Washington, D.C. · Friday, October 9, 2026Independent civic journalism
The Washington Tribune
washingtontribune.com®

Technology & National Security

Justice Department Seizes Domains Used by China-Linked Hacking Tools

Federal investigators disrupted seven domains associated with vulnerability scanning and spear-phishing systems aimed at critical infrastructure and universities.

A second disruption of the same network

The Justice Department and FBI announced Thursday that they had seized seven internet domains used by two intrusion tools known as Microscan and FishHub. Court documents connect the systems to Integrity Technology Group, a company based in China that the department says has government contracts. Private researchers refer to associated activity as Flax Typhoon. The action is the second public U.S. disruption of the company's infrastructure, following a 2024 operation against a large botnet of infected consumer devices.

How Microscan allegedly worked

According to unsealed court records, Integrity Tech used a Mirai-based botnet and other systems to scan victim networks for weaknesses that clients could later exploit. Targets included a South Carolina power company, an international nongovernmental organization, airports in Japan and Poland, Taiwanese energy companies and universities. Scanning alone does not prove a successful breach, but it can reveal exposed services and prioritize attacks. Seizing access infrastructure can interrupt that reconnaissance and provide investigators with additional evidence.

FishHub supported spear phishing

The department says FishHub helped deliver malware after an initial compromise, allowing remote access or searching for particular files. Confirmed victims included about 20 Taiwanese universities. Five seized domains allegedly participated in malware delivery, while another domain supported unauthorized remote administration. The allegations come from government affidavits and warrants, not a completed criminal trial. Public attribution should therefore distinguish between documented technical indicators, sworn allegations and any later judicial finding.

Why critical infrastructure is vulnerable

Power companies, airports, universities and public organizations often operate complex networks containing old equipment, third-party services and internet-connected devices. A single unpatched system can become an entry point. Security teams should use the indicators released with the operation, review unusual outbound connections, rotate exposed credentials and segment operational technology from ordinary business systems. Domain seizures disrupt infrastructure but do not remove malware already installed on a victim network.

International cooperation is essential

The FBI's San Diego and Baltimore field offices coordinated with the bureau's Cyber Division, the Justice Department and foreign partners, including Japanese authorities. Cyber campaigns cross borders and frequently use infrastructure located outside the attacker's country. Cooperation can speed evidence preservation and domain control, but differences in law and diplomatic relations complicate attribution and prosecution. Governments should publish enough technical detail for defenders without exposing investigative methods that would help adversaries adapt.

What organizations should do now

Network operators can compare logs against the government's advisory, patch internet-facing systems and verify that backups are isolated and recoverable. Employees should be trained to recognize targeted messages without being blamed for sophisticated deception. Leaders should also know who has authority to disconnect systems and notify regulators during an incident. The success of the federal action will depend on whether victims use the released intelligence. A seized domain is a meaningful disruption, but sustained defense requires continuous monitoring and faster remediation of known vulnerabilities. Smaller organizations that lack dedicated teams should contact sector information-sharing groups or trusted managed-security providers rather than assume the operation affected only large critical-infrastructure operators. Suppliers and universities should review their own exposure too.

Reporting note: This article draws on public records and verified reporting; material claims are attributed in the text.

Return to the front page