IC Technology & Cyber — 2026-10-10

DOJ and FBI Seize Flax Typhoon Hacking Tools as CISA NSA Issue Joint Advisory on Chinese Government-Linked Cyber Threats

BLUFSeizing seven domains disrupts but does not dismantle Flax Typhoon's infrastructure, and Microscan's broad vulnerability coverage means unpatched critical infrastructure operators face continued targeting on rebuilt tooling.

The Justice Department and FBI announced court-authorized seizures of seven domains, unsealed in the Western District of Pennsylvania on Thursday, to deny access to the Microscan scanning tool and the FishHub spear phishing tool 1. DOJ states that Integrity Technology Group, a PRC company with government contracts, operated both tools as part of Flax Typhoon activity 1. Microscan targets included a South Carolina power company, Japanese and Polish airports, and Taiwanese gas and power firms 12, while FishHub's confirmed victims included about 20 Taiwanese universities 1. ITPro reported Microscan holds over 1,300 vulnerability-scanning scripts 3. The FBI, CISA, and NSA issued a joint advisory with indicators of compromise 12. DOJ described this as its second Integrity Tech disruption after the September 2024 botnet takedown 1.

Analysis
The seizures remove two tools and seven domains but leave the contractor model intact, so Integrity Tech's operators can rebuild scanning and phishing infrastructure on new domains. The joint advisory shifts the burden to defenders, who must hunt the published indicators in Exchange servers, VPN appliances and exposed web applications. Microscan's 1,300-plus scripts cover common enterprise software, so unpatched OpenSSL, WebLogic, WordPress, Jenkins and Struts deployments stay exposed regardless. Targeting of a South Carolina utility and Japanese and Polish airports points to reconnaissance of operational technology beyond Taiwan, which CISA ties to pre-positioning for disruption. Reporting rests on one Justice Department release that trade press repeats. The action may be mainly signaling, since the tools are cheap to replace and operators may hold backup infrastructure.
7 sources
  1. Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools - U.S. Department of Justice (Western District of Pennsylvania)
  2. DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub - CyberScoop
  3. US seizes vulnerability scanning and spear phishing tools used by China-sponsored hackers - ITPro
  4. FBI Seized Vulnerability Scanning and Spear Phishing Tools Used by China-Linked Hackers - Cyber Security News
  5. US Disrupts Chinese State-Sponsored Hacking Tools - SecurityWeek
  6. FBI disrupts Chinese hacking tools used to breach critical infrastructure - BleepingComputer
  7. FBI disrupts Flax Typhoon hacking tools used in global cyberattacks - Help Net Security

View in full brief →

UNCLASSIFIED // OPEN SOURCE