Skip to content

US seizes Chinese cyber hacking tools linked to Flax Typhoon attacks

US seizes Chinese hacking tools linked to Flax Typhoon attacks
  • US authorities seized websites supporting Microscan and FishHub, two hacking tools operated by Chinese cybersecurity company Integrity Tech and linked to the Flax Typhoon campaign.
  • The tools were used to scan critical infrastructure networks, facilitate phishing attacks and steal sensitive information from organizations in the US, Taiwan and other countries.
  • A 58-page international cybersecurity advisory details Chinese hacking operations, including attacks on energy companies, airports, universities and government agencies.

US authorities, working with international cybersecurity partners, have disrupted infrastructure supporting two hacking tools operated by Integrity Technology Group, a Chinese cybersecurity company accused of assisting state-backed cyber operations against critical infrastructure worldwide.

The Beijing-based company, also known as Integrity Tech, was hired by China’s Ministry of State Security to support operations targeting universities, government agencies, telecommunications providers and media organizations, according to US authorities.

The Justice Department seized multiple websites associated with Microscan and FishHub, tools used for vulnerability scanning, phishing operations and unauthorized access to compromised networks.

Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure.

FBI Assistant Director Brett Leatherman

“The PRC relies on contractors and enabling companies to expand the reach and scale of its malicious cyber activity.”

The operation was accompanied by a 58-page technical advisory detailing hacking tools used by Chinese threat actors over the past six years in connection with Flax Typhoon, a long-running cyber espionage campaign.

Integrity Tech has employed automated vulnerability scanners, botnets and manual hacking techniques to obtain sensitive information from targeted organizations.

Court documents and cybersecurity advisories describe Microscan as a reconnaissance platform developed to identify vulnerabilities that Chinese hackers could exploit.

Targets of its scanning activity included a power company in South Carolina, airports in Japan and Poland, and Taiwanese critical infrastructure operators in the natural gas and electricity sectors.

Microscan has been used since 2017 to run penetration-testing scripts designed to identify specific vulnerabilities in websites.

FishHub, another platform developed by Integrity Tech, was designed to accelerate phishing operations. It also enabled attackers to download malware onto networks after gaining unauthorized access.

Authorities said attackers used FishHub’s remote-access capabilities against approximately 20 universities in Taiwan.

Breadth of attacks across critical infrastructure sectors

The technical advisory draws on multiple FBI incident response investigations involving organizations compromised by Integrity Tech or other Chinese hacking groups using the company’s tools.

The Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA) said attackers frequently concentrated on network edge devices that received limited security monitoring. Compromising these systems enabled hackers to establish persistent access while reducing the likelihood of detection.

Chris Butera, CISA’s acting executive assistant director for cybersecurity, warned that Chinese government hackers “continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing.”

Cybersecurity authorities from Australia, Japan, the United Kingdom, Spain, New Zealand and Canada contributed to the international advisory.

Integrity Tech has also served as a supplier and operator of infrastructure for other Chinese hacking groups, acquiring, selling or hosting tools used to compromise systems and extract sensitive information.

Among those tools is EBurst, which targets compromised email accounts hosted on Microsoft Exchange servers. It supports multiple interfaces for password spraying and password guessing, techniques used to identify valid account credentials.

Other tools associated with the operations provide access to email messages, calendars and contact information.

“The FBI recovered an archived email database the threat actors used to target email accounts of victim organizations. The threat actors collect account credentials and exfiltrate victim email data from on-premise systems and cloud-based services,” the agencies said.

“Observed victims of email data theft included government organizations, law enforcement agencies, healthcare systems, and religious institutions located in Southeast Asia. In some instances, the threat actors restricted access to the exfiltrated data to only IP addresses from Xiamen, China.”

Previous US operations against Integrity Tech

Integrity Tech has faced repeated US sanctions and law enforcement actions over the past three years because of its alleged involvement in Flax Typhoon operations.

Microsoft researchers publicly identified the Flax Typhoon campaign in 2023, linking the group to cyber espionage activity targeting organizations in Taiwan and other regions.

In September 2024, the Justice Department disrupted a Mirai-based botnet operated by Integrity Tech that had compromised more than 260,000 consumer devices.

Acting under court authorization, the FBI removed malware from infected systems and seized control of internet infrastructure used by Flax Typhoon.

The group primarily targeted government agencies, educational institutions, critical manufacturing companies and information technology organizations in Taiwan. Microsoft also identified victims across Southeast Asia, North America and Africa.

The campaign relied heavily on compromised internet-connected equipment to establish access to networks and support subsequent attacks.

Christopher Wray, then director of the FBI, said Flax Typhoon had become adept at infecting internet of things (IoT) hardware, including “cameras, video recorders and storage devices,” and exploiting those compromises to target “everyone from corporations and media organizations to universities and government agencies.”