News

The FBI Seized Hacking Tools a Chinese Security Firm Used to Scan a US Power Company and Taiwan's Universities

The FBI seized domains behind Microscan and FishHub, tools US officials tie to Beijing contractor Integrity Tech and the Flax Typhoon hackers, who scanned a South Carolina power company and hit about 20 Taiwanese universities.

The FBI Seized Hacking Tools a Chinese Security Firm Used to Scan a US Power Company and Taiwan's Universities

The FBI has taken down the infrastructure behind two hacking tools that US officials say a Chinese security company built for one of Beijing's state-backed hacking crews. One was used to probe a power company in South Carolina. The other was used to break into Taiwanese universities as recently as March.

On Thursday, the Justice Department and FBI announced court-authorized seizures of seven web domains tied to Microscan, a vulnerability scanner, and FishHub, a tool for delivering malware and stealing data after a phishing hit. The seizures were authorized in the Western District of Pennsylvania.

US officials say both tools came from Integrity Technology Group, a for-profit Beijing security firm with Chinese government ties, and were used by the group known as Flax Typhoon.

What the tools were pointed at

Unsealed court documents say Microscan scanned a South Carolina power company's network on or about April 26 and December 29, 2022. It was also aimed at a multinational NGO, airports in Japan and Poland, and at least two Taiwanese natural gas and power companies. Flax Typhoon went on to break into networks Microscan had scanned, the documents say, including a university in Hsinchu, Taiwan, in March 2023 and another in Puli Township in August 2022.

FishHub went after education. Five of the seized domains delivered it as recently as March and infected about 20 Taiwanese universities. "I believe the tool was named FishHub because it facilitated phishing activity," FBI agent Adam James wrote in his affidavit. Once inside, it compressed and exfiltrated selected files.

A web app for reading other people's email

The seizures came with a joint advisory from the FBI, CISA and NSA, plus agencies in the UK, Australia, Canada, Japan, New Zealand and Spain. The 58-page document covers six years of Flax Typhoon activity.

The playbook is methodical, and it has been running since at least mid-January 2021. The hackers break in with open-source scanners, fake login pages built with cross-site scripting, and password spraying against Microsoft 365 and Exchange. They stay in by running SoftEther VPN renamed as conhost.exe or dllhost.exe so it blends in with Windows. They steal mail with scripts that pull mailboxes through Exchange Web Services.

The strangest detail is what happens to that mail. The group runs a web application that "provides third-party access to stolen email content." Users can pull up a specific account's inbox by adding arguments to a URL. The advisory does not say who those third parties are.

Victims of the email theft included government organizations, law enforcement, healthcare systems and religious institutions in Southeast Asia. Some of the stolen data was locked so it could only be viewed from IP addresses in Xiamen, China.

The same contractor, again

Integrity Tech is a familiar target. In September 2024 the Justice Department dismantled its Mirai botnet of more than 260,000 consumer devices. The US Treasury sanctioned the company in January 2025, and the UK followed in December 2025. In 2024, then FBI Director Christopher Wray said the company's "chairman has publicly admitted that for years his company has collected intelligence and performed reconnaissance for Chinese government security agencies."

When Treasury sanctioned it, Integrity Tech told the Shanghai Stock Exchange the US move had no factual basis, and China's Foreign Ministry said it firmly opposed the sanctions.

Officials now describe the strategy as going after the suppliers, not just the hackers. "The PRC relies on contractors and enabling companies to expand the reach and scale of its malicious cyber activity," said the FBI's Brett Leatherman. "Under the FBI Cyber Strategy, we pursue both the actors who threaten critical infrastructure and the enterprises that support them."

CISA's Chris Butera warned that Chinese government-affiliated actors "continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing."

The UK's Paul Chichester of the NCSC said the "breadth of sectors that have been targeted across the globe demonstrate the extent of the threat." Flax Typhoon is far from the only China-linked crew active right now: another has been phishing AI policy experts while impersonating Anthropic staff and former White House officials.

Some offers on this page may be paid placements or contain affiliate links.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free