do not erase the operators, the underlying tradecraft, or the demand for those services.
What comes next
The immediate win is disruption: fewer working domains, fewer functioning tools, and more indicators for defenders to hunt. The longer-term question is whether Integrity Tech or related operators can replace the seized infrastructure fast enough to restore the same capability — or whether repeated takedowns make that business model slower, more expensive, and easier to detect.
Editor’s Note: This article distinguishes allegations in court filings from confirmed victim activity and will be updated if authorities publish additional technical findings.
Support independent technology reporting: Bitcoin donations help fund BitcoinVersus.Tech research and publishing.
Disclaimer: BitcoinVersus.Tech provides technology news and analysis for informational purposes only.

Leave a Reply