Skip to content
R42 / Technology / 00213

US seizes seven domains tied to Integrity Tech tools

Microscan performed network reconnaissance while FishHub supported spear-phishing attacks; the court action was paired with an international technical advisory.

09.10.26 Gabriel Silva 3 MIN
WhatsApp X Facebook LinkedIn Telegram Email

R42 / SUMMARY

The US Justice Department and FBI seized seven domains associated with Microscan and FishHub, tools that American authorities attribute to operators linked to Integrity Technology Group. The action disrupts infrastructure used for scanning, spear phishing and remote access, but it does not mean every compromised system or responsible actor has been neutralized.

KEY POINTS

  1. 01A US court authorized the seizure of seven domains on October 8, 2026.
  2. 02Microscan was used to identify vulnerabilities in internet-facing networks.
  3. 03FishHub supported spear phishing and malware delivery after initial access.
  4. 04Claims tying the activity to Integrity Tech and Chinese government-linked actors are attributions by US authorities and partners.
  5. 05The advisory recommends patching, MFA and closer monitoring of edge devices.

The US Department of Justice and FBI announced on October 8, 2026 that a court had authorized the seizure of seven domains associated with two intrusion tools, Microscan and FishHub. According to documents presented by the authorities, operators linked to China-based Integrity Technology Group used the infrastructure to locate vulnerable networks and support attacks against organizations in the United States and other countries.

The court order and domain seizures are confirmed actions. Responsibility attributed to Integrity Tech, links to Chinese state-sponsored operations and the connection to the cluster known as Flax Typhoon are assessments made by the US government and international partners. Integrity Tech has contracts with the Chinese government, according to the Justice Department. China’s foreign ministry told Reuters that it opposes hacking activity and what it described as ill-intentioned misinformation.

Two tools served different stages of an operation

Microscan was used for reconnaissance. It searched exposed services and vulnerabilities that could later be exploited. The Justice Department says the tool operated, among other methods, through a network of internet-of-things devices infected with a variant of the Mirai malware.

Scanning targets named in the court documents include a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and power companies, two Taiwanese universities and a multinational nongovernmental organization. Being scanned does not necessarily mean that a network was breached; reconnaissance maps possible entry points.

FishHub operated at a later stage. Prosecutors say the tool supported spear-phishing campaigns and delivered malware after initial access. That code could provide unauthorized remote control, search for particular files and send them to servers controlled by the operators. Approximately 20 Taiwanese universities are described as confirmed victims of this activity.

The advisory extends beyond the seized domains

The seizure coincided with a joint advisory from CISA, the FBI, the NSA and security agencies in other countries. It describes combinations of automated scanning, hands-on exploitation, botnets, VPN infrastructure and legitimate system tools used to preserve access without drawing attention.

Named sectors include government, critical manufacturing, healthcare, information technology, law enforcement, education and religious organizations. The advisory also notes that edge devices connecting corporate networks to the internet may receive less monitoring than internal servers, creating an opportunity for intruders to maintain access for longer periods.

To reduce exposure, the agencies recommend disabling unused services and ports, applying fixes for known vulnerabilities listed in the advisory, sanitizing web application inputs and requiring multifactor authentication wherever possible. Organizations can also compare their logs against the published indicators of compromise.

Seizure disrupts infrastructure without ending the threat

Removing domains from the operators’ control makes the tools harder to reach and can break stages of malware delivery. It does not automatically repair previously compromised equipment, remove copies of the tools hosted elsewhere or amount to the arrest of the people responsible.

The Justice Department describes this as its second public technical disruption of infrastructure attributed to Integrity Tech. In September 2024, another operation dismantled a botnet built from more than 200,000 compromised consumer devices. That history defines the immediate value of the latest action: limiting available resources and giving defenders technical evidence, without claiming that the group or its capabilities have disappeared.

Written by

Gabriel Silva

Responsible for reporting and writing this story at Rota42.

R42 / FAQ

What did the United States seize?

Authorities seized seven domains associated with access to and delivery of two tools, Microscan and FishHub. The court-authorized action was announced on October 8, 2026.

What did Microscan and FishHub do?

Microscan automated network reconnaissance to find vulnerabilities. FishHub supported spear phishing and, after an initial breach, delivered malware that could provide remote access or locate and remove files.

Were all the named targets successfully hacked?

No. Scanning identifies possible weaknesses but does not prove a breach. The Justice Department does say that approximately 20 Taiwanese universities were confirmed victims of FishHub-related activity.

What is Flax Typhoon?

Flax Typhoon is a security-industry name used to track a cluster of cyber activity. The international advisory says some observed techniques are consistent with that cluster while cautioning that vendor labels do not necessarily map to exactly the same actor.

What defensive steps did the advisory recommend?

Recommendations include disabling unused services and ports, patching known vulnerabilities, sanitizing web application inputs, requiring multifactor authentication and hunting for indicators of compromise on internet-facing devices.

Continue reading

View archive

We use necessary storage for operation and security. With your permission, we enable audience measurement, personalization and optional advertising features.

Necessary Always active for security, session, language, theme and recording your choice. Analytics Allows audience, navigation and performance measurement to improve content and experience. Personalization Allows content, preferences and experiences to be adapted based on your choices. Marketing Allows advertising storage, ad personalization and full measurement.

Install Rota42

On iPhone or iPad, open Rota42 in Safari and follow these steps:

  1. Tap Share in the Safari menu.
  2. Choose “Add to Home Screen”.
  3. Enable “Open as Web App”, then tap Add.