FBI seizes Flax Typhoon domains behind MicroScan and FishHub tools
According to BleepingComputer, the FBI has seized seven domains used by the Chinese state-sponsored group known as Flax Typhoon to run two hacking tools, MicroScan and FishHub. The tools were used in attacks that breached critical infrastructure and other organizations worldwide. The Flax Typhoon domain seizure does not remove the threat entirely, but it cuts off infrastructure that defenders can now treat as known-bad.
What we know
The seizures target infrastructure behind two platforms that U.S. authorities allege were operated by China-based Integrity Technology Group (Integrity Tech). U.S. authorities say the company has contracts with the Chinese government. The seized domains now display FBI notices naming the Flax Typhoon group and Integrity Tech.
The report, published on October 8, 2026, draws on the U.S. Department of Justice and an FBI seizure affidavit. FBI Cyber Division assistant director Brett Leatherman said Integrity Tech gave China-linked actors capabilities for widespread vulnerability scanning and, in some cases, intrusions against U.S. and foreign critical infrastructure.
MicroScan
MicroScan is a vulnerability-scanning platform built to find weaknesses in target networks. Per the affidavit, it was used together with a botnet of internet-connected devices infected with Mirai malware to scan potential victims. Law enforcement confirmed the domain used to reach MicroScan was online in September 2026.
FishHub
FishHub was used for spear-phishing and to deliver further malware to networks that were already compromised. That malware gave attackers remote access, let them search for specific files and sent stolen data to servers controlled by Integrity Tech. On a server linked to FishHub, investigators found data belonging to more than 20 organizations, including six universities in Taiwan.
Who is affected
Scanning targets named in the affidavit include a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and electricity companies, and universities. The affidavit confirms scanning led to successful breaches at two Taiwanese universities, scanned in August 2022 and March 2023.
The FBI did not disclose whether the named power companies, airports and energy providers were actually breached. Treat those as scanning targets, not confirmed victims.
What has not been confirmed
- Which organizations beyond the two Taiwanese universities were breached.
- Whether the seizures have stopped the activity or the operators have moved to new infrastructure.
- The full list of vulnerabilities MicroScan was used to find: not disclosed in the source.
Why this matters
Analysis, not new facts: a scanner paired with a Mirai-infected botnet means probing can arrive from ordinary consumer and IoT addresses, so blocking by source reputation alone is weak. Internet-facing systems in energy, aviation and education are the stated focus, and any unpatched edge service in those sectors is a plausible entry point. Seizing domains disrupts the operators but does not clean up machines already compromised.
Indicators and detection
The seized domains named in the report are listed below, defanged. Search DNS, proxy and email logs for historical contact with them.
c0cc[.]cc (MicroScan access) 98aicai[.]com (malware delivery) 98aicode[.]com (malware delivery) outlook3650[.]com (malware delivery) youtubecard[.]com (malware delivery) linkedinns[.]net (malware delivery) 98aiblog[.]com (tied to SoftEther VPN on compromised systems)
Hunting ideas that follow from the facts:
- Look for unexpected SoftEther VPN software on servers and workstations, since it was used to keep remote access to victim networks.
- Review mail logs for lookalike domains imitating Outlook, YouTube or LinkedIn, which several seized names resemble.
- Check for unusual outbound transfers of files to unfamiliar servers from systems that received suspicious attachments.
What to do
- Search at least the past few years of DNS, proxy, firewall and email logs for the domains above; the activity reported dates back to 2022.
- If any match, treat the host as compromised: isolate it, review for SoftEther and remote-access tooling, and investigate data exfiltration.
- Inventory and patch internet-facing systems, particularly in critical infrastructure, energy, aviation and education environments.
- Find and remove or isolate unmanaged IoT devices that could be part of a Mirai-style botnet.
- Block the listed domains and brief your incident response team. Organizations that find evidence of compromise should consider reporting it to the FBI.
