US authorities have seized seven domains tied to Microscan and FishHub, two intrusion tools that a Chinese contractor built for state-sponsored hacking crews. The US Department of Justice said the takedown targets Integrity Technology Group (Integrity Tech), a Beijing firm holding government contracts.
The bureau described the company as an enabler of Flax Typhoon, the espionage cluster that has stalked critical networks for years. Agents acted on a court-ordered warrant, pulling down delivery domains that included 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com and linkedinns[.]net.
What the tools did
Prosecutors say Integrity Tech ran a botnet of Mirai-infected Internet of Things gear. Operators used Microscan, a Python web app carrying more than 1,300 penetration-testing scripts, to fingerprint weaknesses before clients moved in.
Court filings name a South Carolina power company, a multinational non-governmental organization, and airports in Japan and Poland among the scanned targets. Natural gas and power firms in Taiwan also appeared. FishHub handled the phishing side, breaching networks so operators could drop remote-access malware or pull requested files.
Who is exposed
Roughly 20 Taiwanese universities are confirmed victims. Two had been scanned first and then breached, with attackers planting SoftEther VPN to keep a foothold.
It is the second disruption of the contractor in as many years. In September 2024 the Justice Department dismantled a Mirai botnet that had ensnared more than 200,000 consumer devices.
What defenders should do
A joint FBI and CISA advisory urges organizations to close unused services and ports, replace default passwords, enforce MFA everywhere and patch promptly. Security teams should watch for living-off-the-land tooling and hunt logs for unusual addresses and ports. Indicators of compromise tied to the intrusions accompany the advisory.
