The news
The FBI seized seven internet domains operated by the Chinese state-linked hacking group Flax Typhoon, disrupting infrastructure behind two of its tools, a vulnerability scanner called MicroScan and a spear-phishing platform called FishHub, BleepingComputer reported on October 8.
According to BleepingComputer, the seized domains were c0cc.cc, used to access MicroScan; 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com and linkedinns.net, used for FishHub malware delivery; and 98aiblog.com, tied to a SoftEther VPN service. The FBI coordinated with the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency and international partners on an accompanying advisory. The Hacker News reported the advisory was joint among the U.S., U.K., Australia, Canada, Japan, New Zealand and Spain.
MicroScan is a Python-based scanner with more than 1,300 penetration-testing scripts, according to both outlets. The Hacker News said its scripts cover software including OpenSSL, Oracle WebLogic, WordPress, Jenkins and Apache Struts. FishHub is used to send spear-phishing messages, deliver malware and steal data; BleepingComputer reported data from more than 20 organizations was found on a FishHub server.
Flax Typhoon, also tracked as Ethereal Panda and RedJuliett, is operated by Beijing-based Integrity Technology Group, according to BleepingComputer. Brett Leatherman of the FBI's Cyber Division said the company provided China-linked threat actors with capabilities used for widespread vulnerability scanning, as quoted by BleepingComputer. He added, as quoted by The Hacker News, that exposing these enablers makes it harder for China to target American networks.
BleepingComputer listed vulnerabilities the group commonly exploits, many years old, including CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2015-3306 and CVE-2014-6278. Targeted sectors include U.S. government agencies, critical manufacturing, healthcare, IT, law enforcement and education, the outlet reported.
The numbers
- Domains seized
- 7
- Penetration-testing scripts in MicroScan
- 1,300+
- Organizations whose data was on a FishHub server
- 20+ (BleepingComputer)
- Countries on the joint advisory
- 7 (The Hacker News)
Why CEOs should care
For CISOs, the lesson is that a nation-state group is leaning on old, known vulnerabilities, some more than a decade old, at industrial scale. Run the CVEs listed in the advisory against your asset inventory, with priority on internet-facing VPNs, web servers and developer tools such as Jenkins and GitLab. A domain seizure slows the operators; it does not patch your systems.
Security teams should also block the seized domains and the indicators in the joint advisory, and review email logs for lures tied to FishHub domains that imitate familiar brands such as Outlook, YouTube and LinkedIn. Healthcare, manufacturing and education organizations named as targets should treat this as a prompt to confirm their exposure.
Boards and CFOs should ask how long known critical flaws stay open in their environment and whether the company would know if a scanner like MicroScan had already probed it. Third-party and supplier networks matter too, since the targets span critical infrastructure sectors.
The bigger picture
The action continues a U.S. campaign against Integrity Technology Group. The Hacker News noted the 2024 takedown of the Raptor Train botnet tied to the same group. Officials are increasingly targeting the private contractors that build tools for state hackers, not only the hackers themselves, and allied agencies warn such actors combine automated scanning with large botnets.
What’s next
Expect follow-up guidance and indicators from CISA and partner agencies, and watch for the group to rebuild infrastructure under new domains, as disrupted operators often do.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







