US seizes seven domains tied to Integrity Tech tools
Microscan performed network reconnaissance while FishHub supported spear-phishing attacks; the court action was paired with an international technical advisory.
R42 / SUMMARY
The US Justice Department and FBI seized seven domains associated with Microscan and FishHub, tools that American authorities attribute to operators linked to Integrity Technology Group. The action disrupts infrastructure used for scanning, spear phishing and remote access, but it does not mean every compromised system or responsible actor has been neutralized.
KEY POINTS
- A US court authorized the seizure of seven domains on October 8, 2026.
- Microscan was used to identify vulnerabilities in internet-facing networks.
- FishHub supported spear phishing and malware delivery after initial access.
- Claims tying the activity to Integrity Tech and Chinese government-linked actors are attributions by US authorities and partners.
- The advisory recommends patching, MFA and closer monitoring of edge devices.
The US Department of Justice and FBI announced on October 8, 2026 that a court had authorized the seizure of seven domains associated with two intrusion tools, Microscan and FishHub. According to documents presented by the authorities, operators linked to China-based Integrity Technology Group used the infrastructure to locate vulnerable networks and support attacks against organizations in the United States and other countries.
The court order and domain seizures are confirmed actions. Responsibility attributed to Integrity Tech, links to Chinese state-sponsored operations and the connection to the cluster known as Flax Typhoon are assessments made by the US government and international partners. Integrity Tech has contracts with the Chinese government, according to the Justice Department. China’s foreign ministry told Reuters that it opposes hacking activity and what it described as ill-intentioned misinformation.
Two tools served different stages of an operation
Microscan was used for reconnaissance. It searched exposed services and vulnerabilities that could later be exploited. The Justice Department says the tool operated, among other methods, through a network of internet-of-things devices infected with a variant of the Mirai malware.
Scanning targets named in the court documents include a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and power companies, two Taiwanese universities and a multinational nongovernmental organization. Being scanned does not necessarily mean that a network was breached; reconnaissance maps possible entry points.
FishHub operated at a later stage. Prosecutors say the tool supported spear-phishing campaigns and delivered malware after initial access. That code could provide unauthorized remote control, search for particular files and send them to servers controlled by the operators. Approximately 20 Taiwanese universities are described as confirmed victims of this activity.
The advisory extends beyond the seized domains
The seizure coincided with a joint advisory from CISA, the FBI, the NSA and security agencies in other countries. It describes combinations of automated scanning, hands-on exploitation, botnets, VPN infrastructure and legitimate system tools used to preserve access without drawing attention.
Named sectors include government, critical manufacturing, healthcare, information technology, law enforcement, education and religious organizations. The advisory also notes that edge devices connecting corporate networks to the internet may receive less monitoring than internal servers, creating an opportunity for intruders to maintain access for longer periods.
To reduce exposure, the agencies recommend disabling unused services and ports, applying fixes for known vulnerabilities listed in the advisory, sanitizing web application inputs and requiring multifactor authentication wherever possible. Organizations can also compare their logs against the published indicators of compromise.
Seizure disrupts infrastructure without ending the threat
Removing domains from the operators’ control makes the tools harder to reach and can break stages of malware delivery. It does not automatically repair previously compromised equipment, remove copies of the tools hosted elsewhere or amount to the arrest of the people responsible.
The Justice Department describes this as its second public technical disruption of infrastructure attributed to Integrity Tech. In September 2024, another operation dismantled a botnet built from more than 200,000 compromised consumer devices. That history defines the immediate value of the latest action: limiting available resources and giving defenders technical evidence, without claiming that the group or its capabilities have disappeared.
Gabriel Silva
Responsible for reporting and writing this story at Rota42.
R42 / FAQ
What did the United States seize?
Authorities seized seven domains associated with access to and delivery of two tools, Microscan and FishHub. The court-authorized action was announced on October 8, 2026.
What did Microscan and FishHub do?
Microscan automated network reconnaissance to find vulnerabilities. FishHub supported spear phishing and, after an initial breach, delivered malware that could provide remote access or locate and remove files.
Were all the named targets successfully hacked?
No. Scanning identifies possible weaknesses but does not prove a breach. The Justice Department does say that approximately 20 Taiwanese universities were confirmed victims of FishHub-related activity.
What is Flax Typhoon?
Flax Typhoon is a security-industry name used to track a cluster of cyber activity. The international advisory says some observed techniques are consistent with that cluster while cautioning that vendor labels do not necessarily map to exactly the same actor.
What defensive steps did the advisory recommend?
Recommendations include disabling unused services and ports, patching known vulnerabilities, sanitizing web application inputs, requiring multifactor authentication and hunting for indicators of compromise on internet-facing devices.