Back to Feed
Nation-stateOct 9, 2026

US Disrupts Chinese State-Sponsored Hacking Tools

US disrupts Chinese state-sponsored hacking tools MicroScan and FishHub.

Summary

The US has disrupted two Chinese state-sponsored hacking tools, MicroScan and FishHub, used by Integrity Technology Group for attacks on critical infrastructure. MicroScan, a vulnerability scanner built using a Mirai botnet variant, and FishHub, used for network intrusions via spear phishing, targeted entities in the US, Taiwan, Japan, and Poland. The US seized domains associated with these tools, and both the US and EU have previously sanctioned Integrity Tech.

Full text

The United States on Thursday announced the disruption of two hacking tools used by Chinese state-sponsored threat actors in attacks against US and foreign critical infrastructure. Built by Integrity Technology Group (Integrity Tech), MicroScan has been used for vulnerability scanning, while FishHub has enabled network intrusions via spear phishing. Integrity Tech, the US says, used a Mirai malware variant to build an IoT botnet that facilitated MicroScan’s use for reconnaissance against victims’ networks, including a US power company, NGOs, Japanese and Polish airports, and Taiwanese critical infrastructure entities and universities. FishHub enabled Integrity Tech’s clients to access victim networks remotely, search for specific files, and exfiltrate them. The tool has been used in attacks against at least 20 universities in Taiwan. The US seized the domains the threat actors were using to access MicroScan and FishHub, including c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net. In 2024, the US disrupted Integrity Tech’s Raptor Train botnet, and in 2025 sanctioned it for providing cybersecurity products to Chinese state-sponsored APTs such as Flax Typhoon. The European Union sanctioned the company in March 2026.Advertisement. Scroll to continue reading. A new joint advisory (PDF) from government agencies in the US, UK, Australia, Canada, Japan, New Zealand, and Spain shows that MicroScan has been active since at least 2017, targeting Apache Struts, Juniper ScreenOS, Jenkins, OpenSSL, Oracle, Rejetto HFS, WebLogic Server, WordPress, and other services. “This Python-based web application contains over 1,300 penetration testing scripts written to scan websites for specific vulnerabilities,” the advisory reads. The tool was mainly associated with Flax Typhoon (also known as Ethereal Panda, Red Juliett, Storm-0919, and UNC5007) activity, but Integrity Tech is believed to have been working with other Chinese APTs as well. Flax Typhoon was also seen using BBScan, dirsearch, Fscan, ksubdomain, masscan, Nmap, OneForAll, ShuiZe, and WPScan for reconnaissance, and command-line exploit utilities and the EBurst Microsoft Exchange password spraying tool for initial access. The threat actors deployed VPN tools such as SoftEther for persistence and downloaded databases or manually extracted data from victims’ email addresses. They also used the PHP script Curlc4.txt and command-line utility office-cli for email exfiltration, and DC.ex to extract sensitive data from Active Directory. “The threat actors collect account credentials and exfiltrate victim email data from on-premises systems and cloud-based services. Observed victims of email data theft included government organizations, law enforcement agencies, healthcare systems, and religious institutions located in Southeast Asia. In some instances, the threat actors restricted access to the exfiltrated data to only IP addresses from Xiamen, China,” the advisory reads. Related: US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward Related: Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire SonicWall and Splunk Patch Critical VulnerabilitiesRein Security Raises $25 Million to Guard AI Agents at RuntimeFake Decryption Tools Masked $11M Markup in Ransomware Recovery SchemeFortiBleed Attackers Locking Victims Out of Fortinet DevicesQilin Ransomware Suspect Arrested in Japan, Extradited to GermanyChrome 155 Update Patches 247 VulnerabilitiesASOS Confirms Cyberattack, Data BreachAndroid’s October 2026 Updates Patch 25 Vulnerabilities Latest News Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT SecurityCitrix Urges Immediate Patching of Critical NetScaler VulnerabilityGoogle Pixel 10 Exploits Earned Hackers $560,000 at Pwn2OwnFormula Predicts When AI Chatbots Are at Risk of Turning BadCisco Patches a Dozen Critical VulnerabilitiesSecurity Awareness Training Isn’t Dead, but It Needs a RethinkAttackers Target Critical Atlassian Vulnerability Within Hours of PoC PublicationUS Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveRapid7 has named Rik Ferguson as VP of Security Intelligence.Cytactic has appointed Tim Brown as CSO.Scott Simkin has joined Vega as CMO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • domain — c0cc[.]cc
  • domain — 98aicai[.]com
  • domain — 98aicode[.]com
  • domain — outlook3650[.]com
  • domain — youtubecard[.]com
  • domain — linkedinns[.]net

Entities

Flax Typhoon (threat_actor)Integrity Technology Group (vendor)MicroScan (product)FishHub (product)Ethereal Panda (threat_actor)