The FBI and the Department of Justice announced October 8 that they have seized seven domains and disrupted two hacking tools tied to Flax Typhoon, the China-linked threat group U.S. authorities associate with Integrity Technology Group, a Beijing-based information-security company Washington says holds contracts with the Chinese government. The operation targeted reconnaissance and spear-phishing infrastructure that prosecutors say was used to scan — and in some cases infiltrate — critical infrastructure networks in the United States and abroad.
The two tools played different roles in the intrusion chain. Microscan was a vulnerability scanner run partly through a botnet of internet-connected devices infected with a Mirai malware variant, letting operators probe victim networks from infrastructure that looked unrelated to the real attacker. Court filings cited targets including a power company in South Carolina, airports in Japan and Poland, natural gas and electricity organizations in Taiwan, a multinational nonprofit, and two Taiwanese universities. One of the more striking details: eight publicly known vulnerabilities on Microscan's target list included a 2014 Shellshock flaw in Bash, a 2015 BIND denial-of-service bug, a 2016 Apache Struts remote-code-execution hole, a 2019 Pulse Secure VPN file-read bug, and a 2021 GitLab remote-code-execution vulnerability — a reminder that unpatched legacy software remains an active attack surface years after fixes are available.
FishHub played the other half of the operation: spear-phishing and post-compromise activity. Authorities say it delivered malware that provided remote access, searched victim systems for selected files, and exfiltrated them to attacker-controlled servers. The Justice Department confirmed roughly twenty Taiwanese universities as victims of FishHub-linked activity. One seized domain also supported unauthorized remote-administration software that kept a connection open to some of the same university networks.
The scale of the underlying infrastructure is worth absorbing. Court documents allege Integrity Technology Group ran a Mirai-variant IoT botnet managed through an application called Sparrow, with a botnet database reportedly recording more than 1.2 million infected devices by June 2024 — including over 385,000 devices in the United States. Microscan itself reportedly ran more than 1,300 scanning scripts and remained accessible as recently as September 2026. Agencies from the United States and six partner countries issued a joint advisory on Integrity Tech's role in enabling malicious cyber activity.
This is the second public disruption of Integrity Tech's infrastructure in two years: the Justice Department took down a 200,000-device Mirai botnet tied to the company in September 2024. The cat-and-mouse pattern illustrates the limits of infrastructure seizures — botnets can be rebuilt — but also why the government keeps doing them: each operation buys time, exposes tradecraft, and forces operators to reconstitute under law-enforcement scrutiny.
For enterprise defenders, the takeaway is refreshingly concrete. Audit legacy and internet-facing systems against the known exploited vulnerabilities catalog, segment operational networks from general-purpose IT, and treat phishing-resistant authentication and continuous patching as non-negotiable rather than aspirational. Flax Typhoon's playbook didn't depend on a zero-day; it depended on organizations leaving old doors unlocked.