Microscan and FishHub: the tools FBI says China used to scan US networks
The FBI and DOJ seized seven domains for Microscan and FishHub, alleging a China-based contractor supplied tooling to state-linked hacking.
The Justice Department and FBI announced court-authorized seizures of seven domains used to operate two intrusion tools, Microscan and FishHub, in an operation aimed at denying access to the infrastructure behind a China-linked hacking campaign. The announcement came October 8.
Microscan handled vulnerability scanning. FishHub supported spear-phishing operations, according to the Justice Department. Court documents unsealed in the Western District of Pennsylvania allege that cyber actors working for Integrity Technology Group, a China-based company holding contracts with the PRC government, operated and used the tools as part of activity the private sector tracks as Flax Typhoon.
Prosecutors say Integrity Tech built a botnet of internet-of-things devices infected with a variant of Mirai malware, and that the botnet helped the company scan for vulnerabilities with Microscan. The tools were used to scan and, in some cases, compromise U.S. and foreign critical infrastructure systems and other networks. The seizures were carried out to prevent those behind the activity from continuing to use the tools and related internet domains.
Brett Leatherman, Assistant Director of the FBI's Cyber Division, said disrupting enablers makes it harder for the PRC to target American networks and infrastructure. "The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity," he said.
The operation's significance lies less in one hacking group than in the layer beneath it. If the allegations hold, the case describes a contractor model: a company with government contracts allegedly supplying scanning and phishing tooling that lets state-linked campaigns operate at scale. Disrupting that layer could complicate similar campaigns, though the seizures do not by themselves dismantle Flax Typhoon or Integrity Tech, and it is not clear whether equivalent capabilities can be rebuilt.
Open questions remain.
What Defenders Should Do
- Inventory internet-facing systems and prioritize patching known exploited vulnerabilities; scanning tools like Microscan exist to find unpatched exposure first. - Harden IoT and edge devices: change default credentials, disable unnecessary services, segment networks, and monitor for Mirai-family behavior such as rapid outbound scanning and telnet/SSH brute forcing. - Treat spear-phishing as a primary initial-access vector. Enforce phishing-resistant MFA, filter inbound mail, and train staff to report suspicious messages. - Hunt for indicators tied to Flax Typhoon and Mirai variants, and review logs for anomalous scanning activity originating from internal devices. - Monitor domain and infrastructure takedowns for threat-actor adaptation; assume capability can be rebuilt and maintain detection coverage.
Sources
- https://beavercountyradio.com/news/justice-department-and-fbi-seize-vulnerability-scanning-and-spear-phishing-tools-operated-and-used-by-china-state-sponsored-hackers/ - https://hackread.com/fbi-seizes-flax-typhoon-hacking-tools-china/ - https://www.itpro.com/security/cyber-crime/us-seizes-vulnerability-scanning-and-spear-phishing-tools-used-by-china-sponsored-hackers - https://www.helpnetsecurity.com/2026/10/09/fbi-flax-typhoon-microscan-fishhub-domains/ - https://www.legalreader.com/federal-agencies-seize-china-based-hacking-tools/
Continue reading
More in this thread
Seven nations say Integrity Tech hacking is ongoing, but advisory gives no breach count
Peter Olaleru
Banks face two clocks on AI: NCSC oversight guidance and ECB's October demand
Peter Olaleru
FBI Removes Contractor After Patch Failure Exposes Employee Data
Peter Olaleru
Conversation
Reader notes
Loading comments...