Security
The FBI Seized Flax Typhoon's Tools for the Second Time in Two Years. The CVE List Is the Part Defenders Should Read
The Justice Department seized the domains behind Microscan and FishHub, two tools it says Integrity Technology Group operated for China-linked hackers who scanned a US power company, Japanese and Polish airports, and Taiwanese energy firms. The accompanying seven-nation advisory shows the platform ran almost entirely on vulnerabilities patched years ago.
MAI
On 8 October the Justice Department announced court-authorised seizures of the domains behind two hacking tools, Microscan and FishHub, which it says were operated by people working for Integrity Technology Group — a company based in the People's Republic of China that holds contracts with the PRC government, and the corporate identity behind the group Microsoft named Flax Typhoon. Court documents were unsealed in the Western District of Pennsylvania. Seven domains now serve FBI seizure notices instead of malware.
It is the second time the same company's infrastructure has been taken apart by the same government in two years. Troy Rivetti, US Attorney for the Western District of Pennsylvania, called it the "second disruption of Integrity Tech's massive operations in as many years." In September 2024 the Justice Department disrupted the company's Mirai botnet of more than 200,000 consumer devices. The United Kingdom sanctioned Integrity Tech in 2025 and the European Union followed in 2026. The company is still operating.
What the two tools did
Microscan was a vulnerability scanner — Python-based, carrying more than 1,300 penetration-testing scripts, in service since 2017. Its distinguishing feature was not sophistication but laundering: a substantial part of the scanning ran across a botnet of internet-of-things devices infected with a Mirai variant, so the traffic arrived at victims from consumer hardware rather than from Integrity Tech's own address space. Clients received the results and chose what to do with them.
The named targets read as a summary of what China's cyber programme has been interested in: a power company in South Carolina, airports in Japan and Poland, natural gas and electricity companies in Taiwan, a multinational non-governmental organisation, and Taiwanese universities. Two of those universities were scanned in August 2022 and March 2023 and were later breached. The FBI has not said whether the power company or the airports were.
FishHub handled the next stage — spear-phishing, and the delivery of further malware once a network was compromised, giving clients remote access and the ability to search for and remove specific files to servers Integrity Tech controlled. Roughly 20 Taiwanese universities are confirmed victims. A third tool, the open-source EBurst, was used to spray passwords at Microsoft Exchange accounts.
John A. Eisenberg, the Assistant Attorney General for National Security, said the United States "will not allow China or its proxies to operate against United States interests with impunity in cyberspace."
The advisory is the more useful document
Alongside the seizures, the FBI, CISA and the NSA published a joint advisory with partner agencies in Australia, Canada, Japan, New Zealand, Spain and the United Kingdom. It runs to 58 pages and covers roughly six years of activity drawn from FBI incident response work.
Three findings in it matter more than the takedown. The operators concentrated on edge devices that organisations do not closely monitor, which is how access measured in years rather than weeks becomes possible. Email taken from government, law enforcement, healthcare and religious organisations across Southeast Asia sat on servers where, in some cases, access was restricted to IP addresses in Xiamen. And then there is the vulnerability list, which is the part a defender should actually read.
| CVE | Affected software | Published |
|---|---|---|
| CVE-2014-6278 | GNU Bash (Shellshock) | 2014 |
| CVE-2015-3306 | ProFTPD | 2015 |
| CVE-2015-5477 | ISC BIND | 2015 |
| CVE-2016-3081 | Apache Struts | 2016 |
| CVE-2019-11510 | Pulse Secure VPN | 2019 |
| CVE-2021-3199 | ONLYOFFICE DocumentServer | 2021 |
| CVE-2021-22205 | GitLab | 2021 |
| CVE-2023-22894 | Strapi | 2023 |
The newest entry is three years old. The oldest is Shellshock, which was patched in 2014. Every one of these has had a fix available for years. A scanning platform worth two federal disruption operations was built almost entirely on vulnerabilities that nobody got around to patching, on equipment that nobody was watching.
What a seizure removes, and what it does not
The seizures work because the domains were hard-coded into the tools for communication and authentication, so removing them makes the tools inoperable. Jason Bilnoski, deputy assistant director of the FBI's Cyber Division, described the logic plainly:
We aim to remove the capability from the threat actors. We target their infrastructure, their money, and their tools. — Jason Bilnoski, FBI Cyber Division
What the operation does not do is touch the contractor. Integrity Tech is in China, beyond the reach of a Pennsylvania warrant, and registering replacement domains is among the cheapest things in this business. Brett Lally, a supervisory special agent in the FBI's San Diego office, said the bureau will be watching for signs of reconstitution. On the evidence of 2024, it will find them.
That leaves the durable half of the response on the defender's side rather than the prosecutor's. Brett Leatherman, assistant director of the FBI's Cyber Division, framed the strategic point: "The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity." Those companies scale by automating the cheapest available attack against the largest available number of unmaintained internet-facing systems. A seizure removes one vendor's tooling for a while. Patching removes the market.
What to do
Read the joint advisory at ic3.gov and check your logs against its indicators of compromise. Patch the CVEs above on anything internet-facing, with priority on VPN and file-transfer appliances. Turn off exposed services that do not need to be exposed, and enforce multifactor authentication on remote access and mail. Paul Chichester of the UK's National Cyber Security Centre put the scope of the problem in one line: the "breadth of sectors that have been targeted across the globe demonstrate the extent of the threat."
Sources: Justice Department press release 26-1155 · The Record: International coalition seizes tools used by cyber firm behind Flax Typhoon · BleepingComputer: FBI disrupts Chinese hacking tools used to breach critical infrastructure · Fortune / AP: FBI says it seized phishing tools used by Chinese hackers · CyberScoop: DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub