U.S. Disrupts China-Linked Hacking Tools Used Against Critical Infrastructure

by Ben Voss
U.S. Disrupts China-Linked Hacking Tools Used Against Critical Infrastructure

The Justice Department and FBI announced Thursday that they had seized seven internet domains and disrupted two tools used by China-linked cyber actors to scan and attack critical infrastructure. The operation targeted infrastructure associated with Integrity Technology Group, a China-based company that U.S. officials say has links to the Chinese government.

What the operation disrupted

The tools were called Microscan and FishHub. According to the Justice Department, Microscan was used for network reconnaissance, including vulnerability scanning through an internet-of-things botnet infected with a variant of Mirai malware. FishHub allegedly supported spear-phishing operations and delivered additional malware after an initial compromise.

The Justice Department said the activity was associated with actors using tactics and techniques linked in the security industry to Flax Typhoon. The NSA separately said related activity used techniques consistent with Flax Typhoon, Storm 919, Ethereal Panda and Red Juliett.

Court documents identified Microscan scanning targets that included a South Carolina power company, Japanese and Polish airports, Taiwanese natural-gas and power organizations, two Taiwanese universities and a multinational nongovernmental organization. The Justice Department said confirmed FishHub victims included approximately 20 Taiwanese universities.

Why defenders should pay attention

The campaign reached multiple sectors and regions. The NSA said related actors enabled by Integrity Technology Group targeted government services, critical manufacturing, healthcare, public health, information technology, law enforcement, education and religious organizations in North America, Southeast Asia and Africa.

The operation was the Justice Department’s second publicly announced disruption of Integrity Technology Group’s infrastructure. In September 2024, the department said it disrupted a related Mirai botnet consisting of more than 200,000 compromised consumer devices in the United States and worldwide.

The FBI and partner agencies also released a cybersecurity advisory with indicators of compromise, observed tactics and mitigation guidance for network defenders.

What organizations should do now

  1. Review the advisory. Compare its listed domains, indicators and techniques with firewall, DNS, endpoint and identity logs.
  2. Hunt for reconnaissance. Look for unusual vulnerability scanning, repeated probes and unexpected access to externally exposed services.
  3. Investigate spear-phishing. Search mail, proxy and endpoint records for suspicious links, downloaded executables and unauthorized remote-access tools.
  4. Protect accounts. Reset credentials and tokens associated with suspicious activity, and verify multifactor authentication for privileged users.
  5. Limit lateral movement. Separate internet-facing services and user networks from operational technology, administrative systems and sensitive data stores.

References

Associated Press. (2026, October 8). The FBI has seized tools used by Chinese hackers for cyber operations, officials say. https://apnews.com/article/8948c5d83180675bcf21cd98426eabf7

U.S. Department of Justice. (2026, October 8). Justice Department and FBI seize vulnerability scanning and spear phishing tools operated and used by China-state sponsored hackers. https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-vulnerability-scanning-and-spear-phishing-tools-operated

Federal Bureau of Investigation. (2026, October 8). Chinese government-linked cyber threat actors combine automated and hands-on hacking tools to steal sensitive data. https://www.fbi.gov/investigate/cyber/alerts/2026

National Security Agency. (2026, October 8). NSA joins FBI and others to provide guidance to mitigate Chinese government-linked actors targeting sensitive data. https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4622576/nsa-joins-fbi-and-others-to-provide-guidance-to-mitigate-chinese-government-lin/