FBI Disrupts Chinese Hacking Tools Used to Breach Critical Infrastructure Worldwide
The Federal Bureau of Investigation (FBI) has made a significant breakthrough in disrupting two Chinese state-sponsored hacking tools used to breach critical infrastructure and organizations globally. The FBI seized seven domains, including those supporting the MicroScan and FishHub platforms, allegedly operated by China-based Integrity Technology Group (Integrity Tech), which has contracts with the Chinese government.
According to the U.S. Department of Justice, these tools were used to scan for vulnerabilities and breach critical infrastructure networks in the United States and other countries. The FBI’s Cyber Division Assistant Director Brett Leatherman stated that disrupting these organizations makes it harder for China-linked hackers to target American networks, as the Chinese government relies on contractors and other companies to expand the reach of their cyber operations.
MicroScan is a vulnerability-scanning platform developed by Integrity Tech to identify security weaknesses in targeted networks. The platform was used along with a botnet of internet-connected devices infected with Mirai malware to scan potential targets, including a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and electricity companies, and universities. An FBI seizure affidavit confirmed that the scanning activity led to successful breaches at two Taiwanese universities whose networks were scanned using MicroScan in August 2022 and March 2023.
The second platform, FishHub, was used to conduct spear-phishing attacks and deliver additional malware to networks already compromised. This malware gave attackers unauthorized remote access to victims’ networks and allowed them to search for specific files and exfiltrate data to servers controlled by Integrity Tech. The FBI seized five domains used to deliver the malware, including those linked to SoftEther VPN software installed on compromised systems to maintain remote access.
The disruption of these hacking tools has significant implications, as they were used in intrusions involving critical infrastructure worldwide. While the FBI did not disclose whether specifically named power companies, airports, and energy providers were successfully breached, it is clear that the Chinese government-linked hackers targeted a wide range of organizations globally. The joint cybersecurity advisory issued by the FBI, CISA, NSA, and international partners highlights the importance of protecting against these types of attacks.
The seized domains now display FBI seizure notices identifying the Flax Typhoon hacking group and Integrity Technology Group. This disruption demonstrates the ongoing efforts of law enforcement to counter cyber threats from nation-state actors and emphasizes the need for organizations worldwide to prioritize cybersecurity measures to protect themselves against similar attacks.
For readers, this development serves as a reminder that nation-state actors continue to use sophisticated tools to breach critical infrastructure and steal sensitive information. To mitigate these risks, it is essential to implement robust cybersecurity practices, including regular vulnerability scanning, penetration testing, and employee education on phishing attacks. Additionally, staying informed about emerging threats and collaborating with international partners can help organizations stay ahead of cyber adversaries.
Source: Bleeping Computer — 2026-10-08