FBI Seizes Domains Used by China-Linked Hackers to Target Critical Infrastructure

Summary
The FBI seized seven domains tied to Flax Typhoon tools MicroScan and FishHub, which authorities say were used to scan for vulnerabilities, breach organizations, steal data, and maintain access to victim networks.
Key points
- The FBI seized seven domains linked to MicroScan and FishHub, platforms allegedly operated by China-based Integrity Technology Group for Flax Typhoon.
- MicroScan used Mirai-infected devices to scan for vulnerabilities; investigators say scans led to breaches, including at two Taiwanese universities.
- FishHub supported spear-phishing, malware delivery, remote access, file searches, and data theft; investigators found files from more than 20 organizations on a linked server.
- Authorities say the activity targeted critical infrastructure and organizations across sectors and multiple regions; they did not confirm that every named target was breached.
- The FBI, CISA, NSA, and international partners issued an advisory with indicators of compromise and details of attacker tools and activity.
- Authorities urge organizations to review the indicators, patch vulnerable systems, disable unnecessary exposed services, and enforce multifactor authentication.
Article Details
- Event Type
- Law-enforcement seizure of hacking infrastructure
- Impact
- The FBI seized seven domains supporting vulnerability scanning, malware delivery, and persistent remote access. Investigators confirmed breaches of two Taiwanese universities following scans and found data belonging to more than 20 organizations, including six universities in Taiwan, on a server linked to the data-theft platform. Authorities confirmed intrusions involving critical infrastructure but did not disclose whether the specifically mentioned power companies, airports, and energy providers were successfully breached.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 98aiblog[.]com | Seized domain tied to SoftEther VPN installed on compromised systems to maintain remote access. |
| DOMAIN | 98aicai[.]com | Seized domain used to deliver malware associated with FishHub. |
| DOMAIN | 98aicode[.]com | Seized domain used to deliver malware associated with FishHub. |
| DOMAIN | c0cc[.]cc | Seized domain used by Integrity Tech to access the MicroScan vulnerability-scanning platform. |
| DOMAIN | linkedinns[.]net | Seized domain used to deliver malware associated with FishHub. |
| DOMAIN | outlook3650[.]com | Seized domain used to deliver malware associated with FishHub. |
| DOMAIN | youtubecard[.]com | Seized domain used to deliver malware associated with FishHub. |
MITRE ATT&CK
T1083 · File and Directory DiscoveryMalware enabled attackers to search compromised networks for specific files.T1110.003 · Password SprayingAttackers used EBurst to conduct password-spraying attacks against Microsoft Exchange servers.T1114 · Email CollectionAttackers used tools to steal emails; investigators also discovered an application enabling third parties to browse stolen emails.T1133 · External Remote ServicesSoftEther VPN was installed on compromised systems to maintain remote access to victim networks.T1566 · PhishingFishHub was used to conduct spear-phishing attacks.T1595.002 · Vulnerability ScanningMicroScan and a Mirai-infected botnet were used to scan potential targets for vulnerabilities.
CVE
CVE-2014-6278CVE-2014-6278: GNU Bash (Shellshock) remote code execution vulnerability.CVE-2015-3306CVE-2015-3306: ProFTPD unauthorized file read vulnerability.CVE-2015-5477CVE-2015-5477: ISC BIND denial-of-service vulnerability.CVE-2016-3081CVE-2016-3081: Apache Struts remote code execution vulnerability.CVE-2019-11510CVE-2019-11510: Pulse Secure VPN arbitrary file read vulnerability.CVE-2021-22205CVE-2021-22205: GitLab remote code execution vulnerability.CVE-2021-3199CVE-2021-3199: ONLYOFFICE DocumentServer unauthorized file write vulnerability.CVE-2023-22894CVE-2023-22894: Strapi information disclosure vulnerability.
