In short: On October 8, 2026, the FBI and the U.S. Department of Justice seized seven internet domains used to run two hacking tools, MicroScan and FishHub, operated by a Beijing-based company called Integrity Technology Group and tied to the China-linked hacking collective Flax Typhoon. A day later, CISA added five exploited flaws to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch them by October 11, 2026.
This is the second major public takedown aimed at Integrity Tech in two years, and the scope is wider than a single group: a joint advisory backed by seven countries says the company has been providing the tooling behind years of intrusions into critical infrastructure, universities, and government networks around the world. Here is what actually happened, which systems are at risk, and what defenders should do now.
The domain seizures: what the FBI took down
The court-authorized seizures were announced on October 8 after documents were unsealed in the Western District of Pennsylvania. Visitors to the affected domains now land on FBI seizure notices. According to the Justice Department, the operation was designed to deny malicious actors access to the two tools and disrupt their ability to scan networks, phish victims, and steal data.
Two tools sat at the center of the operation:
- MicroScan is a vulnerability-scanning platform. Authorities say it was used to find weak points in target networks, powered in part by a botnet of compromised internet-connected devices infected with a Mirai malware variant. Named targets included a power company in the United States, airports in Japan and Poland, Taiwanese universities, a multinational non-governmental organization, and Taiwanese critical-infrastructure companies. The scanning led to actual breaches, including at two Taiwanese universities.
- FishHub handled the next step: spear-phishing attacks that delivered additional malware into networks that had already been probed. The malware gave the operators unauthorized remote access and a way to exfiltrate files to servers they controlled. Investigators found data and files from more than 20 organizations on a server linked to FishHub, including material tied to six universities in Taiwan.
This follows the same pattern law enforcement used in other supply-chain and infrastructure compromises: take away the platform, and the campaign has to rebuild its plumbing from scratch.
Who is Integrity Technology Group?
Integrity Technology Group is a China-based cybersecurity company that, according to U.S. authorities, holds contracts with the Chinese government. The FBI has previously assessed that Integrity Tech is responsible for the intrusion activity publicly attributed to Flax Typhoon, essentially calling the company the real identity behind the hacker name.
The company is not new to law enforcement attention. The United States sanctioned it last year, and in September 2024 authorities disrupted a Mirai-based botnet tied to the firm that had absorbed more than 200,000 compromised consumer devices worldwide. The MicroScan and FishHub seizure is described by the DOJ as its second public technical disruption against the same outfit.
The FBI has called the operation indiscriminate and reckless, noting that the campaign reached government organizations, critical manufacturing, healthcare, and IT companies across North America, Southeast Asia, and Africa.
The seven-country joint advisory
Paired with the seizures, the FBI, CISA, and the NSA released a joint advisory with partner agencies in the United Kingdom, Australia, Canada, Japan, New Zealand, and Spain. The advisory urges organizations to patch vulnerable systems, enforce multi-factor authentication, and watch for the published indicators of compromise tied to Integrity Tech’s infrastructure.
According to the advisory, the group’s playbook combines automated scanning tools, cross-site scripting attacks, and password spraying against Microsoft Exchange servers, while establishing persistence through VPN software and exfiltrating emails and credentials using scripts. It also warned that actors linked to the company continue to position themselves inside critical-infrastructure networks, including operational technology systems, so that critical functions could be disrupted at a future point of their choosing.
CISA’s five new KEV additions and the October 11 deadline
On October 9, CISA added five security flaws to its Known Exploited Vulnerabilities catalog, confirming they had been exploited by Flax Typhoon. The list is notable for how old some of the bugs are, a reminder that attackers happily reuse ancient vulnerabilities when defenders leave them unpatched:
- CVE-2015-3306 (CVSS 10.0): improper access control in ProFTPD that lets remote attackers read and write arbitrary files via the site cpfr and site cpto commands.
