www.securityweek.com 9 Oct 2026, 08:36 UTC

US Seizes Domains Used by Chinese Hackers to Scan and Spy on Networks

US Seizes Domains Used by Chinese Hackers to Scan and Spy on Networks

THE United States says it has disrupted two tools built by Chinese firm Integrity Technology Group and used by state-sponsored hacking groups against critical infrastructure. MicroScan was used to scan networks for vulnerabilities; FishHub let users remotely access compromised networks, search for files and steal data. US authorities seized the domains used to reach both tools, including c0cc[.]cc, 98aicai[.]com and linkedinns[.]net.

According to a joint advisory from agencies in the US, UK, Australia, Canada, Japan, New Zealand and Spain, MicroScan has been active since at least 2017. The Python-based application contains more than 1,300 scripts for finding vulnerabilities in websites and services including Apache Struts, Jenkins, Oracle, WebLogic Server and WordPress. Integrity Tech reportedly used a Mirai malware variant to build an internet-connected device botnet that supported MicroScan reconnaissance.

Targets included a US power company, non-governmental organisations, airports in Japan and Poland, and Taiwanese infrastructure and universities. FishHub was used in attacks on at least 20 Taiwanese universities.

The advisory links the activity mainly to Flax Typhoon, but says Integrity Tech may also have worked with other Chinese hacking groups. It describes theft of credentials and email data from government, law enforcement, healthcare and religious organisations in South-east Asia; in some cases, access to stolen data was restricted to IP addresses in Xiamen, China. The article does not say whether the domain seizures ended all related activity.

View full article

Article by CyberSIXT