US seizes Chinese scanning tools used to break into critical networks
The Justice Department and FBI pulled the plug on Microscan and FishHub, two tools prosecutors say a Chinese government contractor used to hunt for weak spots in US infrastructure.

Key points
- The Justice Department and FBI announced court-authorized seizures on October 8, 2026 of two hacking tools, Microscan and FishHub, operated by Integrity Technology Group, a Chinese company that holds contracts with the government in Beijing.
- Court documents unsealed in the Western District of Pennsylvania tie the tools to Flax Typhoon, a hacking crew US officials say works on behalf of the Chinese state.
- A joint advisory from the Cybersecurity and Infrastructure Security Agency lists eight old software flaws the group leaned on, some dating back to 2014.
- The hackers targeted Microsoft Exchange email servers with password-guessing attacks and planted themselves inside networks using legitimate VPN software, according to CISA.
- Threat Vectr's own leak-site tracking shows no public extortion listings tied to this group, which fits a pattern of quiet espionage rather than ransom demands.
Federal prosecutors moved on October 8 to shut down two tools that the Justice Department says a Chinese contractor built to scan for and sometimes infiltrate US networks. The tools are called Microscan and FishHub. According to court documents unsealed in the Western District of Pennsylvania, both were run by Integrity Technology Group, a company in the People's Republic of China that holds government contracts.
The hackers using the tools are tracked as Flax Typhoon. We first reported on the group on 2 September 2026, and our story published the same day as the seizures, "Ten governments name a Shanghai contractor as the engine behind China's data-theft campaigns", covers how a joint advisory pins years of intrusions on Integrity Technology Group.
Assistant Attorney General for National Security John A. Eisenberg said the National Security Division would "continue to respond decisively" to disrupt the group and the infrastructure behind it. First reported by The Hacker News, the seizures also pulled down several domains the tools relied on to function.
What do the tools actually do?
Microscan is a vulnerability scanner: it crawls the open internet looking for computers running software with known holes in it, the digital equivalent of walking down a street rattling door handles. FishHub is a spear-phishing kit, meaning it helps attackers send targeted fake emails designed to trick a specific employee into handing over a password or opening a booby-trapped file.
They form the opening moves of an intrusion. Find the weak door, then trick someone into opening it.
Which flaws were the hackers using?
A joint advisory from CISA published the same day names eight specific software vulnerabilities the group exploited. Several are old enough to vote. Because the specific CVE identifiers aren't confirmed in the sources available to us, we're not reproducing them here; CISA's advisory carries the full list.
CISA also flagged password spraying against Microsoft Exchange email servers. Password spraying is a slow, patient attack: criminals try one common password against thousands of accounts rather than thousands of passwords against one account, which helps them slip past lockout rules.
Once inside, the group used ordinary VPN software to stay connected and ran scripts to quietly copy out emails and login credentials.
Does a domain seizure actually stop them?
It slows them down, but doesn't end them. Taking Microscan and FishHub offline forces Integrity Tech to rebuild tooling and move customers to fresh infrastructure, which costs time and money. Groups like Flax Typhoon tend to resurface under a new name with fresh servers.
My read: the more useful signal is the eight-CVE list. If a Chinese state contractor is still getting mileage out of a 2014 Bash bug, the problem isn't clever hacking. It's unpatched boxes sitting on the public internet.
What should organisations do now?
CISA's advice is unglamorous and effective. Turn off services and ports you aren't using. Patch the eight listed vulnerabilities. Switch on multifactor authentication, meaning a second check beyond a password, on every service that supports it, especially Exchange. Clean up web application inputs so attackers can't inject malicious code through a form field.
For ordinary staff, the FishHub side matters most. A targeted phishing email from a group like this won't look sloppy. If a message pushes you to act fast on something involving credentials or document access, slow down and verify through a channel you already trust.



