Government

US Disrupts Chinese State-Sponsored Hacking Tools

Flax Typhoon and other APTs used MicroScan and FishHub to scan and hack US and foreign critical infrastructure.

Chinese hacking tools disrupted by US

The United States on Thursday announced the disruption of two hacking tools used by Chinese state-sponsored threat actors in attacks against US and foreign critical infrastructure.

Built by Integrity Technology Group (Integrity Tech), MicroScan has been used for vulnerability scanning, while FishHub has enabled network intrusions via spear phishing.

Integrity Tech, the US says, used a Mirai malware variant to build an IoT botnet that facilitated MicroScan’s use for reconnaissance against victims’ networks, including a US power company, NGOs, Japanese and Polish airports, and Taiwanese critical infrastructure entities and universities.

FishHub enabled Integrity Tech’s clients to access victim networks remotely, search for specific files, and exfiltrate them. The tool has been used in attacks against at least 20 universities in Taiwan.

The US seized the domains the threat actors were using to access MicroScan and FishHub, including c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net.

In 2024, the US disrupted Integrity Tech’s Raptor Train botnet, and in 2025 sanctioned it for providing cybersecurity products to Chinese state-sponsored APTs such as Flax Typhoon. The European Union sanctioned the company in March 2026.

Advertisement. Scroll to continue reading.

A new joint advisory (PDF) from government agencies in the US, UK, Australia, Canada, Japan, New Zealand, and Spain shows that MicroScan has been active since at least 2017, targeting Apache Struts, Juniper ScreenOS, Jenkins, OpenSSL, Oracle, Rejetto HFS, WebLogic Server, WordPress, and other services.

“This Python-based web application contains over 1,300 penetration testing scripts written to scan websites for specific vulnerabilities,” the advisory reads.

The tool was mainly associated with Flax Typhoon (also known as Ethereal Panda, Red Juliett, Storm-0919, and UNC5007) activity, but Integrity Tech is believed to have been working with other Chinese APTs as well.

Flax Typhoon was also seen using BBScan, dirsearch, Fscan, ksubdomain, masscan, Nmap, OneForAll, ShuiZe, and WPScan for reconnaissance, and command-line exploit utilities and the EBurst Microsoft Exchange password spraying tool for initial access.

The threat actors deployed VPN tools such as SoftEther for persistence and downloaded databases or manually extracted data from victims’ email addresses. They also used the PHP script Curlc4.txt and command-line utility office-cli for email exfiltration, and DC.ex to extract sensitive data from Active Directory.

“The threat actors collect account credentials and exfiltrate victim email data from on-premises systems and cloud-based services. Observed victims of email data theft included government organizations, law enforcement agencies, healthcare systems, and religious institutions located in Southeast Asia. In some instances, the threat actors restricted access to the exfiltrated data to only IP addresses from Xiamen, China,” the advisory reads.

Related: US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward

Related: Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

Related Content

Government

Zhang Yu was charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026.

Government

SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.

Malware & Threats

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.

Malware & Threats

The malware framework uses a modular architecture and a custom executable file format for long-term persistence.

Artificial Intelligence

The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents.

Cybercrime

Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world.

Artificial Intelligence

China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI.

Nation-State

The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version