Thursday, 8 October 2026

Seven domains seized after FBI halts China-linked intrusion platforms

U.S. authorities seized domains and disrupted two tools that state-linked hackers used to scan and breach critical infrastructure worldwide.

Rows of data center servers in a cool-lit room

The short version

  • The FBI seized seven domains and disrupted two hacking platforms tied to a China-linked group.
  • MicroScan and FishHub were used to identify weaknesses and deliver malware, enabling intrusions into networks worldwide.
  • Authorities say Integrity Technology Group, linked to the Chinese government, supplied capabilities to state-backed actors for broad scouting and intrusions.
  • A joint cybersecurity advisory provides indicators of compromise to help organizations defend against similar attacks.
Quick read · 1 min

The FBI has shut down seven domains tied to a China-linked hacking operation that used two tools, MicroScan and FishHub, to probe networks and breach critical infrastructure around the world. Integrity Technology Group is named as the company behind the operation, connected to the Chinese government.

What this means for you: large services and universities could be at risk if defenses aren’t up to date. If your organization hasn’t patched systems or enabled multifactor authentication, you could be exposed to phishing or malware that gains remote access after an intrusion.

What happens next: authorities released a joint advisory with concrete indicators of compromise to help organizations detect intrusions and fix gaps. Expect ongoing collaboration between U.S. and international partners to disrupt related operations and share defense guidance.

The FBI has halted seven domains tied to a China-linked hacking operation, taking down the infrastructure behind two tools used to scan for security gaps and break into networks. Officials say the operation ran through Integrity Technology Group, a company with ties to the Chinese government, to help global attackers identify weaknesses and, in some cases, breach networks that support critical services.

U.S. officials describe Integrity Tech as a contractor with direct connections to the Chinese state. The two tools, MicroScan and FishHub, were deployed to find security flaws and to deliver malware that allowed attackers to maintain access after an initial intrusion. Targets spanned the United States and other regions, including a power utility in the U.S., airports abroad, energy firms in Asia, and several universities. In at least two cases, MicroScan scans led to breaches at Taiwanese universities in 2022 and 2023, according to the affidavit.

In addition to the seven domains seized, investigators shut down the c0cc.cc domain used to access MicroScan and five other domains that delivered the malicious code. A seventh domain connected to the SoftEther VPN software was used to keep remote access on compromised systems. The seized domains now display FBI seizure notices naming the Flax Typhoon group and Integrity Tech.

Alongside the domain actions, a joint advisory from the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency (NSA) outlines how these operators targeted sectors such as government, manufacturing, healthcare, IT services, education and faith-based organizations, with activity reported across multiple continents including North America.

MicroScan is described as a Python-based vulnerability scanner with more than 1,300 scripts meant to spot flaws in widely used software. The affidavit notes it could be used with a Mirai-style botnet to probe networks. FishHub, meanwhile, served as a spear-phishing and data-exfiltration tool after breaches, giving attackers a way to control compromised systems. Investigators found data linked to more than 20 organizations on a server tied to FishHub, including several Taiwanese universities.

The advisory lists eight commonly targeted vulnerabilities, from older flaws in ProFTPD and Bash to more recent weaknesses in VPNs and web apps. Investigators also found use of open-source tools for password-spraying attacks against Exchange servers and other methods to harvest credentials.

Authorities urge organizations to review the indicators of compromise from the advisory, patch exposed systems, disable unnecessary exposed services, and enforce multifactor authentication to reduce risk from this kind of intrusion.

Security operations center screen showing maps and logs
Padlock

You're reading the quick version.