US Disrupts China-Linked Integrity Tech ‘s Cyber Espionage Tools
US authorities seized China-linked Integrity Tech tools Microscan and FishHub used to hack critical infrastructure.
The US Justice Department and FBI seized Microscan and FishHub, tools operated by Beijing-based Integrity Technology Group, which holds Chinese government contracts. Microscan, reachable via c0cc.cc and active since at least 2017, ran more than 1,300 scripts against weaknesses in OpenSSL, WordPress, Jenkins, and Apache Struts, backed by a Mirai IoT botnet whose June 2024 database listed over 1.2 million devices, including more than 385,000 in the United States. FishHub used spear-phishing against about 20 Taiwanese universities to deliver malware, grant remote access, or steal files. Researchers link the company to Flax Typhoon, also called Ethereal Panda and RedJuliett, and agencies from seven countries issued a joint advisory; the same week the State Department offered $10 million for information on Zhang Yu of Silk Typhoon.