FBI Seizes Chinese Hacking Tools Used Against Critical Infrastructure
The FBI and U.S. Justice Department have seized two hacking tools operated by Integrity Technology Group, a China-based company linked by officials to the Flax Typhoon cyber group. The action disrupted infrastructure used to scan and attack critical networks in the United States and abroad.
The court-authorized seizure targeted Microscan and FishHub. Officials say the tools were used to identify vulnerable systems, conduct spear-phishing campaigns and deliver malware. The targets included power companies, airports, universities and energy infrastructure, according to the Justice Department.
What the tools did
According to the Justice Department, Integrity Technology Group developed Microscan to conduct reconnaissance against computer networks. The company used a botnet of internet-connected devices infected with a variant of Mirai malware to help scan for weaknesses.
Investigators identified Microscan scanning against a U.S. power company based in South Carolina, a multinational nongovernmental organization, Japanese and Polish airports, Taiwanese critical-infrastructure companies in the natural-gas and power sectors, and two Taiwanese universities.
FishHub served a different purpose. Officials allege that it helped attackers compromise networks through spear phishing and then download additional malware. That malware could provide unauthorized remote access or search for files and send them to servers controlled by Integrity Technology Group. The Justice Department said confirmed FishHub victims included approximately 20 Taiwanese universities.
The FBI and Justice Department said the seizures denied the actors access to the two tools. The FBI said it will continue monitoring for attempts to rebuild the infrastructure.
Why organizations should care
The operation shows how compromised internet-connected devices and centralized scanning platforms can help attackers search for exposed systems at scale. The Justice Department said Integrity Technology Group has contracts with the Chinese government and that the tools were used against U.S. and foreign critical infrastructure.
The action was the department’s second public technical disruption of Integrity Technology Group’s hacking infrastructure. In September 2024, authorities disrupted an associated Mirai malware botnet that consisted of more than 200,000 consumer devices in the United States and worldwide, including cameras, video recorders and home and office routers.
The FBI and partner agencies also published a cybersecurity advisory with indicators of compromise intended to help network defenders identify and respond to related activity.
Practical defensive steps
- Review exposed systems. Inventory internet-facing routers, firewalls, remote-access tools and other devices, then remove services that are not required.
- Apply security updates. Patch operating systems, networking equipment and internet-of-things devices, and replace hardware that no longer receives updates.
- Check logs for reconnaissance. Look for repeated connection attempts, unusual scans, suspicious phishing messages and outbound traffic to unfamiliar infrastructure.
- Use the official advisory. Compare network telemetry with the indicators published by the FBI and partner agencies.
References
- Riddle, S., & Tucker, E. (2026, October 8). The FBI has seized tools used by Chinese hackers for cyber operations, officials say. The Associated Press. https://apnews.com/article/fbi-justice-department-china-hacking-8948c5d83180675bcf21cd98426eabf7
- U.S. Department of Justice. (2026, October 8). Justice Department and FBI seize vulnerability scanning and spear phishing tools operated and used by China-state sponsored hackers. https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-vulnerability-scanning-and-spear-phishing-tools-operated
