
US authorities say they have seized online infrastructure behind two hacking tools allegedly operated by a China-based company linked to a state-sponsored group. The Justice Department and FBI announced the court-authorised action on Thursday, naming the tools Microscan and FishHub. The action is a disruption of the tools’ access points, not a claim that every affected network has been cleaned or that the wider campaign has ended.
In the Justice Department’s account, Integrity Technology Group built Microscan to probe networks for weaknesses. Investigators allege it could work through a botnet of infected internet-connected devices and helped identify systems for later exploitation. The targets named in court documents include a US power company, airports in Japan and Poland, Taiwanese power and gas companies, universities and a multinational nongovernmental organisation. Being scanned does not mean every named organisation suffered a successful intrusion.
FishHub played a different alleged role. Authorities say it facilitated spear-phishing attacks and, after an initial breach, delivered malware that could give unauthorised access or collect selected files. The Justice Department says about 20 Taiwanese universities were confirmed victims of activity involving that tool. It also says it seized domains associated with the platforms. The filings describe allegations and investigative findings, not a conviction of the company or everyone associated with it.
What makes this story important is the industrialisation of cyber operations. A compromised household router or camera can become part of a system for scanning other organisations. A malicious email can then become an entry point for a more targeted attack. The same chain can cross borders quickly, so a network defender in one country may face infrastructure and tooling assembled somewhere else.
US officials connect the activity to the group known as Flax Typhoon and say Integrity Technology Group has contracts with China’s government. China has long disputed US accusations that it backs cyberattacks. The public evidence here is the Justice Department’s seizure announcement and court material; readers should keep that attribution in mind, particularly when claims about state sponsorship go beyond the technical facts of a compromised device or seized domain.
This is not the first US action against the company. The Justice Department said it disrupted an Integrity Tech botnet in 2024 that involved more than 200,000 consumer devices worldwide. The new seizures suggest the authorities see the company’s capability to rebuild or shift platforms as an ongoing concern. An accompanying advisory gives defenders indicators they can check against their own logs, but the absence of a match would not by itself prove a network is safe.
TechBooky previously examined reports of China-linked cyber activity against Taiwan. This case has a different evidentiary basis: US court-authorised seizures and a named company. For organisations running critical infrastructure, the practical lesson is familiar but urgent. Keep internet-facing devices patched, restrict remote access, train staff against targeted phishing and investigate unusual scanning before it becomes a foothold. Taking tools offline may slow an attacker; it does not replace that defensive work.







