
US seizes seven domains tied to Flax Typhoon
Justice and the FBI attribute the MicroScan and FishHub tools to Integrity Technology Group, a Chinese company; no source mentions victims in Mexico.
The US Department of Justice said on Oct. 8 that, together with the FBI, it seized the infrastructure of MicroScan, a tool for finding vulnerabilities in networks, and of FishHub, another for spear phishing, meaning emails designed to trick a specific person or organization. The announcement says they are run by hackers known as Flax Typhoon, working for Integrity Technology Group, a Chinese company with contracts with its government.
The court file was made public in the Western District of Pennsylvania. BleepingComputer counts seven seized domains, which now display FBI notices naming Flax Typhoon and Integrity Tech. Neither the announcement nor that outlet mentions victims in Mexico. The attribution to the company and the group is that of the US government: there is no independent confirmation or response from Integrity Tech.
Among the FishHub domains that distributed malware, Justice lists these five: 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com and linkedinns[.]net. According to BleepingComputer, the other two are 98aiblog[.]com, linked to a SoftEther VPN, and c0cc[.]cc, the entry point to MicroScan.
How it operated, according to Justice
Integrity Tech allegedly used a botnet of internet-of-things devices infected with a Mirai variant, the malware that turns cameras and routers into a network of remotely controlled machines. That network supported MicroScan's scans, and the company's customers then exploited the vulnerabilities found. The victims named in the announcement are:
- An electric utility in South Carolina.
- A multinational nonprofit.
- Airports in Japan and Poland.
- Taiwanese natural gas and energy companies.
- Two Taiwanese universities scanned with MicroScan and about 20 more attacked with FishHub.
It is Justice's second public action against that company's infrastructure: in September 2024 it had already dismantled a botnet of more than 200 000 consumer devices.
John A. Eisenberg, assistant attorney general for National Security, said, according to the announcement, that the United States will not allow China or its proxies to operate with impunity in cyberspace. Brett Leatherman, assistant director of the FBI's Cyber Division, said China uses contractor companies to expand its activity and that exposing them makes it harder for it to attack US networks.
Flax Typhoon is the name Microsoft and other security teams give to a cyberespionage group that, according to BleepingComputer, overlaps with Ethereal Panda and Red Juliett. The agencies say part of that activity may not be linked to Integrity Tech.
The FBI and allied agencies also published a cybersecurity advisory with indicators of compromise for defenders. This newsroom did not read it directly, so its lists of CVEs and indicators should be taken from that document.



