The FBI and Justice Department said Oct. 8 that they had seized six internet domains used to provide access to Microscan and FishHub, tools U.S. authorities allege were run by the China-based Integrity Technology Group for vulnerability reconnaissance, spear phishing and follow-on intrusion activity. The court-authorized action is aimed at an enabling layer of cyber operations: the web infrastructure that lets operators deliver or control tools, rather than only the computers they may have compromised.
According to the Justice Department’s announcement, the domains were c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com and linkedinns[.]net. The department said the seizure denied users access to the two platforms. FBI and Justice Department officials told the Associated Press that the tools had been rendered inoperable.

What the seized domains supported
The government’s account separates the two systems by role. Microscan was described as a vulnerability-scanning platform, used to identify exposed systems and weaknesses that could be exploited later. Investigators said its reconnaissance activity included a U.S. power company, a multinational nongovernmental organization, airports in Japan and Poland, natural-gas and power-sector organizations in Taiwan, and two Taiwanese universities.
One of the six domains was identified as an access point for Microscan. The remaining five were tied to FishHub, which the Justice Department said was used in spear-phishing campaigns. After an initial compromise, FishHub could download malware for remote access or search for and take specified files, according to the department. The agency said confirmed FishHub victims included roughly 20 universities in Taiwan.

That division is useful for network defenders because it describes a chain rather than a single piece of malicious software. Scanning identifies exposed targets; deceptive messages seek a foothold; malware delivered after compromise can preserve access and collect information. Disrupting domains associated with those functions can break connections between operators and their infrastructure, even though it does not by itself establish how long any prior compromise may have persisted inside a victim network.
The Justice Department also said Microscan used an internet-of-things botnet infected with a variant of Mirai. That detail links the reconnaissance operation to a familiar problem in cybersecurity: consumer and small-office devices with weak security can be recruited at scale and used as distributed scanning or attack infrastructure, obscuring the traffic’s origin and spreading it across many networks.
Attribution remains the government’s allegation
In court documents unsealed in the Western District of Pennsylvania, the Justice Department alleged that malicious actors working for Integrity Technology Group operated and used both platforms. It said Integrity Tech, which it described as a China-based company with contracts with the Chinese government, supplied capabilities to China-linked threat actors targeting U.S. and foreign networks.
The FBI has characterized Integrity Technology Group as the entity known in private-sector threat reporting as Flax Typhoon, the Associated Press reported. That identification, as well as the asserted connection between the company and Chinese state interests, should be understood as the assessment of U.S. authorities rather than an independently adjudicated finding in the seizure announcement.
The immediate legal action was against domains, not a public announcement of arrests or the physical seizure of every copy of the software. Domain seizures can be consequential because they remove a reliable route to a service or payload delivery point. They can also be temporary operational setbacks if an operator can register replacement domains, rebuild hosting arrangements or shift to other infrastructure. An FBI official told the AP that Integrity Tech could try to reconstruct its systems, even as the disruption would affect its ability to operate.
A continuing campaign against alleged Integrity Tech infrastructure
This is the Justice Department’s second public technical disruption involving alleged Integrity Tech infrastructure. In September 2024, the department said it disrupted a separate Mirai botnet associated with the company that involved more than 200,000 compromised consumer devices worldwide. The earlier operation addressed a pool of infected machines; the October action targets systems authorities say were used for reconnaissance and phishing-led access.
U.S. pressure on the company has also included financial sanctions. Treasury sanctioned Integrity Tech in January 2025 over activity attributed to Flax Typhoon, as reported at the time by BleepingComputer. The actions do not prove that disruption and sanctions can permanently eliminate an operator’s capacity, but they show an effort to raise the cost of maintaining the infrastructure that supports it.
A separate Justice Department operation in August targeted QScan and QTRouter, platforms authorities said were used by China state-sponsored hackers against U.S. critical infrastructure. That August seizure involved different platforms and should not be conflated with Microscan or FishHub. Together, the reported actions target different parts of an alleged operation, from compromised-device infrastructure to tools used for reconnaissance and access.
For organizations responsible for exposed systems, the practical value of the latest action is not limited to whether the named domains remain unreachable. The Justice Department said the FBI and U.S. and foreign partners published a cybersecurity advisory containing indicators of compromise associated with Integrity Tech intrusion activity. Security teams can use those indicators alongside their own logs, email telemetry and endpoint records to look for past contact with the identified infrastructure or related intrusion behavior.
