DOJ Seizes Seven Domains Used for Alleged China-Linked Hacking of Critical Infrastructure

·

The Justice Department and FBI said Thursday they had seized seven internet domains used to operate two hacking tools that U.S. authorities allege were deployed by China state-linked actors to scan, phish and in some cases compromise critical infrastructure and other networks in the United States and abroad.

The court-authorized seizures, announced Oct. 8, target domains tied to tools known as “Microscan” and “FishHub.” According to unsealed court filings, Microscan was a web-vulnerability scanning tool allegedly used to identify weak points in victim networks, while FishHub was a spear-phishing tool that authorities say could be used to trick targets into giving access and then pull down additional malware to search for and steal files. The seizure warrant directed Verisign to redirect the domains to FBI-controlled name servers and display an FBI seizure notice — in plain terms, the government took control of the web addresses so the tools would no longer operate from those domains.

The allegations are laid out in filings unsealed in the U.S. District Court for the Western District of Pennsylvania, including a supporting affidavit from FBI Special Agent Adam James. The Justice Department said the domains were used by malicious cyber actors working for Integrity Technology Group, also called Integrity Tech, a company based in the People’s Republic of China. DOJ linked the activity to the threat cluster commonly labeled “Flax Typhoon.” The claims in the affidavit and the department’s statements are allegations by the U.S. government, not adjudicated findings.

According to the affidavit, Microscan scans were at times routed through a Mirai-variant botnet — a network of hacked internet-connected devices — to disguise where the activity came from. FishHub, the affidavit says, could be used after an initial compromise to download more malware and exfiltrate files to servers controlled by Integrity Tech.

The filing ties the tools to a wide set of alleged targets, including a U.S. power company in South Carolina, a multinational nongovernmental organization, airports in Japan and Poland, Taiwanese natural gas and power-sector companies, and multiple universities in Taiwan. The affidavit says that as of March 2026, a FishHub server contained data or files from more than 20 entities, including six universities in Taiwan.

The action matters because the alleged victim set spans critical infrastructure, universities, airports and an NGO — organizations whose disruption or compromise can carry national-security consequences. It also fits into a broader U.S. campaign against infrastructure that authorities attribute to Integrity Tech and Flax Typhoon, rather than a one-day standalone move.

DOJ described Thursday’s seizures as its second public technical disruption of Integrity Tech infrastructure. The first was announced in September 2024, when the department said it disrupted a Mirai-variant botnet attributed to the same actor ecosystem. In a 2024 joint advisory, the FBI, Cyber National Mission Force and National Security Agency said that botnet had more than 260,000 devices as of June 2024.

“Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure,” FBI Cyber Division Assistant Director Brett Leatherman said, according to the DOJ press release.

The FBI’s San Diego and Baltimore field offices are investigating the case, with help from international partners including Japan’s National Police Agency. The Justice Department said the domain seizures were carried out under court authority using federal computer-crime and forfeiture laws.

Tags: #cybersecurity, #china, #fbi, #malware