Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Government

US Disrupts Chinese State-Sponsored Hacking Tools

Flax Typhoon and other APTs used MicroScan and FishHub to scan and hack US and foreign critical infrastructure.

Chinese hacking tools disrupted by US

The United States on Thursday announced the disruption of two hacking tools used by Chinese state-sponsored threat actors in attacks against US and foreign critical infrastructure.

Built by Integrity Technology Group (Integrity Tech), MicroScan has been used for vulnerability scanning, while FishHub has enabled network intrusions via spear phishing.

Integrity Tech, the US says, used a Mirai malware variant to build an IoT botnet that facilitated MicroScan’s use for reconnaissance against victims’ networks, including a US power company, NGOs, Japanese and Polish airports, and Taiwanese critical infrastructure entities and universities.

FishHub enabled Integrity Tech’s clients to access victim networks remotely, search for specific files, and exfiltrate them. The tool has been used in attacks against at least 20 universities in Taiwan.

The US seized the domains the threat actors were using to access MicroScan and FishHub, including c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net.

In 2024, the US disrupted Integrity Tech’s Raptor Train botnet, and in 2025 sanctioned it for providing cybersecurity products to Chinese state-sponsored APTs such as Flax Typhoon. The European Union sanctioned the company in March 2026.

Advertisement. Scroll to continue reading.

A new joint advisory (PDF) from government agencies in the US, UK, Australia, Canada, Japan, New Zealand, and Spain shows that MicroScan has been active since at least 2017, targeting Apache Struts, Juniper ScreenOS, Jenkins, OpenSSL, Oracle, Rejetto HFS, WebLogic Server, WordPress, and other services.

“This Python-based web application contains over 1,300 penetration testing scripts written to scan websites for specific vulnerabilities,” the advisory reads.

The tool was mainly associated with Flax Typhoon (also known as Ethereal Panda, Red Juliett, Storm-0919, and UNC5007) activity, but Integrity Tech is believed to have been working with other Chinese APTs as well.

Flax Typhoon was also seen using BBScan, dirsearch, Fscan, ksubdomain, masscan, Nmap, OneForAll, ShuiZe, and WPScan for reconnaissance, and command-line exploit utilities and the EBurst Microsoft Exchange password spraying tool for initial access.

The threat actors deployed VPN tools such as SoftEther for persistence and downloaded databases or manually extracted data from victims’ email addresses. They also used the PHP script Curlc4.txt and command-line utility office-cli for email exfiltration, and DC.ex to extract sensitive data from Active Directory.

“The threat actors collect account credentials and exfiltrate victim email data from on-premises systems and cloud-based services. Observed victims of email data theft included government organizations, law enforcement agencies, healthcare systems, and religious institutions located in Southeast Asia. In some instances, the threat actors restricted access to the exfiltrated data to only IP addresses from Xiamen, China,” the advisory reads.

Related: US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward

Related: Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Rapid7 has named Rik Ferguson as VP of Security Intelligence.

Cytactic has appointed Tim Brown as CSO.

Scott Simkin has joined Vega as CMO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.