FBI seizes domains used by Chinese state hackers to scan critical infrastructure

The FBI seized seven domains used by the Chinese state-sponsored hacking group Flax Typhoon — also tracked as Ethereal Panda and Red Juliett — to operate two hacking tools that scanned and breached critical infrastructure across the United States and allied nations, according to a joint advisory published this week by the FBI, CISA, NSA, and international partners.
U.S. authorities say the tools, named MicroScan and FishHub, were built and operated by China-based Integrity Technology Group, a company they say holds contracts with the Chinese government. FBI Cyber Division Assistant Director Brett Leatherman said Integrity Technology Group «provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure.»
Why This Disruption Matters
Nation-state hacking groups targeting critical infrastructure represent one of the most consequential categories of cyber threat, because the targets — power grids, airports, water systems, telecommunications — have real-world safety consequences beyond data theft. This action is notable because it names a specific company (Integrity Tech) as the operator behind the tooling, rather than attributing the activity to an anonymous state actor, and because it follows a documented pattern: the Justice Department disrupted an Integrity Tech-run Mirai botnet of over 200,000 devices in September 2024, the UK sanctioned the company in 2025, and the EU sanctioned it in 2026 for cyberattacks against Europe and its allies. This is the same actor being disrupted for the third time by three different jurisdictions.
The Tools and Their Targets
MicroScan is a Python-based vulnerability scanner with more than 1,300 penetration-testing scripts, built to probe widely used enterprise software including Oracle WebLogic, Apache Struts, WordPress, and Jenkins. It was deployed alongside a botnet of Mirai-infected consumer devices to scan targets that included a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and electricity companies, and multiple universities. The FBI confirmed that two Taiwanese universities scanned in August 2022 and March 2023 were later breached, though it did not disclose whether the named power companies, airports, or energy providers themselves suffered intrusions beyond the scanning stage.
FishHub, the second tool, handled the espionage and data-theft phase: spear-phishing and malware delivery to networks already compromised, giving operators remote access, file search, and data exfiltration capability. A server linked to FishHub held stolen data from more than 20 organizations, including six Taiwanese universities. Investigators also found a custom web application that let third parties browse the stolen emails without directly accessing the compromised accounts — effectively a storefront for exfiltrated data.
Scope of the Advisory
The joint advisory names U.S. government agencies, critical manufacturing, healthcare, IT, law enforcement, education, and religious organizations as targeted sectors, with victims identified across Southeast Asia, Africa, and North America. The agencies cautioned that not all of the broader malicious activity they observed can be definitively linked to Integrity Tech, suggesting the scanning infrastructure may have been shared or resold to other operators. The tools frequently exploited older, well-documented vulnerabilities — including the 2014 Shellshock bash bug, a 2016 Apache Struts remote code execution flaw, and a 2021 GitLab RCE — a reminder that unpatched legacy vulnerabilities remain a primary entry point for state-sponsored actors years after public disclosure.
The FBI is urging organizations to review the advisory's published indicators of compromise, patch the named vulnerabilities, disable unnecessary exposed services, and enforce multifactor authentication, as reported by BleepingComputer.
Originally reported by BleepingComputer. Read the original article for additional details.
View original source