An international coalition of cybersecurity agencies has seized infrastructure tied to Integrity Tech, a Chinese cybersecurity firm accused of supporting state-backed hacking on behalf of Beijing's Ministry of State Security. The operation targeted websites underpinning two tools—Microscan and FishHub—that have been used in a long-running campaign known as Flax Typhoon.
Microscan has been used since 2017 to scan websites for vulnerabilities, while FishHub streamlined phishing and gave attackers remote access to breached networks. Authorities said FishHub was used against about 20 universities in Taiwan. Other victims included a South Carolina power company, airports in Japan and Poland, and Taiwanese firms in the natural gas and power sectors.
The advisory, published by the FBI, CISA, and NSA with input from Australia, Japan, the UK, Spain, New Zealand, and Canada, warned that Chinese hackers are positioning themselves inside critical infrastructure networks, including operational technology systems. This is not the first action against Integrity Tech: in September 2024, the DOJ disrupted a Mirai-based botnet built from more than 260,000 consumer devices. Microsoft first identified Flax Typhoon publicly in 2023.