People
Threat Actors
Ethereal PandaTracking name for operations overlapping the activity described in the joint advisory; agencies caution that not all activity is necessarily linked to Integrity Tech.Flax TyphoonChinese state-sponsored hacking group identified as using the seized infrastructure. The joint advisory describes overlapping activity tracked under this name, while cautioning that not all activity is necessarily linked to Integrity Tech.Integrity TechShort name for Integrity Technology Group, the alleged operator of MicroScan and FishHub and the operator of a Mirai botnet disrupted in 2024.Integrity Technology GroupChina-based company, also called Integrity Tech, alleged to operate MicroScan and FishHub. U.S. authorities say it has Chinese government contracts and provided capabilities used for scanning and intrusions.Red JuliettTracking name for operations overlapping the activity described in the joint advisory; agencies caution that not all activity is necessarily linked to Integrity Tech.
Malware
Products
Active Directoryattacks against Microsoft Exchange servers, along with other tools to steal emails, collect Active Directory credentials, and exfiltrate data.Apache StrutsThese scripts targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, Jenkins, and other applications.GitLabCVE-2021-22205: GitLab remote code execution vulnerability.GNU BashCVE-2014-6278: GNU Bash (Shellshock) remote code execution vulnerability.ISC BINDCVE-2015-5477: ISC BIND denial-of-service vulnerability.JenkinsThese scripts targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, Jenkins, and other applications.Microsoft Exchange ServerThe attackers also used the open-source EBurst tool to conduct password-spraying attacks against Microsoft Exchange servers, along with other tools to steal emails, collect Active Directory credentials, and exfiltrateONLYOFFICE DocumentServerCVE-2021-3199: ONLYOFFICE DocumentServer unauthorized file write vulnerability.Oracle WebLogicThese scripts targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, Jenkins, and other applications.ProFTPDCVE-2015-3306: ProFTPD unauthorized file read vulnerability.Pulse Secure VPNCVE-2019-11510: Pulse Secure VPN arbitrary file read vulnerability.SoftEther VPNA seventh seized domain, 98aiblog.com, was tied to the SoftEther VPN software installed on compromised systems to maintain remote access to victim networks.StrapiCVE-2023-22894: Strapi information disclosure vulnerability.WordPressThese scripts targeted widely used software, including Oracle WebLogic, Apache Struts, WordPress, Jenkins, and other applications.
Tools
EBurstThe attackers also used the open-source EBurst tool to conduct password-spraying attacks against Microsoft Exchange servers, along with other tools to steal emails, collect Active Directory credentials, and exfiltrateFishHubby Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide.MicroScandomains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide.
Countries
ChinaThe seizures targeted infrastructure supporting the two hacking platforms allegedly operated by China-based Integrity Technology Group (Integrity Tech), which U.S.JapanThese targets include a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and electricity companies, and universities.PolandThese targets include a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and electricity companies, and universities.TaiwanAccording to the FBI seizure affidavit, investigators found data and files belonging to more than 20 organizations on a server linked to the FishHub data-theft tool, including six universities in Taiwan.United StatesDepartment of Justice, the tools were used to scan for vulnerabilities and breach critical infrastructure networks in the United States and other countries.
Industries
Critical infrastructureFBI disrupts Chinese hacking tools used to breach critical infrastructurecritical manufacturinggovernment agencies, critical manufacturing, healthcare, information technology, law enforcement, educational institutions, and religious organizations, as well as organizations in Southeast Asia, Africa, and Northeducational institutionsgovernment agencies, critical manufacturing, healthcare, information technology, law enforcement, educational institutions, and religious organizations, as well as organizations in Southeast Asia, Africa, and NorthHealthcaregovernment agencies, critical manufacturing, healthcare, information technology, law enforcement, educational institutions, and religious organizations, as well as organizations in Southeast Asia, Africa, and NorthInformation Technologygovernment agencies, critical manufacturing, healthcare, information technology, law enforcement, educational institutions, and religious organizations, as well as organizations in Southeast Asia, Africa, and NorthLaw enforcementThe FBI seized the c0cc.cc domain used by Integrity Tech to access the MicroScan platform, which law enforcement confirmed was online in September 2026.religious organizationshealthcare, information technology, law enforcement, educational institutions, and religious organizations, as well as organizations in Southeast Asia, Africa, and North America.