NEWS

FBI Seizes Seven Domains Behind Flax Typhoon's MicroScan and FishHub Hacking Tools

The FBI seized seven domains used by China-linked Flax Typhoon to run MicroScan and FishHub, tools tied to breaches of global critical infrastructure.

Dylan H.

News Desk

October 9, 2026
7 min read
FBI Seizes Seven Domains Behind Flax Typhoon's MicroScan and FishHub Hacking Tools

FBI Seizes Domains Powering Flax Typhoon's Hacking Platforms

The FBI and Justice Department announced on October 8, 2026 that they had executed a court-authorized seizure of seven domains used by the Chinese state-sponsored hacking group Flax Typhoon to run two attack platforms, MicroScan and FishHub, linked to intrusions against power companies, airports, universities, and other critical infrastructure organizations worldwide. The seizure warrants, unsealed in the Western District of Pennsylvania, identify Integrity Technology Group ("Integrity Tech") — a China-based contractor the United States sanctioned in 2025 — as the operator of both platforms on behalf of China-linked threat actors.


What Happened

Investigators say MicroScan and FishHub were used to scan, breach, and exfiltrate data from victim networks across multiple sectors and continents between at least 2022 and 2026. The seized infrastructure broke down as follows:

DomainRole
c0cc.ccOperator access point for the MicroScan scanning platform
98aicai.comFishHub malware delivery
98aicode.comFishHub malware delivery
outlook3650.comFishHub malware delivery, spoofing Microsoft Outlook
youtubecard.comFishHub malware delivery, spoofing YouTube
linkedinns.netFishHub malware delivery, spoofing LinkedIn
98aiblog.comSoftEther VPN access maintained on breached university networks

Prosecutors say that between April and December 2022, MicroScan was used to scan a South Carolina power company, a multinational non-governmental organization, airports in Japan and Poland, and Taiwanese natural gas and electricity companies. Two Taiwanese universities were scanned in August 2022 and March 2023, respectively, and attackers broke into both networks shortly afterward, later installing SoftEther VPN software — reached through the 98aiblog.com domain — to preserve long-term access. The FBI confirmed the c0cc.cc MicroScan access point was still active as recently as September 2026, shortly before the seizure.

Alongside the seizures, the FBI, CISA, and NSA — joined by international partner agencies — published a joint cybersecurity advisory, AA26-281A, warning that Integrity Tech-enabled actors have been combining automated scanning tools, large-scale botnets, and hands-on exploitation to steal sensitive data from organizations "worldwide, including U.S. critical infrastructure sectors." The advisory also describes a password-spraying tool called EBurst, used against Microsoft Exchange servers, and a custom web application that let third parties browse stolen email archives without needing the victim's own account credentials. The FBI recovered one such archived email database; its victims reportedly included government organizations, law enforcement agencies, healthcare systems, and religious institutions across Southeast Asia.

The Tools: MicroScan and FishHub

MicroScan

MicroScan is described in court filings as a Python-based vulnerability scanner built from more than 1,300 penetration-testing scripts. It was designed to identify weaknesses in internet-facing applications and services — including Oracle WebLogic, Apache Struts, WordPress, and Jenkins deployments — so that Integrity Tech's clients could later exploit them. Investigators tied MicroScan's scanning activity to a Mirai-variant botnet of compromised internet-of-things devices, which the group used to distribute and mask its reconnaissance traffic. The advisory lists several specific, mostly older vulnerabilities MicroScan was built to find, including flaws in ProFTPD (CVE-2015-3306), ISC BIND (CVE-2015-5477), Apache Struts (CVE-2016-3081), ONLYOFFICE (CVE-2021-3199), Strapi (CVE-2023-22894), the Bash "Shellshock" flaw (CVE-2014-6278), Pulse Secure VPN (CVE-2019-11510), and GitLab (CVE-2021-22205) — a reminder that unpatched, years-old CVEs remain productive targets for this actor.

