Flax Typhoon, the China-linked hacking cluster, lost two tools on Thursday when the Justice Department and FBI seized the domains that ran them. The tools, Microscan and FishHub, handled vulnerability scanning and spear phishing, and prosecutors tie both to a Chinese contractor that built them for clients.
Per the Justice Department, court documents unsealed in the Western District of Pennsylvania allege that Integrity Technology Group operated both tools. The company is based in the People's Republic of China and holds contracts with the Chinese government, and the department describes the Flax Typhoon actors as associated with it. Microscan ran through a botnet of internet-of-things devices infected with a Mirai variant, and Integrity Tech reached it through the seized domain c0cc[.]cc. The department says the tool existed to map victim networks for weaknesses that clients would exploit later.
The scanning hit a wide mix of targets. Flax Typhoon's Microscan activity included a South Carolina power company, a multinational nongovernmental organization, airports in Japan and Poland, Taiwanese natural gas and power companies, and two Taiwanese universities. Scanning alone is not a break-in, but the department says the tools were used to scan and, in some cases, to hack.
FishHub worked further down the attack chain. After an initial compromise, it pulled additional malware onto the victim network. That malware either gave clients remote access or searched for specific files and sent them to servers Integrity Tech controlled. Confirmed FishHub victims include about 20 Taiwanese universities. Five of the seized domains helped deliver the malware: 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com and linkedinns[.]net. Three of those names borrow from familiar services, the kind of lookalike that makes a phishing message harder to spot.
It is the second public technical disruption of Integrity Tech's infrastructure, and the second blow to the company behind Flax Typhoon's tooling. In September 2024 the department announced a court-authorized takedown of the company's Mirai botnet, which spanned more than 200,000 consumer devices. FBI Cyber Division Assistant Director Brett Leatherman said the PRC leans on contractors to widen the reach of its cyber operations, and that exposing them makes American networks harder to target. Two seizures in two years against the same company suggest that takedowns raise the cost of rebuilding more than they end the operation.
Alongside the seizures, the FBI and partner agencies in the US and abroad published a cybersecurity advisory with indicators of compromise tied to Integrity Tech intrusion activity. The department says the advisory is meant to help network defenders identify and respond to that activity in their own environments, and its indicators are the quickest thing for a security team to check logs against.












