Science & Tech · Cybersecurity · 7 hrs ago
US seizes domains linked to Chinese firm's hacking tools
US authorities seized seven domains linked to MicroScan and FishHub, tools used by China’s Integrity Technology Group.
The company has contracts with the Chinese government, according to allegations by the US Justice Department.
A joint warning from agencies in seven countries linked activity enabled by the firm to cyber operations tracked under several names, including Flax Typhoon.
The warning identified victims in parts of the United States, Southeast Asia, Africa and North America, but did not name Australia as a victim location.
Australia’s cyber security agency said the vulnerabilities and methods described could also affect Australian organisations and urged them to reduce the risk.
The advisory described stolen emails and confirmed FishHub victims at about 20 Taiwanese universities.
It recommends multifactor authentication for webmail, VPNs and critical systems.
US authorities seized seven domains linked to Integrity Technology Group’s MicroScan and FishHub hacking tools.
The seizures were detailed in court documents unsealed in the Western District of Pennsylvania.
A joint advisory linked activity enabled by the Chinese firm to campaigns tracked as Flax Typhoon, Ethereal Panda and Red Juliett.
The advisory named victims in the United States, Southeast Asia, Africa and North America, but not Australia.
Australian officials said the advisory’s vulnerabilities and techniques apply to Australian entities and urged organisations to reduce the threat.
- Who
- US authorities seized the domains linked to Integrity Technology Group, a Chinese firm.
- What
- They seized seven domains supporting the firm’s MicroScan vulnerability scanner and FishHub spear-phishing tool.
- When
- The article was published on October 11, 2026; the seizure date is not stated.
- Where
- The court documents were unsealed in the Western District of Pennsylvania. The named victims were in the United States, Southeast Asia, Africa and North America.
- Why
- The domains supported tools and infrastructure linked to hacking activity attributed to actors enabled by the firm.
This story does not have two clearly opposing sides.
While Australia is not specifically named, the vulnerabilities, tactics, techniques and procedures outlined in this advisory are applicable to Australian entities
Therefore, we encourage organisations to mitigate the threat
The advisory said MicroScan had been in use since 2017.
A court-authorised operation took down the company’s Mirai botnet of more than 200,000 consumer devices.
The US Treasury sanctioned Integrity Technology Group.
US authorities’ seizure of seven domains was reported alongside a joint warning from agencies in seven countries.
- Domains seized
- Seven
- Tools supported
- MicroScan and FishHub
- MicroScan scripts
- More than 1,300 penetration-testing scripts
- Confirmed FishHub victims
- About 20 Taiwanese universities
- Mirai botnet disruption
- More than 200,000 consumer devices
- Companies sanctioned
- Integrity Technology Group, by the US Treasury in January 2025











