FBI takes down domains powering Chinese hacking platforms MicroScan and FishHub

The FBI has seized seven domains linked to Chinese state-sponsored hackers known as Flax Typhoon and to Integrity Technology Group. Authorities say the MicroScan and FishHub platforms were used for vulnerability scanning, intrusions, and spear-phishing against critical infrastructure and other targets worldwide. An affidavit tied MicroScan to a Mirai-infected botnet and to later breaches at two Taiwanese universities.
The FBI took seven domains tied to Integrity Technology Group, a China-based contractor U.S. officials link to state cyber operations. Two platforms, MicroScan and FishHub, allegedly supported scanning, intrusions, and spear-phishing. MicroScan reportedly worked with a Mirai-infected device botnet; scans preceded breaches at two Taiwanese universities. FishHub allegedly enabled remote access, file searches, and data theft, with files from over 20 organizations found on a related server.
A joint advisory from FBI, CISA, NSA and partners described targeting of government, manufacturing, healthcare, IT, law enforcement, education, religious groups, and organizations across several regions. Seized domains now show notices naming Flax Typhoon and Integrity Tech.
The seizures may disrupt one set of tools, but they might not eliminate broader cyber threats. Organizations in critical infrastructure, education, healthcare, and government could still face scanning and phishing attempts, potentially leading to data theft or service disruptions. The advisory may help defenders prioritize patches and monitoring. Public trust could be affected if breaches continue, while international cooperation may shape future responses.