US Disrupts Chinese State-Sponsored Hacking Tools

The US has disrupted two sophisticated hacking tools used by Chinese state-sponsored threat actors to launch attacks against critical infrastructure and organizations in the US and abroad. The operation, announced on Thursday, targets MicroScan and FishHub, which were developed by Integrity Technology Group (Integrity Tech) to facilitate network intrusions and data exfiltration.

MicroScan is a Python-based web application that contains over 1,300 penetration testing scripts designed to scan websites for specific vulnerabilities. This tool has been active since at least 2017 and was mainly associated with the activity of Flax Typhoon, also known as Ethereal Panda, Red Juliett, Storm-0919, and UNC5007. However, Integrity Tech is believed to have worked with other Chinese Advanced Persistent Threats (APTs) as well.

FishHub enabled Integrity Tech’s clients to access victim networks remotely, search for specific files, and exfiltrate them. This tool has been used in attacks against at least 20 universities in Taiwan. The US seized the domains that the threat actors were using to access MicroScan and FishHub, including c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net.

The disruption of these hacking tools is a significant development in the ongoing efforts to combat Chinese state-sponsored cyber threats. The US has previously disrupted Integrity Tech’s Raptor Train botnet in 2024 and sanctioned the company for providing cybersecurity products to Chinese APTs like Flax Typhoon in 2025. The European Union also sanctioned Integrity Tech in March 2026.

The joint advisory from government agencies in the US, UK, Australia, Canada, Japan, New Zealand, and Spain provides further insight into the tools used by these threat actors. MicroScan contains a range of scripts designed to scan websites for vulnerabilities, including those in Apache Struts, Juniper ScreenOS, Jenkins, OpenSSL, Oracle, Rejetto HFS, WebLogic Server, WordPress, and other services.

The threat actors also deployed VPN tools such as SoftEther for persistence and downloaded databases or manually extracted data from victims’ email addresses. They used the PHP script Curlc4.txt and command-line utility office-cli for email exfiltration, and DC.ex to extract sensitive data from Active Directory.

This operation highlights the importance of international cooperation in combating cyber threats. The disruption of MicroScan and FishHub demonstrates that even sophisticated hacking tools can be brought down with the right combination of technical expertise and law enforcement action. As a result, organizations should remain vigilant against these types of attacks and ensure they have robust security measures in place to prevent network intrusions and data exfiltration.

In practical terms, organizations should prioritize regular vulnerability scanning and patching, implement robust access controls and monitoring, and educate employees on spear phishing tactics. By taking these steps, organizations can reduce their risk exposure to these types of attacks and stay ahead of the threat actors.


Source: SecurityWeek — 2026-10-09