The U.S. Department of Justice and the FBI announced on October 8, 2026 that they had seized seven domains used to operate MicroScan and FishHub, two intrusion tools that officials say are run by Beijing-based Integrity Technology Group, a company the private sector tracks as Flax Typhoon. The court-authorized seizures were announced by the Justice Department's Western District of Pennsylvania and represent the latest law enforcement action against a hacking campaign that officials link to the Chinese government.
The Associated Press reported on October 8, 2026 that the tools were used to scan, phish and hack targets including U.S. and foreign critical infrastructure. The operation is the second time in two years that U.S. authorities have moved against the same company. In September 2024, the FBI announced it had disrupted a Flax Typhoon botnet that infected more than 200,000 consumer devices, including cameras, video recorders and home and office routers.
Officials described the campaign as broad and indiscriminate. "We aim to remove the capability from the threat actors. We target their infrastructure, their money, and their tools," said Jason Bilnoski, Deputy Assistant Director of the FBI's Cyber Division, who called the operation "indiscriminate and reckless." The seized infrastructure included login pages, malware delivery domains and a VPN endpoint, court documents show.
On the same day, ten agencies in seven countries published a joint cybersecurity advisory, AA26-281A, that runs 58 pages and details how the actors steal email from Microsoft Exchange environments, move through victim networks and maintain persistence. The advisory was coauthored by the FBI, CISA, the NSA and partner agencies in the United Kingdom, Australia, Canada, Japan, New Zealand and Spain.
Key Facts
Help Net Security reported on October 9, 2026 that the seven seized domains are c0cc[.]cc, 98aiblog[.]com, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com and linkedinns[.]net. The first, c0cc[.]cc, was the access point for MicroScan and was still serving a login page as recently as about September 9, 2026. Five of the domains delivered FishHub malware, while 98aiblog[.]com was used to distribute SoftEther VPN software that helped the intruders hold onto compromised networks.
MicroScan is a reconnaissance tool that Integrity Technology Group developed and that contains more than 1,300 penetration-testing scripts. Prosecutors say it dates to at least 2017. Between April and December 2022, MicroScan was used to scan a power company in South Carolina, a multinational non-governmental organization, airports in Japan and Poland, and Taiwanese natural gas and power companies. Two universities in Taiwan were scanned in August 2022 and March 2023, and the attackers broke into both networks soon after, according to court papers.
FishHub is the second tool named in the seizure. It was used to break into networks through spear phishing and then to drop additional malware. The FBI said the attackers were still running FishHub as of March 2026. The Justice Department's press release says approximately 20 Taiwanese universities are confirmed victims, while the FBI affidavit states that the FishHub server held files from more than 20 entities and that commands showed six were Taiwan universities. That discrepancy is one of several details that separate the public announcement from the underlying court record.
The joint advisory lists eight known flaws that the actors successfully exploited: CVE-2014-6278 in GNU Bash, CVE-2015-3306 in ProFTPD, CVE-2015-5477 in ISC BIND, CVE-2016-3081 in Apache Struts, CVE-2019-11510 in Pulse Connect Secure, CVE-2021-22205 in GitLab, CVE-2021-3199 in ONLYOFFICE and CVE-2023-22894 in Strapi. Five of the eight were newly added to CISA's Known Exploited Vulnerabilities catalog. The advisory says the actors have been breaking into networks since at least mid-January 2021.
Among the tradecraft described: the intruders used the open-source Python tool EBurst to spray passwords against Microsoft 365 and Exchange accounts, installed SoftEther VPN for persistence, ran DC.exe for DCSync credential theft and used a PHP bot called Curlc4.txt to exfiltrate mail over Exchange Web Services to a domain named natcloudservice[.]com. The Hacker News reported on October 8, 2026 that the same hackers ran a web application that provides third-party access to stolen email content, restricted in some cases to IP addresses in Xiamen, China. The advisory has 39 pages of indicators of compromise, and its appendix lists about 218 domain names and 515 IP addresses, some dating to 2016.
Analysis
What this really means is that U.S. law enforcement is now pursuing the infrastructure and the business behind Chinese state-linked hacking, not just the individual intrusions. The Justice Department did not simply announce an indictment or a sanction; it seized domains, which removes working capability from the operators. Brett Leatherman, Assistant Director of the FBI's Cyber Division, framed the action in exactly those terms: "The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure."
The choice of targets shows how broad the campaign was. A South Carolina power company, a multinational NGO, airports in Japan and Poland, Taiwanese gas and power companies and two Taiwanese universities all appear in the same set of court papers. This is not espionage aimed at a single ministry. It is scanning at scale, followed by phishing and hands-on exploitation, which the advisory describes as a combination of automated scanning tools, large-scale botnets and manual intrusion techniques.
The money trail is also part of the story. Gblock reported on October 9, 2026 that payment records tie the domains together: the five FishHub domains were renewed about February 10, 2026 from a single IP address using AliPay funds, and c0cc[.]cc was bought and renewed through an Alipay account with a Beijing address. Payment attribution matters because it connects the operational infrastructure to a single commercial entity, which is precisely what prosecutors need to justify seizures of domains rather than merely naming malware families.
The advisory's finding that stolen mail could in some cases be opened only from IP addresses in Xiamen, China, suggests the operators tried to limit who could read the exfiltrated content. The FBI says it recovered an archived email database the actors used to target victim mailboxes. That recovery is significant because it may allow investigators to identify which mailboxes were actually compromised, a harder task than detecting the phishing that preceded it.
Why It Matters
The seizure matters first for the victims. Government offices, police agencies, health systems and religious institutions in Southeast Asia lost email to this crew, according to the joint advisory. The same actors also targeted U.S. government services, critical manufacturing, healthcare and IT organizations, plus U.S. law enforcement, education and religious groups, with additional victims in Africa and North America. Removing the delivery domains and the MicroScan login page raises the cost of continued operations.
It also matters because it is the second disruption of Integrity Tech's operations in as many years. U.S. Attorney Troy Rivetti called it "our second disruption of Integrity Tech's massive operations in as many years," referring to the September 2024 takedown of a Mirai-variant botnet. That earlier botnet had database records of more than 1.2 million infected devices, with more than 260,000 actively infected as of about June 5, 2024, and more than 200,000 devices disrupted in September 2024. A repeat performance suggests the company has been able to rebuild, and that the U.S. approach is now to keep taking away infrastructure as it appears.
Finally, the sanctions history matters. The U.S. Treasury sanctioned Integrity Technology Group in January 2025, and the United Kingdom sanctioned it in December 2025. Domain seizures add a technical layer on top of financial pressure. The Associated Press reported on October 8, 2026 that in Beijing, Chinese foreign ministry spokesperson Mao Ning said China has always cracked down on hacking and firmly opposes spreading disinformation for political purposes. That denial is a standard response, but it does not change the fact that the domains, the payment records and the victim scans are now part of a public court record.
Next Up
The FBI says it will keep watching for ways the company might rebuild its infrastructure. Brett Lally, a Supervisory Special Agent in the FBI's San Diego field office, said the department would continue to monitor how Integrity Technology Group might reconstitute its tools. Practically, that means tracking new domain registrations, new payment trails and new VPN endpoints that match the patterns laid out in advisory AA26-281A.
For defenders, the advisory is the immediate action item. The 39 pages of indicators of compromise, the eight exploited CVEs and the EBurst password-spraying technique give network teams a concrete list to hunt against. The five CVEs newly added to CISA's Known Exploited Vulnerabilities catalog set a deadline for federal agencies to patch. Organizations that run Microsoft Exchange, SoftEther VPN or any of the affected products should assume that scanning, password spraying and mailbox theft will continue even after seven domains go dark.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.