Technology & National Security
Justice Department Seizes Domains Used by China-Linked Hacking Tools
Federal investigators disrupted seven domains associated with vulnerability scanning and spear-phishing systems aimed at critical infrastructure and universities.
A second disruption of the same network
The Justice Department and FBI announced Thursday that they had seized seven internet domains used by two intrusion tools known as Microscan and FishHub. Court documents connect the systems to Integrity Technology Group, a company based in China that the department says has government contracts. Private researchers refer to associated activity as Flax Typhoon. The action is the second public U.S. disruption of the company's infrastructure, following a 2024 operation against a large botnet of infected consumer devices.
How Microscan allegedly worked
According to unsealed court records, Integrity Tech used a Mirai-based botnet and other systems to scan victim networks for weaknesses that clients could later exploit. Targets included a South Carolina power company, an international nongovernmental organization, airports in Japan and Poland, Taiwanese energy companies and universities. Scanning alone does not prove a successful breach, but it can reveal exposed services and prioritize attacks. Seizing access infrastructure can interrupt that reconnaissance and provide investigators with additional evidence.
FishHub supported spear phishing
The department says FishHub helped deliver malware after an initial compromise, allowing remote access or searching for particular files. Confirmed victims included about 20 Taiwanese universities. Five seized domains allegedly participated in malware delivery, while another domain supported unauthorized remote administration. The allegations come from government affidavits and warrants, not a completed criminal trial. Public attribution should therefore distinguish between documented technical indicators, sworn allegations and any later judicial finding.
Why critical infrastructure is vulnerable
Power companies, airports, universities and public organizations often operate complex networks containing old equipment, third-party services and internet-connected devices. A single unpatched system can become an entry point. Security teams should use the indicators released with the operation, review unusual outbound connections, rotate exposed credentials and segment operational technology from ordinary business systems. Domain seizures disrupt infrastructure but do not remove malware already installed on a victim network.
International cooperation is essential
The FBI's San Diego and Baltimore field offices coordinated with the bureau's Cyber Division, the Justice Department and foreign partners, including Japanese authorities. Cyber campaigns cross borders and frequently use infrastructure located outside the attacker's country. Cooperation can speed evidence preservation and domain control, but differences in law and diplomatic relations complicate attribution and prosecution. Governments should publish enough technical detail for defenders without exposing investigative methods that would help adversaries adapt.
What organizations should do now
Network operators can compare logs against the government's advisory, patch internet-facing systems and verify that backups are isolated and recoverable. Employees should be trained to recognize targeted messages without being blamed for sophisticated deception. Leaders should also know who has authority to disconnect systems and notify regulators during an incident. The success of the federal action will depend on whether victims use the released intelligence. A seized domain is a meaningful disruption, but sustained defense requires continuous monitoring and faster remediation of known vulnerabilities. Smaller organizations that lack dedicated teams should contact sector information-sharing groups or trusted managed-security providers rather than assume the operation affected only large critical-infrastructure operators. Suppliers and universities should review their own exposure too.
Reporting note: This article draws on public records and verified reporting; material claims are attributed in the text.
