Back Ibtimes.Sg US Seizes 7 Domains Linked to Chinese Hackers: 250000 Wi
The U.S. government seized seven internet domains on Oct. 8 that authorities say were used in hacking operations linked to Beijing-based Integrity Technology Group. The domains supported two tools, MicroScan and FishHub, that investigators say were used to scan networks and conduct spear-phishing attacks.
The seizure targets infrastructure associated with the alleged hacking activity. It does not mean the government has removed the more than 200,000 compromised devices associated with an earlier Flax Typhoon botnet disruption in September 2024. That figure describes the earlier operation, not the number of devices affected by the latest seizure.
FBI Seizes 7 Domains Linked to MicroScan and FishHub Hacking Tools
"Today the Justice Department and FBI announced court-authorized seizures to deny malicious cyber actors access to two hacking tools, 'Microscan' and 'FishHub,' used to scan and, in some cases, compromise U.S. and foreign critical infrastructure," the Justice Department said on Oct. 8, 2026. A court in the Western District of Pennsylvania authorized the seizure. Visitors to the affected domains now encounter notices indicating that the FBI has taken control of them.
The operation follows U.S. allegations that Integrity Technology Group has supported cyber activity associated with Flax Typhoon , a China-linked hacking group. The company has held contracts with the Chinese government, according to U.S. authorities.
The Justice Department said the accompanying advisory "provides indicators-of-compromise associated with Integrity Tech intrusion activity and is designed to help network defenders identify and respond to Integrity Tech's malicious activity." The participating agencies include counterparts in the UK, Australia, Canada, Japan, New Zealand and Spain.
"Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure," FBI Cyber Division Assistant Director Brett Leatherman said.
Flax Typhoon Botnet Infected More Than 200,000 Devices in 2024
"The Department of Justice today announced a court-authorized law enforcement operation that disrupted a botnet consisting of more than 200,000 consumer devices in the United States and worldwide," the department said on Sept. 18, 2024. The devices included routers, internet-connected cameras and network-attached storage equipment. half were reported to be in the U.S.
The U.S. Treasury Department sanctioned Integrity Technology Group in January 2025 and cited more than 260,000 compromised devices in its account of the activity. That number belongs to the earlier botnet and sanctions history; it is not a count of devices affected by the Oct. 8 domain seizure.
The figures describe related allegations and operations, but they measure different things. The latest announcement concerns seven domains connected to two hacking tools. The larger device counts refer to the previously identified botnet.
How to Protect Your Router, Security Camera and Other Connected Devices
Start by checking whether your router, internet-connected camera or network-attached storage device is still receiving security updates. Install available firmware updates and replace equipment that its manufacturer no longer supports.
Change default administrator passwords and disable remote administration if you do not need to access your device from outside your network. These steps can reduce exposure to attacks that target internet-connected equipment.
Organizations should also review advisory AA26-281A from the FBI, CISA, NSA and international partners. Its technical indicators and mitigation guidance can help security teams check whether their networks contain affected systems or show signs of related activity.
The FBI's seizure of seven domains disrupts part of the infrastructure linked to the alleged hacking operations. It does not confirm that previously compromised devices have been cleaned or that the operators cannot establish replacement infrastructure.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
