The U.S. Justice Department and FBI have seized two hacking tools, Microscan and FishHub, that court documents say were operated and used by Flax Typhoon actors working for a China-based company. According to the government, the tools were used to scan, and in some cases hack, U.S. and foreign critical infrastructure systems and other networks.
The court-authorized seizures were announced alongside court documents unsealed in the Western District of Pennsylvania. Prosecutors allege the actors worked for Integrity Technology Group (Integrity Tech), a company based in the People’s Republic of China (PRC) that holds contracts with the PRC government. The action is the latest step by U.S. authorities against China state-sponsored hackers.
How Flax Typhoon Actors Used Microscan for Vulnerability Scanning
According to court documents, Integrity Tech built and used a botnet of internet-of-things devices infected with a variant of Mirai malware. The botnet supported the company’s vulnerability scanning through Microscan, a tool Integrity Tech developed to perform reconnaissance on victim networks and identify weaknesses its clients would later exploit.
Targets of Microscan scanning included a U.S. power company based in South Carolina, a multinational non-governmental organization, airports in Japan and Poland, Taiwanese critical infrastructure companies in the natural gas and power sectors, and two Taiwanese universities. Integrity Tech accessed Microscan through c0cc[.]cc, one of the seized domains.
FishHub and the Flax Typhoon Spear Phishing Operation
The second tool, FishHub, allegedly helped compromise computer networks through spear phishing. After gaining initial access, FishHub downloaded additional malware to the victim network. That malware either gave Integrity Tech’s clients unauthorized remote access or searched for specific files and sent them to servers controlled by Integrity Tech.
Confirmed FishHub victims included about 20 Taiwanese universities. Five seized domains helped deliver the malware: 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net.
What Officials Said About Flax Typhoon
Assistant Attorney General for National Security John A. Eisenberg said the United States “will not allow China or its proxies to operate against United States interests with impunity in cyberspace.” He added that the National Security Division would continue working to disrupt the Flax Typhoon threats and dismantle the infrastructure sustaining them.
Assistant Director Brett Leatherman of the FBI’s Cyber Division said, “The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure.”
U.S. Attorney Troy Rivetti for the Western District of Pennsylvania described the seizures as the second disruption of Integrity Tech’s operations in as many years. Special Agent in Charge Mark Remily of the FBI San Diego Field Office said the action reflects the FBI’s commitment to disrupting PRC state-sponsored cyber actors who threaten critical infrastructure and national security.
Second Disruption of Flax Typhoon Infrastructure
This is the Justice Department’s second public technical disruption of Integrity Tech’s hacking infrastructure. In September 2024, the department announced the court-authorized disruption of Integrity Tech’s Mirai botnet, which included more than 200,000 consumer devices in the United States and worldwide.
Alongside the latest seizures, the FBI and other U.S. and foreign partner agencies published a cybersecurity advisory listing indicators of compromise tied to Integrity Tech intrusion activity. The advisory is intended to help network defenders identify and respond to the group’s malicious activity.
The FBI San Diego and Baltimore Field Offices are investigating the case in coordination with the FBI’s Cyber Division. Assistant U.S. Attorney Brendan McKenna for the Western District of Pennsylvania and Trial Attorney Jacques Singer-Emery of the National Security Division’s National Security Cyber Section are prosecuting the case. Assistant U.S. Attorney Thomas Sullivan for the District of Maryland and the National Police Agency of Japan provided substantial assistance.






































