US Shuts Down Chinese Cyber Espionage Tools: State-Sponsored Hacking Cracked

www.news4hackers.com-us-shuts-down-chinese-cyber-espionage-tools-state-sponsored-hacking-cracked-us-shuts-down-chinese-cyber-espionage-tools-state-sponsored-hacking-cracked

US Disrupts Chinese State-Sponsored Cyber Tools The U.S. government disclosed the takedown of two cyber tools linked to Chinese state-sponsored actors on Thursday.

Overview of the Takedown

The tools, MicroScan and FishHub, were developed by Integrity Technology Group (Integrity Tech) and utilized for network reconnaissance and unauthorized access. MicroScan, a vulnerability scanning tool, was deployed to identify weaknesses in target systems, while FishHub facilitated remote intrusions through spear-phishing campaigns.

Details of MicroScan and FishHub

According to U.S. authorities, Integrity Tech leveraged a Mirai malware variant to construct an IoT botnet, which supported MicroScan’s operations. This botnet targeted critical infrastructure, including a U.S. power company, non-governmental organizations, Japanese and Polish airports, and Taiwanese universities and government entities.

According to U.S. authorities, Integrity Tech leveraged a Mirai malware variant to construct an IoT botnet, which supported MicroScan’s operations.

FishHub enabled clients of Integrity Tech to remotely access compromised networks, search for sensitive files, and exfiltrate data. The tool was implicated in attacks against at least 20 Taiwanese universities.

Botnet Operations and Targets

The U.S. seized domains used by the threat actors to manage MicroScan and FishHub, including c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net. In 2024, U.S. officials disrupted Integrity Tech’s Raptor Train botnet, and the company was sanctioned in 2025 for supplying cybersecurity products to Chinese state-affiliated entities.

Joint Advisory and Vulnerability Targets

A joint advisory from U.S., UK, Australian, Canadian, Japanese, New Zealand, and Spanish agencies revealed that MicroScan has been operational since at least 2017. The tool targets vulnerabilities in software such as Apache Struts, Juniper ScreenOS, Jenkins, OpenSSL, Oracle, Rejetto HFS, WebLogic Server, and WordPress.

Flax Typhoon and Associated Threats

The advisory noted that MicroScan is a Python-based application containing over 1,300 penetration-testing scripts designed to identify specific weaknesses in web environments. The tool has been associated with Flax Typhoon (also known as Ethereal Panda, Red Juliett, Storm-0919, and UNC5007), though Integrity Tech is suspected of collaborating with other Chinese advanced persistent threat (APT) groups.

Flax Typhoon’s operations involved reconnaissance tools like BBScan, dirsearch, Fscan, ksubdomain, masscan, Nmap, OneForAll, ShuiZe, and WPScan, as well as command-line exploit utilities and the EBurst Microsoft Exchange password spraying tool.

Impact and Defensive Measures

The threat actors deployed SoftEther VPN software for persistent access and collected credentials to exfiltrate data from on-premises systems and cloud services. Victims of data theft included government agencies, law enforcement bodies, healthcare providers, and religious institutions in Southeast Asia.

In some cases, access to stolen data was restricted to IP addresses originating from Xiamen, China. The advisory highlighted that Integrity Tech’s activities align with broader Chinese state-sponsored cyber operations, emphasizing the need for enhanced defensive measures against such threats.

Conclusion

The disruption of MicroScan and FishHub marks a significant step in countering the exploitation of compromised infrastructure and malicious software by state-backed actors.



About Author

en_USEnglish