FishHub

FishHub served as Flax Typhoon's spear-phishing and post-compromise platform. According to an FBI agent's seizure warrant affidavit, the tool was "named FishHub because it facilitated phishing activity." Several of its delivery domains — outlook3650.com, youtubecard.com, and linkedinns.net — were built to resemble trusted services like Microsoft Outlook, YouTube, and LinkedIn, making malicious links look familiar enough to draw a click before a target noticed the deception. Once a victim was compromised, FishHub facilitated malware delivery, unauthorized remote access, file searches, and exfiltration of data back to Integrity Tech-controlled servers. Officials said more than 20 organizations' stolen data was recovered directly from the FishHub server.

Who Is Flax Typhoon

Flax Typhoon is the name Microsoft assigned to a China-linked state-sponsored hacking cluster that U.S. officials say operates through Integrity Technology Group, a Beijing-based contractor holding contracts with the Chinese government. This is not the group's first run-in with the FBI: in September 2024, the Justice Department disrupted an Integrity Tech-operated Mirai botnet that had hijacked more than 200,000 consumer devices worldwide — routers, cameras, video recorders, and network-storage devices — marking the first public U.S. disruption of the company's infrastructure. The United States sanctioned Integrity Tech in 2025, and the group has continued to draw international scrutiny since, including sanctions action from the European Union in 2026 over cyberattacks targeting Europe and its allies.

This week's seizure is the second public U.S. disruption of Integrity Tech's operations in roughly two years, and the pattern across both actions is consistent: build or rent large-scale botnet infrastructure, use it to mask and distribute automated scanning, then hand off discovered weaknesses for hands-on exploitation, phishing, and data theft against government, critical infrastructure, and civil-society targets — with a notable concentration of activity against Taiwan.

FBI Cyber Division Assistant Director Brett Leatherman said: "The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure." Assistant Attorney General for National Security John Eisenberg added that the United States would not allow China or its proxies to operate against American interests with impunity in cyberspace. FBI Cyber Division Deputy Assistant Director Jason Bilnoski said the seizure was intended to strip the actors of infrastructure, money, and tools, and that it rendered MicroScan and FishHub inoperable.

Why This Matters for Security Teams

  1. Block and hunt on the seized domains. Check proxy, DNS, and email-gateway logs for historical connections to c0cc.cc, 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, linkedinns.net, and 98aiblog.com. A hit indicates possible exposure even though the domains are now inoperable.
  2. Patch the specific CVEs named in AA26-281A. MicroScan's target list leans on older, well-documented flaws in ProFTPD, ISC BIND, Apache Struts, ONLYOFFICE, Strapi, Bash (Shellshock), Pulse Secure VPN, and GitLab. If any of these remain unpatched on internet-facing systems, prioritize them now — this actor is actively scanning for exactly these weaknesses.
  3. Harden Microsoft Exchange against password spraying. The EBurst tool was used specifically against Exchange authentication. Enforce multi-factor authentication, enable lockout/throttling policies, and review sign-in logs for distributed low-and-slow password-spray patterns.
  4. Train users to spot look-alike login domains. FishHub's delivery infrastructure mimicked Outlook, YouTube, and LinkedIn. Reinforce scrutiny of sender domains and link destinations in phishing awareness training, particularly for lookalikes of common SaaS and webmail brands.
  5. Audit IoT and edge devices for Mirai-variant indicators. Integrity Tech has twice been tied to large consumer-device botnets used to mask scanning traffic. Change default credentials, apply firmware updates, and segment routers, cameras, and NAS devices away from sensitive network segments.
  6. Critical infrastructure and Taiwan-linked organizations should assume historical exposure. Given confirmed scanning and intrusion activity dating back to 2022, organizations in the power, natural gas, airport, and higher-education sectors — especially those with ties to Taiwan — should retroactively review logs and threat-hunt for the IOCs published in AA26-281A.

Sources