October 8, 2026

International coalition seizes tools used by cyber firm behind Flax Typhoon

The U.S. and other nations took down digital tools and infrastructure by Beijing-based Integrity Tech that allowed “widespread vulnerability scanning and, in some cases, intrusions” as part of the Flax Typhoon campaign.

International coalition seizes tools used by cyber firm behind Flax Typhoon

Cybersecurity agencies in several countries partnered to take down tools used by state-backed hackers in China to attack critical infrastructure organizations.

The actions targeted Integrity Tech, a prominent Chinese cybersecurity company hired by the People’s Republic of China’s (PRC) Ministry of State Security to assist in attacks on universities, government agencies, telecommunications providers and media organizations globally.

“Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure,” FBI Assistant Director Brett Leatherman said Thursday. 

“The PRC relies on contractors and enabling companies to expand the reach and scale of its malicious cyber activity.”

The Justice Department seized multiple websites underpinning two powerful hacking tools known as “Microscan” and “FishHub.” U.S. officials published a 58-page advisory on the tools and others that Chinese actors have used over the last six years as part of a long-running campaign known as Flax Typhoon. 

Beijing-based Integrity Tech uses an array of automated scanning tools, botnets and hands-on-keyboard techniques to steal sensitive data from organizations.

Court documents and advisories explained that Integrity Tech built Microscan to conduct reconnaissance for vulnerabilities that could be exploited by Chinese hackers. Victims of the scanning tool include a South Carolina power company, Japanese and Polish airports, Taiwanese critical infrastructure companies in the natural gas and power sectors and more.

MicroScan has been used since 2017 for penetration testing scripts written to scan websites for specific vulnerabilities.

FishHub was another tool Integrity Tech created to expedite the process of conducting phishing attacks. It allowed hackers to download malware onto a victim’s network after it had been breached.

The remote access offered by FishHub was used specifically against about 20 universities in Taiwan, authorities said.

‘Breadth of sectors’

The technical advisory was borne from multiple incident response investigations conducted by the FBI on organizations that had been attacked by Integrity Tech or other Chinese groups that used their tools.

The Cybersecurity and Infrastructure Security Agency (CISA) and The National Security Agency (NSA) said the company typically targeted edge devices that are not closely monitored because they allowed the hackers to maintain long-term, secret access to an organization.

CISA’s acting executive assistant director for cybersecurity, Chris Butera, said Chinese government hackers “continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing.”

The countries that contributed to the advisory include Australia, Japan, the U.K., Spain, New Zealand and Canada.

Paul Chichester, director of operations at the U.K.’s National Cyber Security Centre, said the “breadth of sectors that have been targeted across the globe demonstrate the extent of the threat.”

Integrity Tech is a key cog in China’s web of hacking campaigns — acquiring, selling or hosting tools used by several groups to steal sensitive data and more.  

Some tools, like EBurst, are used to target compromised email accounts on Microsoft Exchange servers using multiple interfaces for password spraying and password guessing. Others are designed to access emails, calendars and contact.

“The FBI recovered an archived email database the threat actors used to target email accounts of victim organizations. The threat actors collect account credentials and exfiltrate victim email data from on-premise systems and cloud-based services,” the agencies said.

“Observed victims of email data theft included government organizations, law enforcement agencies, healthcare systems, and religious institutions located in Southeast Asia. In some instances, the threat actors restricted access to the exfiltrated data to only IP addresses from Xiamen, China.”

Known entity

U.S. agencies have repeatedly targeted Integrity Tech with sanctions and takedown efforts over the last three years as concern has grown over its involvement in the Flax Typhoon attacks, which were initially identified publicly by researchers from Microsoft in 2023. 

In September 2024, the DOJ disrupted Integrity Tech’s Mirai-based botnet, which consisted of more than 260,000 consumer devices. The FBI used a court authorization to remove the malware from infected devices and take control of Flax Typhoon’s internet infrastructure.

The group mainly targeted government agencies and education, critical manufacturing and information technology organizations in Taiwan, but Microsoft said it also saw victims across Southeast Asia, North America and Africa.

Then-FBI Director Christopher Wray said at the time that Flax Typhoon became adept at infecting internet of things (IoT) hardware like “cameras, video recorders and storage devices — using the breaches to target “everyone from corporations and media organizations to universities and government agencies.”

Integrity Technology is best known in China for developing the country’s cyber ranges — powerful training tools that simulate real-world platforms, networks and other digital systems. The company has touted its extensive government funding in the past and experts from the Natto Thoughts research team said the company was founded in 2010 by Cai Jingjing — a legendary hacker in China.

Originally published on The Record