FBI Seizes Seven Domains Tied to Hacking Tools Targeting Power Companies and Airports
The FBI did not arrest a hacker or shut down a single computer. Instead, federal agents went after the digital doors that investigators say powered a sprawling China-linked cyber operation.
The Justice Department and FBI announced that they had seized seven internet domains associated with two hacking tools known as Microscan and FishHub. According to court documents, the tools were operated by people connected to Beijing-based Integrity Technology Group and were used to scan, phish and, in some cases, break into critical infrastructure and other networks in the United States and abroad.
The seizure is the second public U.S. disruption of Integrity Tech’s infrastructure in two years. It also offers a rare look at how investigators can interrupt a cyber campaign without physically reaching the people accused of running it.
What the FBI took offline
The court-authorized operation targeted domains that provided access to Microscan, FishHub and related remote-administration infrastructure. The Associated Press reported that the action rendered the two tools inoperable, although investigators expect to watch for attempts to rebuild the network.
Microscan is described in a joint cybersecurity advisory as a Python-based application containing more than 1,300 scripts designed to search websites and internet-facing systems for known weaknesses. Investigators say the tool helped operators identify vulnerable targets before those weaknesses were exploited.
FishHub allegedly played a different role. After an initial compromise—often involving spear phishing—it could deliver additional malware, give operators remote access to a victim’s network or search for and transmit selected files.
The targets included power systems and airports
The Justice Department said Microscan was used against an unnamed power company in South Carolina, Japanese and Polish airports, Taiwanese natural-gas and electric-power companies, two Taiwanese universities and a multinational nonprofit organization.
Officials also identified about 20 Taiwanese universities as confirmed victims of FishHub activity. A separate FBI-led advisory said the broader campaign targeted U.S. government services, critical manufacturing, health care, information technology, law enforcement, educational institutions and religious organizations.
That does not mean every scanned organization was successfully breached. Cyber actors routinely scan large numbers of internet-connected systems looking for an opening. But the government says some of these operations advanced from automated reconnaissance to hands-on exploitation and the theft of emails, credentials and other sensitive data.
Who is Integrity Technology Group?
Integrity Technology Group is a publicly known cybersecurity company based in China. U.S. officials say it has contracts with the Chinese government and provided infrastructure and technical capabilities to China-linked operators associated with the campaign the private sector calls Flax Typhoon.
The new advisory was jointly issued by U.S. agencies and partners in the United Kingdom, Australia, Canada, Japan, New Zealand and Spain. It says the actors combined large botnets, automated scanning, password attacks, malicious scripts and legitimate remote-access software to enter networks and remain difficult to detect.
China’s foreign ministry said Friday that it opposes hacking activity and what it called the ill-intentioned spread of misinformation. Spokesperson Mao Ning said China favors cooperation with the United States to address online risks, Reuters reported.
This is the second disruption in two years
In September 2024, U.S. authorities disrupted an Integrity Tech-linked botnet built from more than 200,000 compromised consumer devices worldwide. The infected equipment included cameras, video recorders and home and office routers that could make malicious activity appear to originate from ordinary internet connections.
The latest action is narrower but potentially immediate: sever access to the domains that kept two operational tools available. It also demonstrates why domains, cloud servers and rented infrastructure have become high-value targets for investigators confronting state-linked cyber campaigns.
What network defenders are being told to do
The joint advisory urges organizations to disable services and internet-facing ports they do not need, promptly patch known vulnerabilities, sanitize inputs on web applications and require multifactor authentication wherever possible.
It also provides technical indicators that cybersecurity teams can use to search their own systems for signs of the campaign. The intended audience includes government agencies and organizations in critical manufacturing, health care and information technology.
For ordinary consumers, the announcement is not evidence that every router, camera or email account has been compromised. It is a reminder, however, that unpatched internet-connected devices can become part of a much larger operation without their owners realizing it.
The disruption is significant—but not necessarily permanent
Taking seven domains offline can break active connections and deny operators access to important tools. It does not erase the knowledge, personnel or code behind the campaign.
That is why officials characterized the seizure as a disruption rather than a final defeat. The immediate network may be down, but the longer contest is likely to continue through rebuilt infrastructure, new domains and another round of detection.
Sources
- U.S. Justice Department: Seven-domain seizure and alleged targets
- Associated Press: FBI seizure of Microscan and FishHub
- Reuters: U.S. disruption and China’s response
- Joint cybersecurity advisory: Technical findings and mitigation guidance