The US Justice Department and FBI on Thursday seized two hacking tools — called "Microscan" and "FishHub" — that officials say were operated by a China-based government contractor and used by Beijing-backed hackers to scan, phish, and hack critical infrastructure in the United States and abroad. Court-authorized seizures of six internet domains, announced alongside a multinational cybersecurity advisory, mark the second disruption of the contractor's operations in two years and the latest blow in Washington's long-running campaign against Chinese state-sponsored cyber espionage.

The tools were run by Integrity Technology Group — known as Integrity Tech — a company based in the People's Republic of China that holds contracts with the Chinese government, according to court documents unsealed in the Western District of Pennsylvania, as announced by the US Department of Justice.

Table of contents

  1. What was seized — and what the tools did
  2. The targets: power grids, airports, universities
  3. The company behind the tools
  4. A multinational warning, and five new CVEs
  5. The "Flax Typhoon" context
  6. What happens next
  7. Key takeaways
  8. Frequently Asked Questions
  9. Sources
  10. Read more on Chronicle

What was seized — and what the tools did

The seizure targeted two distinct tools with complementary roles in a hacker's toolkit. Microscan was a network-scanning platform: it probed networks for security weaknesses that hackers could exploit, powered by a network of hacked internet-connected devices — a botnet — that helped it scan targets at scale. FishHub, by contrast, was built for deception: it supported spear-phishing emails and delivered malicious software designed to steal files or give attackers remote control of infected systems, according to the Justice Department.

With the domains seized, the operation rendered both tools inoperable, stripping the hackers of their scanning and phishing infrastructure in a single stroke. "The United States will not allow China or its proxies to operate against United States interests with impunity in cyberspace," said John A. Eisenberg, the Assistant Attorney General for National Security.

The targets: power grids, airports, universities

The list of scanned targets reads like a map of what governments consider worth protecting most. Microscan was used against an unnamed power company in the United States — court documents separately identify a South Carolina power company among the scanned targets — as well as airports in Japan and Poland, Taiwanese universities, Taiwanese natural-gas and power companies, and a multinational non-governmental organization, the FBI said.

Officials were careful to note that being scanned does not necessarily mean a target was successfully breached. But reconnaissance of this kind is often the opening move of a longer intrusion campaign: once hackers know where the weaknesses are, they can return later to exploit them. FishHub, meanwhile, facilitated phishing activity that in some cases gave the hackers remote access to victim networks, according to Nextgov's reporting on the case.

The company behind the tools

At the center of the operation sits Integrity Technology Group, a China-based company that US officials describe as a contractor and enabler for the Chinese state's hacking campaigns. The company has contracts with the Chinese government, and its hackers are believed to have worked at its direction, according to the unsealed court documents.

"The [People's Republic of China] relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity," said FBI Cyber Division Assistant Director Brett Leatherman. "By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure."

FBI Cyber Division Deputy Assistant Director Jason Bilnoski, in an interview with the Associated Press, called the campaign "indiscriminate and reckless." "We aim to remove the capability from the threat actors. We target their infrastructure, their money, and their tools," he said.

A multinational warning, and five new CVEs

The seizures were paired with a joint cybersecurity advisory from the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency, and partner agencies in the United Kingdom, Australia, Canada, Japan, New Zealand, and Spain. The advisory warns that Integrity Tech supplies tools and technical support to China-linked hackers targeting government, manufacturing, healthcare, law enforcement, and education organizations worldwide.

The advisory details an aggressive tradecraft toolkit: scanning tools, cross-site scripting attacks, password spraying against Microsoft Exchange servers, persistence through VPN software, and the exfiltration of emails and credentials via scripts, as reported by The Register. To stay hidden, the hackers renamed VPN installers to look like ordinary Windows files and, in some cases, routed stolen data only to IP addresses in Xiamen, China.

Based on the documented activity, CISA added five vulnerabilities to its Known Exploited Vulnerabilities Catalog — a signal to federal agencies and private companies alike that these flaws are actively being abused and must be patched.

The "Flax Typhoon" context

In the cybersecurity industry, the hacking campaign behind these tools is known as Flax Typhoon — a broad-based, state-linked operation that US officials have been working to disrupt for years. This week's action is, in the words of US Attorney Troy Rivetti, "our second disruption of Integrity Tech's massive operations in as many years."

The case follows an established US playbook: rather than waiting to attribute attacks after the damage is done, law enforcement is increasingly going after the infrastructure itself — botnets, domains, and tooling — to raise the cost of state-sponsored hacking. A similar operation in August 2026 disrupted tools called QScan and QTRouter run by a different Chinese-linked group that had targeted critical infrastructure and federal systems.

What happens next

The seized domains are now offline, and the tools are inoperable — but history suggests the campaign will adapt. State-sponsored hacking groups routinely rebuild infrastructure after takedowns, and the multinational advisory is as much a warning of that reality as it is a victory lap. The practical upshot for defenders: patch the newly listed vulnerabilities, harden Exchange servers, and treat any scanning from Integrity Tech-linked infrastructure as hostile reconnaissance.

For Washington, the message was political as well as technical. The operation landed amid a broader US crackdown on Chinese cyber activity and a tense trade and security relationship — a reminder that cyberspace remains one of the most active theaters of great-power competition.

Key takeaways

  • The DOJ and FBI seized domains behind two hacker tools, "Microscan" and "FishHub," used by Beijing-backed hackers to scan and phish critical infrastructure.
  • The tools were operated by Integrity Technology Group, a China-based company with PRC government contracts; the campaign is known to industry as Flax Typhoon.
  • Targets included a US power company, Japanese and Polish airports, Taiwanese universities, and critical infrastructure companies.
  • A joint advisory from the US, UK, Australia, Canada, Japan, New Zealand, and Spain warns the company enables China-linked hacking worldwide.
  • CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog.

Frequently Asked Questions

What are Microscan and FishHub?

Microscan was a network-scanning tool that searched networks for security weaknesses, supported by a botnet of hacked internet-connected devices. FishHub supported spear-phishing emails and delivered malicious software that could steal files or remotely control infected systems, according to the Justice Department.

What is Integrity Technology Group?

Integrity Technology Group (Integrity Tech) is a China-based company with contracts with the Chinese government. US officials say it operated the tools and supplied technical support to China-linked hackers targeting critical infrastructure worldwide. This is the second US disruption of its operations in two years.

What is Flax Typhoon?

Flax Typhoon is the name the cybersecurity industry uses for the broad-based, China-linked hacking campaign behind tools like Microscan and FishHub. US officials describe it as a state-sponsored effort targeting critical infrastructure, government, healthcare, and education networks in the US and allied countries.

Were any of the targets actually hacked?

Officials said the tools scanned targets including a US power company, Japanese and Polish airports, and Taiwanese infrastructure, but being scanned does not necessarily mean a network was successfully breached. The reconnaissance can, however, help intruders identify weaknesses to exploit later.

What should organizations do now?

CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog, so patching is the immediate priority. The multinational advisory also recommends hardening Microsoft Exchange servers, monitoring for unauthorized VPN and proxy traffic, and treating scans from Integrity Tech-linked infrastructure as hostile.

Sources

Read more on Chronicle