U.S. Department of Justice

10/08/2026 | Press release | Distributed by Public on 10/08/2026 11:17

Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers

Today the Justice Department and FBI announced court-authorized seizures to deny malicious cyber actors access to two hacking tools, "Microscan" and "FishHub," used to scan and, in some cases, hack, U.S. and foreign critical infrastructure systems and other networks. As alleged in court documents unsealed in the Western District of Pennsylvania, malicious cyber actors working for Integrity Technology Group (Integrity Tech), a company based in the People's Republic of China (PRC), operated and used the tools. Integrity Tech has contracts with the PRC government.

"The United States will not allow China or its proxies to operate against United States interests with impunity in cyberspace," said Assistant Attorney General for National Security John A. Eisenberg. "The National Security Division will continue to respond decisively and use every tool at our disposal to disrupt the Flax Typhoon threats, dismantle the infrastructure sustaining them, and protect the critical networks that power our daily lives and on which our Nation's security depends."

"These state-sponsored hackers continue to aggressively target and access networks and systems throughout the world in an effort to identify and steal files and otherwise exploit victims' vulnerabilities," said U.S. Attorney Troy Rivetti for the Western District of Pennsylvania. "These seizures, our second disruption of Integrity Tech's massive operations in as many years, send another clear message to cybercriminals from the PRC and elsewhere of the Department's dedication to defending and maintaining cybersecurity in the United States and abroad."

"Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure," said Assistant Director Brett Leatherman of the FBI's Cyber Division. "The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure."

"Today's seizures underscore the FBI's unwavering commitment in disrupting PRC state-sponsored cyber criminals who threaten our critical infrastructure and national security," said Special Agent in Charge Mark Remily of the FBI San Diego Field Office. "FBI San Diego and our law enforcement partners around the world will continue to employ the full force of our investigative authority to protect the American people and safeguard our networks from malicious foreign cyber actors."

According to court documents, Integrity Tech created and used a botnet of internet-of-things devices infected with a variant of Mirai malware. Among other things, this botnet facilitated Integrity Tech's computer vulnerability scanning using Microscan. Integrity Tech developed Microscan to conduct reconnaissance, via the botnet and otherwise, of victim computer networks for vulnerabilities that its clients would later exploit. Targets of Microscan vulnerability scanning include a U.S. power company based in South Carolina, a multi-national Non-Governmental Organization, Japanese and Polish airports, Taiwanese critical infrastructure companies in the natural gas and power sectors, and two Taiwanese universities. Integrity Tech accessed Microscan through one of the seized domains, c0cc[.]cc.

A second Integrity Tech tool, FishHub, is alleged to have facilitated the exploitation of computer networks through spear phishing. After an initial network compromise, FishHub downloaded additional malware to the victim network. This malware provided Integrity Tech's clients with unauthorized remote access to the victim network or searched for specific files and sent them to servers controlled by Integrity Tech. Confirmed victims of FishHub activity included approximately 20 Taiwanese universities. Five of the seized domains helped deliver this malware: 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net.

Today's action marks the Department's second public technical disruption of Integrity Tech's hacking infrastructure. In September 2024, the Justice Department announced the court-authorized disruption of Integrity Tech's Mirai malware botnet which consisted of more than 200,000 consumer devices in the United States and worldwide. In conjunction with the seizures announced today, the FBI, along with other U.S. and foreign-partner agencies, published a cyber security advisory. This advisory provides indicators-of-compromise associated with Integrity Tech intrusion activity and is designed to help network defenders identify and respond to Integrity Tech's malicious activity.

The FBI San Diego and Baltimore Field Offices are investigating the case, in coordination with the FBI's Cyber Division.

Assistant U.S. Attorney Brendan McKenna for the Western District of Pennsylvania and Trial Attorney Jacques Singer-Emery of the National Security Division's National Security Cyber Section are prosecuting the case. Substantial assistance was provided by Assistant U.S. Attorney Thomas Sullivan for the District of Maryland and the National Police Agency of Japan.

Note: View the affidavit here.

View the seizure warrant here.

U.S. Department of Justice published this content on October 08, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on October 08, 2026 at 17:18 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]