Skip to content
RegionAmericas

MediumII Cyber Warfare & Critical Infrastructure8 October 2026, Thursday

FBI seizes seven domains tied to China-linked Flax Typhoon

The US Justice Department and the FBI on 8 October seized, under court order, seven domains belonging to the MicroScan and FishHub tools run by Beijing-based Integrity Technology Group. The tools had been used to scan Taiwanese energy companies and airports in Japan.

Location: PITTSBURGH

BleepingComputer reports that the seizure order came from the US District Court for the Western District of Pennsylvania, and the domains now display an FBI banner. MicroScan is a vulnerability scanner containing more than 1,300 penetration testing scripts. FishHub was used for targeted phishing and to load further malware onto compromised networks. The Record says MicroScan has been in use since 2017; Microsoft first named the group in 2023.

Targets scanned include an electricity company in South Carolina, airports in Japan and Poland, and gas and power companies in Taiwan. The FBI did not say whether these systems were breached. The two sources diverge on the number of victims. BleepingComputer counts data from more than 20 organisations on the FishHub server, six of them Taiwanese universities; The Record says FishHub access was used against about 20 Taiwanese universities.

The FBI, CISA and NSA issued a 58-page joint advisory with Australia, Japan, the UK, Spain, New Zealand and Canada. The sources also differ on the size of the Mirai-based botnet Integrity Tech operated before it was dismantled in 2024. BleepingComputer puts it at more than 200,000 devices, The Record at more than 260,000. The company was placed on the UK sanctions list in 2025 and the European Union's in 2026.

Talay assessment

Bottom line

The operation targets not a single group but the scanning and intrusion pipeline Beijing runs through contractor firms. Seven domains were taken down, yet after the 2024 botnet operation the company was seen building new tools. The most likely path is a brief disruption followed by the infrastructure being rebuilt on new domains.

Likely effects

  • Taiwan's energy infrastructureNegative1–6 months

    The scanning of Taiwan's gas and power companies suggests reconnaissance of the energy grid ahead of a possible crisis.

  • Japanese airportsNegativeWeeks

    Japanese airports appearing on the target list will push transport operators to check their networks for the indicators in the advisory.

  • US–China tech tensionsUncertain1–6 months

    Targeting a state-contracted firm again strengthens Washington's case for widening sanctions on Chinese contractors.

Possibilities, ranked

  1. 1
    Infrastructure is rebuilt55%

    Integrity Tech or linked teams bring the tools back online on new domains within weeks.

    Watch: Security firms' reports of new Flax Typhoon infrastructure

  2. 2
    Sanctions widen30%

    The US Treasury or Commerce Department adds new companies and individuals linked to Integrity Tech to its lists.

    Watch: New Chinese cyber contractors on OFAC and BIS lists

  3. 3
    Lasting disruption15%

    The indicators in the joint advisory are widely blocked and the group's scanning activity drops markedly for months.

    Watch: New breach disclosures from organisations in Taiwan and Japan

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Domains seized▲ 7
  • Joint advisory (pages)▲ 58
  • Countries on the advisory▲ 7

Sources

  1. BleepingComputer — FBI disrupts Chinese hacking tools used to breach critical infrastructure
  2. The Record — International coalition seizes tools used by cyber firm behind Flax Typhoon