FBI Takes Down Flax Typhoon Hacking Tools Behind Global Cyberattacks
FBI seizes domains linked to Chinese state-sponsored cyber operations targeting global infrastructure
Details of the Cyber Operations
The Federal Bureau of Investigation has dismantled seven domains associated with two malicious tools, Microscan and FishHub, which were employed in a series of cyberattacks attributed to a China-based entity. According to the U.S. Department of Justice, the compromised infrastructure was operated by Integrity Technology Group (Integrity Tech), a firm with government contracts in China.
Tools and Tactics
The agency stated that the group developed a botnet using a variant of the Mirai malware, which facilitated network reconnaissance and vulnerability scanning for clients. Between April and December 2022, the Microscan tool was used to probe a South Carolina power company, a multinational non-governmental organization, airports in Japan and Poland, and Taiwanese energy providers.
Targets and Impact
Taiwanese universities were also targeted in August 2022 and March 2023, with subsequent network intrusions reported. The threat actors accessed Microscan through the domain c0cc[.]cc, while FishHub, another tool deployed as of March 2026, enabled spear-phishing attacks to gain initial access.
Malware Distribution and Findings
Once inside networks, FishHub provided remote access to clients or extracted specific files for transmission to servers controlled by Integrity Tech. The Department of Justice confirmed approximately 20 Taiwanese universities as victims, with five seized domains—98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net—used for malware distribution.
An FBI special agent noted in a seizure warrant that the tool’s name likely reflected its role in phishing activities.
Cybersecurity Advisory and Recommendations
Cybersecurity agencies issued a joint advisory highlighting the tactics of Chinese government-linked threat actors, emphasizing the use of automated scanning, botnets, and manual exploitation to steal sensitive data. The advisory detailed vulnerabilities exploited through scanning tools, cross-site scripting, and password spraying on Microsoft Exchange servers, alongside persistence mechanisms via VPN software and data exfiltration via custom scripts.
Recommendations included disabling unused services, securing web application inputs, and implementing multi-factor authentication.
Previous Actions and Ongoing Efforts
This marks the second public disruption of Integrity Tech’s operations by U.S. authorities. In September 2024, the Justice Department dismantled the company’s Mirai botnet, which had compromised over 200,000 consumer devices globally. Officials reiterated commitments to counter threats from China and its proxies, stating that the U.S. would not tolerate cyber operations undermining national interests.
The National Security Division emphasized ongoing efforts to dismantle infrastructure supporting Flax Typhoon campaigns and safeguard critical networks.
