Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

FBI seizes 7 Flax Typhoon domains, disrupting Chinese hacking tools MicroScan and FishHub

The FBI disrupted infrastructure behind a vulnerability scanner and a spear-phishing platform that officials tie to a Beijing contractor, as allies issued a joint advisory.

By · Editor

· 2 min read · Fact-checked

The 60-second brief

  • 1The FBI seized seven domains supporting Flax Typhoon's MicroScan scanner and FishHub phishing platform, BleepingComputer reported October 8.
  • 2MicroScan carries 1,300+ penetration-testing scripts targeting known flaws in common software.
  • 3Officials tie the group to Beijing-based Integrity Technology Group; targets include US agencies, healthcare and manufacturing.

The news

The FBI seized seven internet domains operated by the Chinese state-linked hacking group Flax Typhoon, disrupting infrastructure behind two of its tools, a vulnerability scanner called MicroScan and a spear-phishing platform called FishHub, BleepingComputer reported on October 8.

According to BleepingComputer, the seized domains were c0cc.cc, used to access MicroScan; 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com and linkedinns.net, used for FishHub malware delivery; and 98aiblog.com, tied to a SoftEther VPN service. The FBI coordinated with the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency and international partners on an accompanying advisory. The Hacker News reported the advisory was joint among the U.S., U.K., Australia, Canada, Japan, New Zealand and Spain.

MicroScan is a Python-based scanner with more than 1,300 penetration-testing scripts, according to both outlets. The Hacker News said its scripts cover software including OpenSSL, Oracle WebLogic, WordPress, Jenkins and Apache Struts. FishHub is used to send spear-phishing messages, deliver malware and steal data; BleepingComputer reported data from more than 20 organizations was found on a FishHub server.

Flax Typhoon, also tracked as Ethereal Panda and RedJuliett, is operated by Beijing-based Integrity Technology Group, according to BleepingComputer. Brett Leatherman of the FBI's Cyber Division said the company provided China-linked threat actors with capabilities used for widespread vulnerability scanning, as quoted by BleepingComputer. He added, as quoted by The Hacker News, that exposing these enablers makes it harder for China to target American networks.

BleepingComputer listed vulnerabilities the group commonly exploits, many years old, including CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2015-3306 and CVE-2014-6278. Targeted sectors include U.S. government agencies, critical manufacturing, healthcare, IT, law enforcement and education, the outlet reported.

The numbers

Domains seized
7
Penetration-testing scripts in MicroScan
1,300+
Organizations whose data was on a FishHub server
20+ (BleepingComputer)
Countries on the joint advisory
7 (The Hacker News)

Why CEOs should care

For CISOs, the lesson is that a nation-state group is leaning on old, known vulnerabilities, some more than a decade old, at industrial scale. Run the CVEs listed in the advisory against your asset inventory, with priority on internet-facing VPNs, web servers and developer tools such as Jenkins and GitLab. A domain seizure slows the operators; it does not patch your systems.

Security teams should also block the seized domains and the indicators in the joint advisory, and review email logs for lures tied to FishHub domains that imitate familiar brands such as Outlook, YouTube and LinkedIn. Healthcare, manufacturing and education organizations named as targets should treat this as a prompt to confirm their exposure.

Boards and CFOs should ask how long known critical flaws stay open in their environment and whether the company would know if a scanner like MicroScan had already probed it. Third-party and supplier networks matter too, since the targets span critical infrastructure sectors.

The bigger picture

The action continues a U.S. campaign against Integrity Technology Group. The Hacker News noted the 2024 takedown of the Raptor Train botnet tied to the same group. Officials are increasingly targeting the private contractors that build tools for state hackers, not only the hackers themselves, and allied agencies warn such actors combine automated scanning with large botnets.

What’s next

Expect follow-up guidance and indicators from CISA and partner agencies, and watch for the group to rebuild infrastructure under new domains, as disrupted operators often do.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

FBIFlax TyphoonIntegrity Technology GroupCISA

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.