THE Justice Department and the FBI announced court‑authorised seizures of two hacking tools, Microscan and FishHub, which were built and operated by Integrity Technology Group, a Beijing‑based firm with government contracts. The tools were designed to scan networks and, in many cases, intrude into critical infrastructure across several countries.
Court documents allege that Integrity Tech ran a Mirai‑based IoT botnet used to support Microscan’s reconnaissance and to enable intrusion campaigns, with a botnet registry counting more than 1.2 million infected devices in June 2024, of which around 385,000 were in the United States and roughly 260,000 actively infected at that time (about 126,000 in the U.S.).
Microscan and FishHub were employed against a wide range of targets. Microscan ran more than 1,300 penetration‑testing scripts targeting known weaknesses in software such as OpenSSL, WordPress, Jenkins, and Apache Struts, and was used to scan or hack a power company in South Carolina, a multinational NGO, airports in Japan and Poland, natural gas and power operators in Taiwan, and two Taiwanese universities.
FishHub relied on spear‑phishing to install further malware, providing attackers with remote access or exfiltrating data to Integrity Tech’s servers; confirmed victims include around 20 universities in Taiwan. The case is described by U.S. authorities as part of a broader effort to disrupt China‑linked cyber operations, with the UK’s National Cyber Security Centre and other allies coordinating a joint advisory naming Integrity Tech as a for‑profit enabler. The aim, authorities say, is to degrade the scale and reach of China’s hacking activities by striking at its infrastructure enablers.