TL;DR
- what: The FBI and DoJ seized seven domains and blocked access to scanning and intrusion platforms run by Integrity Technology Group for the China-linked group Flax Typhoon.
- impact: The tooling was used to scan and in some cases infiltrate critical infrastructure, including a South Carolina power company, Japanese and Polish airports, and Taiwanese natural gas and power companies.
- fix: There is no vendor patch: the mitigation is the court-authorized domain seizure plus a joint advisory from seven countries documenting the group's tools and tradecraft.
- who: Critical infrastructure operators, universities, NGOs, Microsoft 365 tenants, and anyone running internet-facing web applications or SOHO and IoT devices.
The FBI and the Department of Justice have seized seven domains and blocked access to platforms that a China-linked contractor used to scan, and in some cases infiltrate, U.S. critical infrastructure. Targets named in court documents include a U.S. power company based in South Carolina, Japanese and Polish airports, a multi-national NGO, and Taiwanese critical infrastructure companies in the natural gas and power sectors.
The group is Flax Typhoon, also tracked as Ethereal Panda and RedJuliett. It is associated with Integrity Technology Group, a Beijing-based company that contracts with the Chinese government. This is the same organization tied to Raptor Train, the SOHO and IoT botnet taken down in a U.S. court-authorized operation in September 2024.
What was seized
The seven domains are:
- c0cc[.]cc
- 98aiblog[.]com
- 98aicai[.]com
- 98aicode[.]com
- outlook3650[.]com
- youtubecard[.]com
- linkedinns[.]net
Several of the names imitate Microsoft, YouTube and LinkedIn branding. According to an FBI affidavit, c0cc[.]cc was the access point for the group's scanning tool as recently as September 9, 2026, one month before the announcement.
MicroScan: a scanning platform in use since 2017
MicroScan is a Python-based web tool for reconnaissance and vulnerability scanning. It was originally hosted on 198.13.53[.]226 and is believed to have been in use as early as 2017. It ships with more than 1,300 penetration testing scripts that check websites for specific vulnerabilities in OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins and Apache Struts.
The scanner is paired with open-source tooling: BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe and wpscan. The operators used the combination to find targets of interest across networks and web applications. Beyond the infrastructure operators already listed, the named targets include two Taiwanese universities.
FishHub: phishing and follow-on payloads
A second Integrity Tech tool, FishHub, allegedly enabled network exploitation through spear-phishing and the deployment of follow-on payloads. Confirmed victims of FishHub-related activity include 20 Taiwanese universities.
The DoJ described the payloads this way: the malware gave Integrity Tech's clients unauthorized remote access to the victim network, or searched for specific files and sent them to servers controlled by Integrity Tech. The word "clients" matters. This was a service sold to other operators, not a single team's private toolkit.
The botnet behind the scanning
Court documents allege that Integrity Tech created and operated an IoT botnet built on a variant of the Mirai malware. The botnet used a number of domains for command-and-control, including subdomains of w8510[.]com, which gave operators bidirectional communication with infected devices. It was controlled and managed through an application named Sparrow.
⚠️ Botnet scale as of June 5, 2024 — A database on the server at 202.182.109[.]151 held records for more than 1.2 million infected devices, including over 385,000 unique U.S. victim devices. More than 260,000 devices were actively infected on that date, approximately 126,000 of them in the U.S.
Tradecraft in the joint advisory
Alongside the seizure, cybersecurity and intelligence agencies from the U.S., the U.K., Australia, Canada, Japan, New Zealand and Spain issued a joint advisory. It calls out Integrity Tech as a for-profit company that acquires or builds cyber tools for use and sale, and that compromises networks directly. The advisory describes activity going back to at least mid-January 2021:
- Initial access to victim networks and cloud-based services using Python- and Go-based command line utilities.
- Cross-site scripting (XSS) attacks used to harvest user credentials.
- SoftEther VPN client software installed on victim devices for persistence.
- EBurst, an open-source Python-based brute-force tool, aimed at accounts in Microsoft 365 cloud environments.
- A command-line utility called office-cli used to gain unauthorized access to mailbox data.
The U.K. National Cyber Security Centre said the actors enabled by Integrity Tech are using AI tools, such as automated scanning, alongside large-scale botnets and manual exploitation to compromise and steal confidential data from companies around the world, including critical sectors.
What the disruption does and does not change
The action removes seven domains and blocks access to the platforms behind them. It does not remove the company. The reporting on this operation describes seizures and blocked access, with no arrests tied to it. The timeline is the clearest signal of what to expect: Raptor Train was taken down in September 2024, and MicroScan was still reachable through c0cc[.]cc in September 2026, two years later.
No patch closes this — This is not a single CVE with a fixed version. The mitigation on record is the court-authorized seizure and the seven-nation advisory documenting the tools. Most of the scanning stack is open source and freely available, so the seized domains are the disposable part of the operation.
FBI Cyber Division Assistant Director Brett Leatherman framed the action as pressure on the contractor model itself: the PRC relies on contractor and enabling companies to expand the reach and scale of its cyber activity, and exposing those enablers makes targeting American networks harder.
The announcement landed with a related move. The State Department is offering up to $10 million for information on Zhang Yu, a Chinese national charged in connection with the 2021 Microsoft Exchange Server attacks tracked as Silk Typhoon, formerly Hafnium. Co-defendant Xu Zewei was extradited from Italy to the U.S. in April 2026.
Why it matters
Three points stand out for security teams and IT managers. First, the reconnaissance is industrial: 1,300 scripts against common web platforms, fed by a botnet of compromised small office and IoT devices, means scanning traffic arrives from ordinary residential and small business addresses. Second, the tooling is mostly commodity. Masscan, NMAP, wpscan and dirsearch look the same in logs whether the operator is a researcher or a state contractor. Third, the post-access tradecraft targets cloud identity and mail: brute force against Microsoft 365 accounts, mailbox access through a command-line utility, and a legitimate VPN client for persistence.
The seized domains and the two IP addresses in the court documents are useful historical indicators. They are also the part of this operation that is easiest for the operator to replace. The durable intelligence is the method: a contractor selling scanning, phishing and access as a service, against power, gas, aviation and university networks in at least four countries.
Originally published on RedEye Threat Intelligence.
Top comments (0)