Threat reportAPTTL-2026-3077
FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub Spear-Phishing Infrastructure Operated by China-Based Integrity Technology Group (Flax Typhoon-linked)
FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub (TL-2026-3077), also tracked as Microscan, is a high-severity advanced persistent threat campaign, first published 2026-10-09. It is attributed to Flax Typhoon (China) with medium confidence, affects Microsoft Exchange Server, references 1 CVE (CVE-2024-21887), maps to 19 MITRE ATT&CK techniques (T1003, T1003.001, T1036.005), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 19MITRE ATT&CK
- Actors
- 2Flax Typhoon
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-3077
- Threat ID
- TL-2026-3077
- Also known as
- Microscan, FishHub, Raptor Train
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- Flax Typhoon, Integrity Technology Group
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- energy, utilities, aviation, education, government administration, health, manufacturing, non-profit organisation
- Target regions
- taiwan, united states of america, japan, poland, Southeast Asia, Africa
- Detection rules
- 9
- Indicators of compromise
- 28
- Updates
- 2026-10-09 · revalidated 1× · latest source
Malware and tooling in FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub
Malware and tooling: Mirai, EBurst, FishHub, Microscan, Mirai, SoftEther VPN
How FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub works
On 2026-10-08 the FBI and U.S. Justice Department announced a court-authorized seizure of seven domains tied to Microscan, a Python-based vulnerability scanner, and FishHub, a spear-phishing and file-theft platform, both allegedly operated by China-based Integrity Technology Group. Court documents link the activity to Flax Typhoon; reported targets include a South Carolina power company, airports in Japan and Poland, Taiwanese energy firms and universities, and a multinational NGO.
The Justice Department and FBI, with partner agencies (National Police Agency of Japan; per press coverage also Australia, the UK, Spain, New Zealand and Canada), seized seven domains under court documents unsealed in the Western District of Pennsylvania (DOJ press release 26-1155; FBI San Diego and Baltimore Field Offices). Integrity Technology Group (Integrity Tech) is a PRC-based company that U.S. authorities say holds Chinese government contracts and is already sanctioned; it is associated with the group tracked by Microsoft as Flax Typhoon (also reported as Ethereal Panda and Red Juliett).
Microscan is a Python-based vulnerability scanner containing more than 1,300 penetration-testing scripts, in use since at least 2017. Reporting says it paired with a Mirai-variant botnet for network reconnaissance and checked for flaws in products including Oracle WebLogic, WordPress, Jenkins, Apache Struts, OpenSSL and Juniper ScreenOS. BleepingComputer lists scanner-targeted CVEs: CVE-2015-3306 (ProFTPD), CVE-2015-5477 (ISC BIND), CVE-2016-3081 (Apache Struts), CVE-2021-3199 (ONLYOFFICE), CVE-2023-22894 (Strapi), CVE-2014-6278 (Shellshock), CVE-2019-11510 (Pulse Secure VPN) and CVE-2021-22205 (GitLab). The Microscan access domain c0cc.cc was confirmed online in September 2026. Scanning victims named in the sources include a South Carolina power company, a multinational NGO, airports in Japan and Poland, and Taiwanese natural gas and power companies. Two Taiwanese universities were scanned and then intruded; Microscan scanned Taiwanese university networks in August 2022 and March 2023.
FishHub is a spear-phishing platform used to deliver malware, provide remote access and steal files to servers controlled by Integrity Tech. Five domains delivered malware (98aicai.com, 98aicode.com, linkedinns.net, outlook3650.com, youtubecard.com); the lookalike names impersonate LinkedIn, Outlook/Microsoft 365 and YouTube. A seventh domain, 98aiblog.com, was tied to SoftEther VPN software installed on compromised systems to keep remote access. Per the FBI affidavit, a FishHub-linked server held data and files from more than 20 organizations, including six Taiwanese universities (other coverage cites roughly 20 Taiwanese universities affected).
Additional tooling in the reporting: EBurst, a password-spraying/guessing tool against Microsoft Exchange; a custom web application for browsing stolen email; and Active Directory credential-theft utilities. Historic Flax Typhoon TTPs cited include edge-device and IoT exploitation, living-off-the-land use of legitimate Windows tools, long-term persistence, and email credential harvesting from on-premises and cloud systems, with exfiltration reportedly restricted to Xiamen, China IP addresses. Integrity Tech's earlier Mirai-variant botnet (Raptor Train) was disrupted in September 2024; botnet size is reported as 200,000+ devices by most sources and 260,000+ by The Record. The FBI-led joint advisory with IOCs (IC3 261008.pdf) could not be parsed in this run, so IOCs here come from news and DOJ reporting only. No CVE is the subject of this threat and no CVSS applies.
MITRE ATT&CK techniques used in TL-2026-3077
Credential Access
T1003 OS Credential Dumping; T1003.001 OS Credential Dumping; T1110.003 Password Spraying
Defense Evasion
Execution
T1059.006 Command and Scripting Interpreter
Command and Control
T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1572 Protocol Tunneling
Collection
T1114.002 Remote Email Collection
Persistence
T1133 External Remote Services; T1505.003 Server Software Component
Initial Access
T1190 Exploit Public-Facing Application; T1566 Phishing
Impact
T1498 Network Denial of Service
Resource Development
T1583.001 Domains; T1583.003 Acquire Infrastructure; T1584.005 Botnet; T1587.001 Develop Capabilities
Reconnaissance
Affected products and versions in FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub
- Microsoft — Exchange Server
Vulnerable versions: Internet-exposed instances without MFA or spray protection - Various — Internet-facing servers and edge devices scanned by Microscan (Oracle WebLogic, WordPress, Jenkins, Apache Struts, OpenSSL, Juniper ScreenOS)
Vulnerable versions: Unpatched versions
Remediation for FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub
Patches
- Apply vendor patches for CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, CVE-2023-22894, CVE-2014-6278, CVE-2019-11510 and CVE-2021-22205 where affected products remain deployed
Immediate actions
- Hunt DNS, proxy and email logs for the seven seized domains: c0cc.cc, 98aicai.com, 98aicode.com, 98aiblog.com, linkedinns.net, outlook3650.com, youtubecard.com
- Search endpoints and servers for unauthorized SoftEther VPN client/server installations
- Review Exchange authentication logs for password-spraying patterns and reset exposed credentials
- Review the FBI-led joint advisory (IC3 261008.pdf) and load its IOCs into detection tooling
Workarounds
- Block egress to the seized domains and restrict outbound VPN protocols to approved endpoints
Longer-term hardening
- Patch internet-facing products commonly checked by Microscan (WebLogic, Struts, Jenkins, WordPress, OpenSSL, Juniper ScreenOS, Pulse Secure, GitLab)
- Enforce MFA on Exchange and VPN access and monitor for AD credential theft
- Monitor edge devices and IoT/NAS/camera assets that are weakly logged
- Train users on spear-phishing using brand-lookalike domains
CVEs associated with FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub
Timeline of FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub
- Microscan usage traced back to at least 2017 (year-level precision in sources).
- Raptor Train Crossbill campaign begins (k3121.com), running until April 2022 per Lumen.
- Microscan scanned Taiwanese university networks (August 2022), per BleepingComputer.
- Microsoft researchers publicly identified Flax Typhoon in 2023 (year-level precision in sources).
- Further Microscan scanning of Taiwanese university networks (March 2023).
- Oriole campaign begins on w8510.com infrastructure, averaging ~30,000 devices by August 2024.
- Microsoft publishes Flax Typhoon analysis of Taiwan-focused living-off-the-land intrusions (SoftEther VPN, China Chopper, Mimikatz).
- Botnet database holds ~1.2 million infected-device records (~385,000 unique U.S. devices).
- DOJ/FBI disrupted an Integrity Tech Mirai-variant botnet of 200,000+ consumer devices (The Record cites 260,000+).
- FBI court-authorized disruption of Raptor Train and joint Five Eyes advisory; operators attempted migration and a DDoS.
- U.S. sanctions Integrity Technology Group for its role in Flax Typhoon attacks.
- Microscan access domain c0cc.cc confirmed online in September 2026.
- Microscan still accessible via c0cc.cc (day-level date; existing record has September 2026).
- DOJ and FBI announced court-authorized seizure of seven Microscan/FishHub domains; documents unsealed in W.D. Pennsylvania; joint advisory with IOCs published.
- Cyber Security News and Hackread published coverage of the seizure.
Update history for TL-2026-3077
- 2026-10-09 — Flax Typhoon: FBI Seizes 7 Domains, Disrupts Mirai-Variant IoT Botnet and Tooling Used in Critical Infrastructure Intrusions: What changed No severity, exploitability or status change: HIGH / ACTIVE already reflect the situation. The update expands scope from Microscan/FishHub to the wider Raptor Train / Nosedive Mirai-variant botnet toolchain (Sparrow, Condor) se
Sources cited for FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub
- FBI Seized Vulnerability Scanning and Spear Phishing Tools Used by China-Linked Hackers
- Justice Department and FBI Seize Vulnerability Scanning and Spear-Phishing Tools Operated by China-Based Integrity Technology Group
- Justice Department and FBI Seize Vulnerability Scanning and Spear-Phishing Tools (W.D. Pennsylvania)
- FBI-led joint cybersecurity advisory with IOCs (IC3 261008)
- FBI disrupts Chinese hacking tools used to breach critical infrastructure
- International coalition seizes tools used by cyber firm behind Flax Typhoon
- FBI Seizes Flax Typhoon Hacking Tools Linked to Chinese Contractor
- Flax Typhoon: MicroScan Scanned Japanese Airports; U.S. Seizes Seven Domains
Detection coverage for TL-2026-3077
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3077 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.