# FBI/DOJ Seize Microscan Vulnerability Scanner and FishHub Spear-Phishing Infrastructure Operated by China-Based Integrity Technology Group (Flax Typhoon-linked)

> On 2026-10-08 the FBI and U.S. Justice Department announced a court-authorized seizure of seven domains tied to Microscan, a Python-based vulnerability scanner, and FishHub, a spear-phishing and file-theft platform, both allegedly operated by China-based Integrity Technology Group. Court documents link the activity to Flax Typhoon; reported targets include a South Carolina power company, airports in Japan and Poland, Taiwanese energy firms and universities, and a multinational NGO.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T06:54:54.481Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3077
- **ID:** TL-2026-3077
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** Flax Typhoon (China)
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2024-21887

## Description

The Justice Department and FBI, with partner agencies (National Police Agency of Japan; per press coverage also Australia, the UK, Spain, New Zealand and Canada), seized seven domains under court documents unsealed in the Western District of Pennsylvania (DOJ press release 26-1155; FBI San Diego and Baltimore Field Offices). Integrity Technology Group (Integrity Tech) is a PRC-based company that U.S. authorities say holds Chinese government contracts and is already sanctioned; it is associated with the group tracked by Microsoft as Flax Typhoon (also reported as Ethereal Panda and Red Juliett).

Microscan is a Python-based vulnerability scanner containing more than 1,300 penetration-testing scripts, in use since at least 2017. Reporting says it paired with a Mirai-variant botnet for network reconnaissance and checked for flaws in products including Oracle WebLogic, WordPress, Jenkins, Apache Struts, OpenSSL and Juniper ScreenOS. BleepingComputer lists scanner-targeted CVEs: CVE-2015-3306 (ProFTPD), CVE-2015-5477 (ISC BIND), CVE-2016-3081 (Apache Struts), CVE-2021-3199 (ONLYOFFICE), CVE-2023-22894 (Strapi), CVE-2014-6278 (Shellshock), CVE-2019-11510 (Pulse Secure VPN) and CVE-2021-22205 (GitLab). The Microscan access domain c0cc.cc was confirmed online in September 2026. Scanning victims named in the sources include a South Carolina power company, a multinational NGO, airports in Japan and Poland, and Taiwanese natural gas and power companies. Two Taiwanese universities were scanned and then intruded; Microscan scanned Taiwanese university networks in August 2022 and March 2023.

FishHub is a spear-phishing platform used to deliver malware, provide remote access and steal files to servers controlled by Integrity Tech. Five domains delivered malware (98aicai.com, 98aicode.com, linkedinns.net, outlook3650.com, youtubecard.com); the lookalike names impersonate LinkedIn, Outlook/Microsoft 365 and YouTube. A seventh domain, 98aiblog.com, was tied to SoftEther VPN software installed on compromised systems to keep remote access. Per the FBI affidavit, a FishHub-linked server held data and files from more than 20 organizations, including six Taiwanese universities (other coverage cites roughly 20 Taiwanese universities affected).

Additional tooling in the reporting: EBurst, a password-spraying/guessing tool against Microsoft Exchange; a custom web application for browsing stolen email; and Active Directory credential-theft utilities. Historic Flax Typhoon TTPs cited include edge-device and IoT exploitation, living-off-the-land use of legitimate Windows tools, long-term persistence, and email credential harvesting from on-premises and cloud systems, with exfiltration reportedly restricted to Xiamen, China IP addresses. Integrity Tech's earlier Mirai-variant botnet (Raptor Train) was disrupted in September 2024; botnet size is reported as 200,000+ devices by most sources and 260,000+ by The Record. The FBI-led joint advisory with IOCs (IC3 261008.pdf) could not be parsed in this run, so IOCs here come from news and DOJ reporting only. No CVE is the subject of this threat and no CVSS applies.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1583.001 Domains
- T1584.005 Botnet
- T1566 Phishing
- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1110.003 Password Spraying
- T1003 OS Credential Dumping
- T1114.002 Remote Email Collection
- T1583.003 Acquire Infrastructure
- T1587.001 Develop Capabilities
- T1059.006 Command and Scripting Interpreter
- T1505.003 Server Software Component
- T1036.005 Masquerading
- T1003.001 OS Credential Dumping
- T1572 Protocol Tunneling
- T1219 Remote Access Tools
- T1105 Ingress Tool Transfer
- T1498 Network Denial of Service

## Sources

- [FBI Seized Vulnerability Scanning and Spear Phishing Tools Used by China-Linked Hackers](https://cybersecuritynews.com/fbi-seized-chinese-hacking-tools/)
- [Justice Department and FBI Seize Vulnerability Scanning and Spear-Phishing Tools Operated by China-Based Integrity Technology Group](https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-vulnerability-scanning-and-spear-phishing-tools-operated)
- [Justice Department and FBI Seize Vulnerability Scanning and Spear-Phishing Tools (W.D. Pennsylvania)](https://www.justice.gov/usao-wdpa/pr/justice-department-and-fbi-seize-vulnerability-scanning-and-spear-phishing-tools)
- [FBI-led joint cybersecurity advisory with IOCs (IC3 261008)](https://www.ic3.gov/CSA/2026/261008.pdf)
- [FBI disrupts Chinese hacking tools used to breach critical infrastructure](https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/)
- [International coalition seizes tools used by cyber firm behind Flax Typhoon](https://therecord.media/flax-typhoon-china-tools-integrity-tech-international-takedown)
- [FBI Seizes Flax Typhoon Hacking Tools Linked to Chinese Contractor](https://hackread.com/fbi-seizes-flax-typhoon-hacking-tools-china/)
- [Flax Typhoon: MicroScan Scanned Japanese Airports; U.S. Seizes Seven Domains](https://dev.to/anoymask/flax-typhoon-microscan-scanned-japanese-airports-us-seizes-seven-domains-kea)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3077
