Threat reportAPTTL-2026-3077

FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub Spear-Phishing Infrastructure Operated by China-Based Integrity Technology Group (Flax Typhoon-linked)

highACTIVE

FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub (TL-2026-3077), also tracked as Microscan, is a high-severity advanced persistent threat campaign, first published 2026-10-09. It is attributed to Flax Typhoon (China) with medium confidence, affects Microsoft Exchange Server, references 1 CVE (CVE-2024-21887), maps to 19 MITRE ATT&CK techniques (T1003, T1003.001, T1036.005), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
1Referenced vulnerabilities
Techniques
19MITRE ATT&CK
Actors
2Flax Typhoon
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-3077

Threat ID
TL-2026-3077
Also known as
Microscan, FishHub, Raptor Train
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
Flax Typhoon, Integrity Technology Group
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
energy, utilities, aviation, education, government administration, health, manufacturing, non-profit organisation
Target regions
taiwan, united states of america, japan, poland, Southeast Asia, Africa
Detection rules
9
Indicators of compromise
28
Updates
2026-10-09 · revalidated 1× · latest source

Malware and tooling in FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub

Malware and tooling: Mirai, EBurst, FishHub, Microscan, Mirai, SoftEther VPN

How FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub works

On 2026-10-08 the FBI and U.S. Justice Department announced a court-authorized seizure of seven domains tied to Microscan, a Python-based vulnerability scanner, and FishHub, a spear-phishing and file-theft platform, both allegedly operated by China-based Integrity Technology Group. Court documents link the activity to Flax Typhoon; reported targets include a South Carolina power company, airports in Japan and Poland, Taiwanese energy firms and universities, and a multinational NGO.

The Justice Department and FBI, with partner agencies (National Police Agency of Japan; per press coverage also Australia, the UK, Spain, New Zealand and Canada), seized seven domains under court documents unsealed in the Western District of Pennsylvania (DOJ press release 26-1155; FBI San Diego and Baltimore Field Offices). Integrity Technology Group (Integrity Tech) is a PRC-based company that U.S. authorities say holds Chinese government contracts and is already sanctioned; it is associated with the group tracked by Microsoft as Flax Typhoon (also reported as Ethereal Panda and Red Juliett).

Microscan is a Python-based vulnerability scanner containing more than 1,300 penetration-testing scripts, in use since at least 2017. Reporting says it paired with a Mirai-variant botnet for network reconnaissance and checked for flaws in products including Oracle WebLogic, WordPress, Jenkins, Apache Struts, OpenSSL and Juniper ScreenOS. BleepingComputer lists scanner-targeted CVEs: CVE-2015-3306 (ProFTPD), CVE-2015-5477 (ISC BIND), CVE-2016-3081 (Apache Struts), CVE-2021-3199 (ONLYOFFICE), CVE-2023-22894 (Strapi), CVE-2014-6278 (Shellshock), CVE-2019-11510 (Pulse Secure VPN) and CVE-2021-22205 (GitLab). The Microscan access domain c0cc.cc was confirmed online in September 2026. Scanning victims named in the sources include a South Carolina power company, a multinational NGO, airports in Japan and Poland, and Taiwanese natural gas and power companies. Two Taiwanese universities were scanned and then intruded; Microscan scanned Taiwanese university networks in August 2022 and March 2023.

FishHub is a spear-phishing platform used to deliver malware, provide remote access and steal files to servers controlled by Integrity Tech. Five domains delivered malware (98aicai.com, 98aicode.com, linkedinns.net, outlook3650.com, youtubecard.com); the lookalike names impersonate LinkedIn, Outlook/Microsoft 365 and YouTube. A seventh domain, 98aiblog.com, was tied to SoftEther VPN software installed on compromised systems to keep remote access. Per the FBI affidavit, a FishHub-linked server held data and files from more than 20 organizations, including six Taiwanese universities (other coverage cites roughly 20 Taiwanese universities affected).

Additional tooling in the reporting: EBurst, a password-spraying/guessing tool against Microsoft Exchange; a custom web application for browsing stolen email; and Active Directory credential-theft utilities. Historic Flax Typhoon TTPs cited include edge-device and IoT exploitation, living-off-the-land use of legitimate Windows tools, long-term persistence, and email credential harvesting from on-premises and cloud systems, with exfiltration reportedly restricted to Xiamen, China IP addresses. Integrity Tech's earlier Mirai-variant botnet (Raptor Train) was disrupted in September 2024; botnet size is reported as 200,000+ devices by most sources and 260,000+ by The Record. The FBI-led joint advisory with IOCs (IC3 261008.pdf) could not be parsed in this run, so IOCs here come from news and DOJ reporting only. No CVE is the subject of this threat and no CVSS applies.

