The United States Department of Justice (DOJ) and the Federal Bureau of Investigation (FBI) announced on Thursday, October 8th, that they have seized a batch of hacking tools and related domain names. Court documents indicate that the hacker groups using these tools are associated with the Chinese Communist Party (CCP).
According to the announcement posted on the DOJ’s official website on Thursday, the DOJ and FBI have seized two tools, “Microscan” and “FishHub,” authorized by the court to prevent hackers from using them for widespread scanning of targets, carrying out phishing attacks, and infiltrating critical infrastructure systems and other networks in the United States and other countries.
The FBI has seized seven website domain names related to these hacking tools, disabling their operation.
The announcement cited court documents unsealed by the U.S. District Court for the Western District of Pennsylvania, revealing that network operatives working for the Chinese government operated and utilized these tools. These individuals are affiliated with Integrity Technology Group, also known as “永信至誠科技集團” based in Beijing, a cybersecurity company listed on the Shanghai Stock Exchange’s Sci-Tech Innovation Board. Official investigations by the U.S., UK, and EU have identified this company as a contracted vendor to CCP government departments such as the Ministry of State Security and Public Security Bureau, and the real entity behind the state-sponsored hacker group “Flax Typhoon.”
The court documents allege that Integrity Technology Group developed the Microscan tool and related botnet networks, and operated the integrated phishing attack management system FishHub. FishHub facilitates the download of more malicious software onto victims’ networks targeted by phishing attacks, stealing sensitive data.
Of the seven seized domain names, five were still distributing the FishHub malware as of March this year, infecting around 20 Taiwanese universities.
According to court documents, hackers used Microscan to scan multiple networks on April 26 and around December 29, 2022. Targets included a power company in South Carolina, a multinational non-governmental organization, airports in Japan and Poland, and at least two natural gas and electricity critical infrastructure enterprises in Taiwan.
The documents also mention that a university in Hsinchu, Taiwan, was breached in March 2023, and another university in Puli Town, Taiwan, was breached in August 2022, both previously scanned by Microscan.
FBI Assistant Director of the Cyber Division Brett Leatherman stated in the announcement that the CCP government has been relying on contractors and related enterprises to expand the scope and scale of malicious cyber activities, and exposing and disrupting the operations of these collaborators helps increase the difficulty of CCP hackers attacking U.S. networks and infrastructure.
In September 2024, the FBI announced the dismantling of a botnet network associated with the “Flax Typhoon” hacking group, which infected over 200,000 consumer devices such as cameras and routers.
Government agencies in the U.S., UK, Australia, Canada, Japan, New Zealand, and Spain subsequently issued security advisories, warning that network attackers connected to the CCP were using botnet networks, malware, and other intrusion tools to target global institutions and organizations, stealing sensitive data, including critical infrastructure networks in the U.S.
The FBI previously disclosed that after multiple countries issued warnings, Integrity Technology Group and Flax Typhoon voluntarily shut down their network with 260,000 devices. However, this year, private security researchers and Western governments have warned that Chinese hackers are still turning compromised routers and IoT devices into botnet networks.
