US takes down domains tied to Chinese hacking contractor
The Justice Department and FBI seized six domains linked to China-based Integrity Technology Group, which officials say supports hacking operations. The domains involved Microscan, a network scanning tool, and FishHub, which was used for deceptive emails and malware delivery. CISA and international partners warned that the contractor aids China-linked hackers targeting critical infrastructure and sectors including government, healthcare and education.
U.S. authorities obtained court approval to take over six domains connected to Integrity Technology Group, a China-based contractor. The sites supported Microscan, which probed networks for vulnerabilities, and FishHub, which enabled deceptive emails and malware distribution. Officials linked the tools to intrusions affecting government, manufacturing, health care, law enforcement and education organizations.
The operation followed earlier U.S. actions against the same company, including a 2024 botnet disruption involving over 200,000 infected consumer devices and 2025 sanctions. Investigators said hacked devices helped Microscan scan targets such as a South Carolina utility, Japanese and Polish airports, Taiwanese energy firms and universities, and an international nonprofit.
The seizures may modestly raise costs for the contractor’s clients by removing tools used for scanning and follow-on access. Organizations in government, health care, education and critical infrastructure could still face heightened risk if similar services persist. Security teams may gain useful warning from the advisory, while affected Taiwanese universities and utilities could see renewed scrutiny. The broader public may benefit indirectly if disruption reduces intrusions, though the long-term effect remains uncertain.