U.S. Authorities Take Action Against Chinese Cyber Intrusions
In a significant move against foreign cyber threats, U.S. federal authorities have recently seized seven internet domains linked to Integrity Technology Group, a Beijing-based company alleged to have connections with the Chinese government. These domains were reportedly utilized to seek out vulnerable networks, distribute malware via spear-phishing campaigns, and execute data theft from various targets. This action marks the second time in just two years that the United States has disrupted the hacking infrastructure associated with this company.
The announcement was made by federal prosecutors, who detailed how Integrity Technology Group operated two sophisticated hacking tools—MicroScan and FishHub—used for malicious activities widely recognized in cybersecurity circles as part of a campaign known as Flax Typhoon. Court documents, which have now been unsealed in the U.S. District Court for the Western District of Pennsylvania, elaborate on the range of targets affected by these cyber intrusions. Notable among them are a power company in South Carolina, airports in both Japan and Poland, and key energy firms in Taiwan, as well as multiple educational institutions and a prominent multinational non-governmental organization.
U.S. Attorney Troy Rivetti, based in Pittsburgh, expressed grave concerns regarding the ongoing operations of state-sponsored hackers. He emphasized that these entities continually exploit weaknesses in networks and systems around the globe to identify and pilfer sensitive data. Rivetti underscored the significance of the seizures as the "second disruption" of Integrity Tech’s expansive operations, sending a clear message to cybercriminals operating from China or elsewhere about the U.S. government’s commitment to safeguarding cybersecurity both domestically and internationally.
In a prior action taken in September 2024, U.S. authorities successfully disrupted a Mirai botnet connected to Integrity Technology Group, which involved more than 200,000 compromised consumer devices worldwide. This sophisticated network allowed its operators to obfuscate malicious traffic by routing it through these infected devices. As part of ongoing efforts to clamp down on such cyber threats, the U.S. Department of the Treasury also imposed sanctions on Integrity Technology Group in January 2025.
The Mechanics of the Attack Tools
The tools used by Integrity Technology Group are characterized by their sophisticated design and malicious intent. MicroScan, one of the primary tools, operates as a Python-based web application that houses over 1,300 penetration-testing scripts specifically crafted to unearth vulnerabilities in systems exposed to the internet. Allegations suggest that its operators employed the compromised Mirai botnet and other supporting infrastructure to mask their activities, further complicating detection efforts.
According to a cybersecurity advisory disseminated by multiple intelligence agencies, including the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency (NSA), MicroScan was designed to target widely used software and services such as OpenSSL, Oracle WebLogic Server, WordPress, Jenkins, and Apache Struts. Alarmingly, it was reported that two Taiwanese universities were compromised shortly after their networks were scanned using the MicroScan tool, highlighting the immediate threats posed by these cyber intrusions.
Additionally, FishHub, the other tool operated by Integrity Technology Group, was purportedly designed for more focused intrusions, utilizing spear-phishing tactics to initiate breaches. After compromising a network, the attackers employed five of the seized domains to deliver additional malicious software, granting remote access, generating file listings, identifying specific documents, compressing them, and transmitting them to servers controlled by the attackers. Notably, victims of FishHub included approximately 20 Taiwanese universities, amplifying the tool’s far-reaching impact.
On October 6, a federal magistrate judge approved the seizure warrants for the domains. The resulting directive mandated that domain registries lock the domains, redirect them to servers managed by the FBI, and display notices of the seizures.
The supporting legal documents assert that the seized domains facilitated various violations of the Computer Fraud and Abuse Act. Furthermore, it was highlighted that these domains were financed with resources originating outside the United States. Although no arrests or formal criminal charges have been filed at this stage, the investigation continues to unfold.
A Proactive Cybersecurity Approach
The U.S. government characterized the Flax Typhoon intrusions as a multi-layered operation. Attackers were alleged to have harvested user credentials through techniques like cross-site scripting attacks and password spraying targeted at Microsoft Exchange servers. To maintain access, they leveraged SoftEther VPN software—often masquerading as legitimate Windows applications—to extract Active Directory user credentials and siphon emails from Microsoft 365 accounts.
As part of the U.S. government’s efforts to bolster cybersecurity, agencies have advised organizations to take proactive measures. Recommendations include patching internet-facing systems, mandating multi-factor authentication for webmail and virtual private networks, disabling unused services, and closely monitoring for unauthorized software and abnormal Active Directory activities. The government also emphasized the importance of reviewing web application logs for signs of exploitation attempts.
While seizing these domains disrupts the immediate infrastructure used for these attacks, experts note that it does not eliminate malware or remote-access tools that may have already infiltrated victim networks. As the cybersecurity landscape continues to evolve, vigilance and preparedness remain paramount in countering these increasingly sophisticated threats.

