Skip to content
FBI Seizes Domains and Tools Used by Chinese Hackers

FBI Seizes Domains and Tools Used by Chinese Hackers

First seen 10 Oct 2026, 16:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 10, 2026 at 21:32 UTC
  • •FBI seized seven domains linked to Chinese hackers on October 8, 2026.
  • •The tools MicroScan and FishHub were used for scanning and phishing attacks.
  • •The operation is part of ongoing efforts against the Flax Typhoon hacking group.

On October 8, 2026, the FBI and Justice Department seized seven domains linked to Chinese hackers associated with Integrity Technology Group, which allegedly provided tools for cyber operations targeting critical infrastructure. The seized tools, MicroScan and FishHub, were used for network scanning and spear-phishing attacks against U.S. and foreign entities, including power companies and universities. This operation follows previous disruptions of the Flax Typhoon botnet, which infected over 200,000 devices in September 2024. The seizure aims to disrupt the hackers' capabilities, although the compromised devices remain unaffected. The FBI has indicated that the operation is part of a broader strategy to target malicious cyber actors linked to state-sponsored activities. The Chinese government has denied the allegations, calling them politically motivated.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-09-18
Flax Typhoon botnet disrupted
FBI announced disruption of a botnet with over 200,000 infected devices, including routers and cameras.
Ibtimes.Sg
2026-10-08
FBI seizes domains and tools
Seven domains linked to Integrity Technology Group were seized, disrupting tools used for cyber operations.
Thebusinessjournal

More articles in this cluster (4)

Following this threat?

Track Flax Typhoon, Flax Typhoon Botnet and Integrity Technology Group in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are the tools involved?
The tools seized are MicroScan and FishHub, used for network scanning and phishing.
Who is affected by these operations?
Entities in the U.S. and abroad, including power companies and universities, are affected.
What should organizations do now?
Organizations should review their network defenses and monitor for any signs of compromise related to these tools.