ai-security EN

US Disrupts Chinese State-Sponsored Hacking Tools

Government

US Disrupts Chinese State-Sponsored Hacking Tools

Flax Typhoon and other APTs used MicroScan and FishHub to scan and hack US and foreign critical infrastructure.

US Disrupts Chinese State-Sponsored Hacking Tools illustration

By

Ionut Arghire

|

October 9, 2026 (4:36 AM ET)

Chinese hacking tools disrupted by US

The United States on Thursday announced the disruption of two hacking tools used by Chinese state-sponsored threat actors in attacks against US and foreign critical infrastructure.

Built by Integrity Technology Group (Integrity Tech), MicroScan has been used for vulnerability scanning, while FishHub has enabled network intrusions via spear phishing.

Integrity Tech, the US says, used a Mirai malware variant to build an IoT botnet that facilitated MicroScan’s use for reconnaissance against victims’ networks, including a US power company, NGOs, Japanese and Polish airports, and Taiwanese critical infrastructure entities and universities.

FishHub enabled Integrity Tech’s clients to access victim networks remotely, search for specific files, and exfiltrate them. The tool has been used in attacks against at least 20 universities in Taiwan.

The US seized the domains the threat actors were using to access MicroScan and FishHub, including c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net.

In 2024, the US disrupted Integrity Tech’s Raptor Train botnet , and in 2025 sanctioned it for providing cybersecurity products to Chinese state-sponsored APTs such as Flax Typhoon. The European Union sanctioned the company in March 2026.

Advertisement. Scroll to continue reading.

A new joint advisory (PDF) from government agencies in the US, UK, Australia, Canada, Japan, New Zealand, and Spain shows that MicroScan has been active since at least 2017, targeting Apache Struts, Juniper ScreenOS, Jenkins, OpenSSL, Oracle, Rejetto HFS, WebLogic Server, WordPress, and other services.

“This Python-based web application contains over 1,300 penetration testing scripts written to scan websites for specific vulnerabilities,” the advisory reads.

The tool was mainly associated with Flax Typhoon (also known as Ethereal Panda, Red Juliett, Storm-0919, and UNC5007) activity, but Integrity Tech is believed to have been working with other Chinese APTs as well.

Flax Typhoon was also seen using BBScan, dirsearch, Fscan, ksubdomain, masscan, Nmap, OneForAll, ShuiZe, and WPScan for reconnaissance, and command-line exploit utilities and the EBurst Microsoft Exchange password spraying tool for initial access.

The threat actors deployed VPN tools such as SoftEther for persistence and downloaded databases or manually extracted data from victims’ email addresses. They also used the PHP script Curlc4.txt and command-line utility office-cli for email exfiltration, and DC.ex to extract sensitive data from Active Directory.

“The threat actors collect account credentials and exfiltrate victim email data from on-premises systems and cloud-based services. Observed victims of email data theft included government organizations, law enforcement agencies, healthcare systems, and religious institutions located in Southeast Asia. In some instances, the threat actors restricted access to the exfiltrated data to only IP addresses from Xiamen, China,” the advisory reads.

Related: US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward

Related: Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

US Disrupts Chinese State-Sponsored Hacking Tools illustration

Written By

Ionut Arghire

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

More from Ionut Arghire

Latest News

US Disrupts Chinese State-Sponsored Hacking Tools illustration

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

## Webinar: AI Is Accelerating Risk. Can Your IT Operations Keep Up?

October 14, 2026

Learn about Frontier Pace Governance: a practical approach to helping IT operations move at AI speed without sacrificing security, accountability, or operational discipline.

Register

## Virtual Event: Zero Trust & Identity Strategies Summit 2026

October 14, 2026

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Rapid7 has named Rik Ferguson as VP of Security Intelligence.

Cytactic has appointed Tim Brown as CSO.

Scott Simkin has joined Vega as CMO.

More People On The Move

Expert Insights

## AI Has Changed Attack Speed, Not Security Fundamentals

US Disrupts Chinese State-Sponsored Hacking Tools illustration

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb)

## Four Cyber Threats Harboring Big Plans for the Future

US Disrupts Chinese State-Sponsored Hacking Tools illustration

  • AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin)

## Begin at the End: How to Enable Agentic Remediation

US Disrupts Chinese State-Sponsored Hacking Tools illustration

Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael)

## “We Think the Security Control Is Working” Is No Longer Good Enough

US Disrupts Chinese State-Sponsored Hacking Tools illustration

Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar)

## This Key Will Self-Destruct: An Open Standard for Revocable API Keys

US Disrupts Chinese State-Sponsored Hacking Tools illustration

Every leaked credential should be dead, or dying, within sixty seconds of being found. Here’s a proposal to make that the default. (Matt Honea)

SecurityWeek

Security Community

Stay Intouch

About SecurityWeek

News Tips

Got a confidential news tip? We want to hear from you.

Submit Tip

Advertising

Reach a large audience of enterprise cybersecurity professionals

Contact Us

Daily Briefing Newsletter

Subscribe to the SecurityWeek Daily Briefing and get the latest content delivered to your inbox.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.