- CVE-2021-3199 (CVSS 9.8): a path-traversal flaw in ONLYOFFICE Docs, reachable through a JWT-protected image-upload parameter, that can lead to remote code execution.
- CVE-2023-22894 (CVSS 7.2): cleartext storage of sensitive information in Strapi that can expose user details to anyone with admin-panel access.
- CVE-2016-3081 (CVSS 8.1): a command-injection flaw in Apache Struts 2 that allows arbitrary code execution via a method prefix when Dynamic Method Invocation is enabled.
- CVE-2015-5477 (CVSS 7.5): a reachable-assertion flaw in ISC BIND that lets a remote attacker trigger a denial of service with crafted TKEY queries.
Three additional flaws named in the advisory were already sitting in the KEV catalog: the infamous Shellshock bug in GNU Bash (CVE-2014-6278), the Ivanti Pulse Connect Secure file-read flaw (CVE-2019-11510), and a GitLab remote code execution bug (CVE-2021-22205).
Federal civilian agencies are required to apply the patches or discontinue use of the affected products by October 11, 2026. If you run any of the affected software, treat that date as your own deadline too. The same patch-now urgency applies to other critical enterprise flaws currently circulating, where unpatched instances keep getting folded into active campaigns.
What defenders should do right now
A seizure like this disrupts the attacker’s infrastructure, but it does not guarantee that every affected network is now clean. Officials were explicit about that. If your organization operates any of the vulnerable products above, or sits in one of the targeted sectors, this is the moment to:
- Patch the five newly listed flaws immediately, along with the three already-known KEV entries in the advisory.
- Enforce multi-factor authentication on all internet-facing services, especially VPN and mail.
- Review the joint advisory’s indicators of compromise and hunt for MicroScan scanning or FishHub phishing artifacts in your logs.
- Segment operational technology from IT networks and monitor for the Exchange password-spraying patterns described in the advisory.
- If you run open-source infrastructure and want a free second look, consider programs like Anthropic’s free Cyber Mission scans for open-source projects.
Frequently asked questions
What is Flax Typhoon?
Flax Typhoon is the name the cybersecurity industry uses for a China-linked state-sponsored hacking collective. U.S. authorities say the group’s intrusion activity is actually run by Integrity Technology Group, a Beijing-based company with Chinese government contracts. It is also tracked by some vendors under names like Ethereal Panda and Red Juliette.
What are MicroScan and FishHub?
MicroScan is a vulnerability-scanning tool used to find weaknesses in target networks, amplified by a botnet of infected internet-of-things devices. FishHub is the follow-on tool for spear-phishing and malware delivery that gave attackers remote access and let them steal data. Both were allegedly built and operated by Integrity Technology Group.
What does the FBI’s domain seizure actually accomplish?
Seven domains supporting the two tools were seized under court authority, cutting off the infrastructure the operators used to reach victims. That forces the campaign to rebuild its tooling and distribution channels, which is a real disruption, though officials caution it does not automatically mean every compromised network is secure.
Which vulnerabilities have to be patched by October 11, 2026?
CISA added CVE-2015-3306 (ProFTPD), CVE-2021-3199 (ONLYOFFICE Docs), CVE-2023-22894 (Strapi), CVE-2016-3081 (Apache Struts), and CVE-2015-5477 (ISC BIND) to its KEV catalog on October 9, 2026. Federal agencies must remediate them by October 11. The accompanying advisory also references Shellshock, an Ivanti Pulse Connect Secure flaw, and a GitLab RCE bug that were already in the catalog.
Has Integrity Tech been targeted before?
Yes. The U.S. sanctioned the company last year, and in September 2024 authorities disrupted a Mirai-based botnet tied to the firm containing more than 200,000 compromised devices. The October 2026 seizure of MicroScan and FishHub domains is the second public technical disruption aimed at its infrastructure.

1 thought on “FBI Seizes Flax Typhoon Hacking Tools MicroScan and FishHub: What Happened and What to Do”