MITRE ATT&CK techniques used in TL-2026-3077

Credential Access

T1003 OS Credential Dumping; T1003.001 OS Credential Dumping; T1110.003 Password Spraying

Defense Evasion

T1036.005 Masquerading

Execution

T1059.006 Command and Scripting Interpreter

Command and Control

T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1572 Protocol Tunneling

Collection

T1114.002 Remote Email Collection

Persistence

T1133 External Remote Services; T1505.003 Server Software Component

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing

Impact

T1498 Network Denial of Service

Resource Development

T1583.001 Domains; T1583.003 Acquire Infrastructure; T1584.005 Botnet; T1587.001 Develop Capabilities

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub

  • Microsoft — Exchange Server
    Vulnerable versions: Internet-exposed instances without MFA or spray protection
  • Various — Internet-facing servers and edge devices scanned by Microscan (Oracle WebLogic, WordPress, Jenkins, Apache Struts, OpenSSL, Juniper ScreenOS)
    Vulnerable versions: Unpatched versions

Remediation for FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub

Patches

  • Apply vendor patches for CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, CVE-2023-22894, CVE-2014-6278, CVE-2019-11510 and CVE-2021-22205 where affected products remain deployed

Immediate actions

  • Hunt DNS, proxy and email logs for the seven seized domains: c0cc.cc, 98aicai.com, 98aicode.com, 98aiblog.com, linkedinns.net, outlook3650.com, youtubecard.com
  • Search endpoints and servers for unauthorized SoftEther VPN client/server installations
  • Review Exchange authentication logs for password-spraying patterns and reset exposed credentials
  • Review the FBI-led joint advisory (IC3 261008.pdf) and load its IOCs into detection tooling

Workarounds

  • Block egress to the seized domains and restrict outbound VPN protocols to approved endpoints

Longer-term hardening

  • Patch internet-facing products commonly checked by Microscan (WebLogic, Struts, Jenkins, WordPress, OpenSSL, Juniper ScreenOS, Pulse Secure, GitLab)
  • Enforce MFA on Exchange and VPN access and monitor for AD credential theft
  • Monitor edge devices and IoT/NAS/camera assets that are weakly logged
  • Train users on spear-phishing using brand-lookalike domains

CVEs associated with FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub

CVE-2024-21887

Timeline of FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub

  • Microscan usage traced back to at least 2017 (year-level precision in sources).
  • Raptor Train Crossbill campaign begins (k3121.com), running until April 2022 per Lumen.
  • Microscan scanned Taiwanese university networks (August 2022), per BleepingComputer.
  • Microsoft researchers publicly identified Flax Typhoon in 2023 (year-level precision in sources).
  • Further Microscan scanning of Taiwanese university networks (March 2023).
  • Oriole campaign begins on w8510.com infrastructure, averaging ~30,000 devices by August 2024.
  • Microsoft publishes Flax Typhoon analysis of Taiwan-focused living-off-the-land intrusions (SoftEther VPN, China Chopper, Mimikatz).
  • Botnet database holds ~1.2 million infected-device records (~385,000 unique U.S. devices).
  • DOJ/FBI disrupted an Integrity Tech Mirai-variant botnet of 200,000+ consumer devices (The Record cites 260,000+).
  • FBI court-authorized disruption of Raptor Train and joint Five Eyes advisory; operators attempted migration and a DDoS.
  • U.S. sanctions Integrity Technology Group for its role in Flax Typhoon attacks.
  • Microscan access domain c0cc.cc confirmed online in September 2026.
  • Microscan still accessible via c0cc.cc (day-level date; existing record has September 2026).
  • DOJ and FBI announced court-authorized seizure of seven Microscan/FishHub domains; documents unsealed in W.D. Pennsylvania; joint advisory with IOCs published.
  • Cyber Security News and Hackread published coverage of the seizure.

Update history for TL-2026-3077

Sources cited for FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub

Detection coverage for TL-2026-3077

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3077 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats