Technology news
The FBI has actually taken 7 domains utilized by Chinese state-sponsored hackers referred to as Flax Typhoon to run 2 hacking tools, MicroScan and FishHub, utilized in attacks that breached important facilities and other companies worldwide.
The seizures targeted facilities supporting the 2 hacking platforms supposedly run by China-based Integrity Technology Group(Integrity Tech ), which U.S. authorities state has agreements with the Chinese federal government.
According to the U.S. Department of Justicethe tools were utilized to scan for vulnerabilities and breach important facilities networks in the United States and other nations.
“Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure,” stated Brett Leatherman, assistant director of the FBI’s Cyber Division.
Leatherman stated the Chinese federal government depends on specialists and other business to broaden the reach of their cyber operations, which interfering with these companies makes it harder for China-linked hackers to target American networks.
MicroScan is a vulnerability-scanning platform established by Integrity Tech to determine security weak points in targeted networks.
According to an FBI seizure affidavitthe platform was utilized in addition to a botnet of internet-connected gadgets contaminated with Mirai malware to scan possible targets.
These targets consist of a South Carolina power business, airports in Japan and Poland, Taiwanese gas and electrical energy business, and universities.
The affidavit likewise verifies that the scanning activity caused effective breaches, consisting of at 2 Taiwanese universities whose networks were scanned utilizing MicroScan in August 2022 and March 2023 and consequently breached.
While the FBI verified that the hacking tools were utilized in invasions including important facilities, it did not divulge whether the particularly called power business, airports, and energy suppliers were effectively breached.
The FBI took the c0cc.cc domain utilized by Integrity Tech to access the MicroScan platform, which police validated was online in September 2026.
The 2nd platform, FishHub, was utilized to perform spear-phishing attacks and provide extra malware to networks currently jeopardized.
The malware offered assailants unapproved remote access to victims’ networks and permitted them to look for particular files and exfiltrate information to servers managed by Integrity Tech.
According to the FBI seizure affidavit, detectives discovered information and files coming from more than 20 companies on a server connected to the FishHub data-theft tool, consisting of 6 universities in Taiwan.
Police took 5 domains utilized to provide the malware: 98aicai.com 98aicode.com outlook3650.com youtubecard.comand linkedinns.net
A seventh took domain, 98aiblog.comwas connected to the SoftEther VPN software application set up on jeopardized systems to keep remote access to victim networks.
The taken domains now show FBI seizure notifications recognizing the Flax Typhoon hacking group and Integrity Technology Group.
Source: BleepingComputer
In coordination with the domain seizures, the FBI, CISA, NSA, and global partners released a joint cybersecurity advisory discussing how Chinese government-linked hackers utilized Integrity Tech’s tools and facilities to jeopardize companies and take delicate info.
The advisory states the assaulters targeted U.S. federal government firms, important production, health care, infotech, police, universities, and spiritual companies, along with companies in Southeast Asia, Africa, and North America.
The activity overlaps with operations tracked as Flax Typhoon, Ethereal Panda, and Red Juliett, although the companies state that not all activity might always be connected to Integrity Tech.
According to the advisory, MicroScan is a Python-based vulnerability scanner consisting of more than 1,300 penetration-testing scripts utilized to determine security defects in sites and services.
These scripts targeted extensively utilized software application, consisting of Oracle WebLogic, Apache Struts, WordPress, Jenkins, and other applications.
Detectives likewise recognized 8 vulnerabilities that were typically targeted by the hackers:
- CVE-2015-3306: ProFTPD unapproved file checked out vulnerability.
- CVE-2015-5477: ISC BIND denial-of-service vulnerability.
- CVE-2016-3081: Apache Struts remote code execution vulnerability.
- CVE-2021-3199: ONLYOFFICE DocumentServer unapproved file compose vulnerability.
- CVE-2023-22894: Strapi details disclosure vulnerability.
- CVE-2014-6278: GNU Bash (Shellshock) remote code execution vulnerability.
- CVE-2019-11510: Pulse Secure VPN approximate file checked out vulnerability.
- CVE-2021-22205: GitLab remote code execution vulnerability.
The enemies likewise utilized the open-source EBurst tool to perform password-spraying attacks versus Microsoft Exchange servers, together with other tools to take e-mails, gather Active Directory qualifications, and exfiltrate information.
The FBI likewise found a customized web application that let 3rd parties search taken e-mails without requiring direct access to the jeopardized accounts.
The joint advisory consists of signs of compromise, consisting of IP addresses, domains, malware hashes, and information of the aggressors’ tools, to assist companies determine prospective invasions.
Authorities are prompting companies to examine the indications, spot susceptible systems, disable unneeded exposed services, and impose multifactor authentication to secure versus attacks.
This is not the very first time United States police interrupted Integrity Tech’s hacking facilities.
In September 2024, the Justice Department interfered with an Integrity Tech-operated Mirai botnet including more than 200,000 jeopardized customer gadgets worldwide.
The UK federal government likewise approved Integrity Tech in 2025and the European Union approved the business in 2026 for participation in cyberattacks targeting Europe and its allies.

Technology news
Develop your security plan for AI-powered attacks
Sign Up With Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital top on what AI-speed attacks alter, what protectors must stop doing, and how to confirm, choose, repair, and re-validate at device speed.
Conserve your seat
Discover more from PMN S.P.O.R.T.S - A PRIME MEDIA NETWORK BRAND
Subscribe to get the latest posts sent to your email.

