FBI seizes seven tool domains as allies warn of Integrity Tech
On 8 October 2026, US and allied agencies warned Integrity Technology enabled China-linked data theft and reported FBI seizures of related tool domains.
On 8 October 2026, the UK NCSC and agencies from Australia, Canada, Japan, New Zealand, Spain, and the United States issued a joint advisory naming China-based Integrity Technology Group as enabling China-linked intrusions that steal sensitive data, including from critical sectors. NCSC said the actors use scanning, large botnets, and hands-on exploitation consistent with Flax Typhoon, Ethereal Panda, and Red Juliett, noted that the UK sanctioned the company last year, and urged organizations to apply mitigations in an FBI-hosted advisory. The Record and CyberScoop reported Justice Department and FBI seizures of sites for Microscan, described as a vulnerability scanner, and FishHub, a spearphishing tool that delivers malware; CyberScoop said a Western District of Pennsylvania court authorized the seizures, while The Register reported seven domains were seized. A 58-page advisory, as reported by The Record, says Microscan has scanned since 2017, FishHub enabled phishing and malware delivery, and EBurst password-sprayed Microsoft Exchange accounts to steal email from universities, government, telecommunications, media, and critical infrastructure. CyberScoop, citing FBI, CISA, and NSA, added cross-site scripting, VPN persistence, and credential theft, and said a Mirai-variant IoT botnet supported Microscan against a South Carolina power company, airports in Japan and Poland, and universities in Taiwan. Sources disagree on details: only NCSC called scanning AI-assisted, only The Record said the firm was hired by China's Ministry of State Security and that the FBI disrupted a Mirai botnet of more than 260,000 devices in September 2024, and The Register alone reported that CISA added CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, and CVE-2023-22894 to the KEV catalog.
- On 8 October 2026, agencies from the UK, Australia, Canada, Japan, New Zealand, Spain, and the United States named China-based Integrity Technology Group in a joint advisory on China-linked theft of sensitive data, including from critical…
- NCSC said the activity uses scanning, large botnets, and hands-on exploitation consistent with Flax Typhoon, Ethereal Panda, and Red Juliett, noted the UK sanctioned the company last year, and urged use of mitigations in an FBI-hosted…
- The Record and CyberScoop reported DOJ and FBI seizures of Microscan and FishHub sites; CyberScoop said a Western District of Pennsylvania court authorized them, and The Register said the FBI seized seven domains.
Coverage timelineoldest first · each row is one article
- · 10h agoChina-linked malicious actors called out by UK and international partners for targeting sensitive data globally
NCSC UK· 76
UK and partners attribute global data theft to China-linked Integrity Technology Group and Flax Typhoon-related activity.
- · 3h agoInternational coalition seizes tools used by cyber firm behind Flax Typhoon
The Record· 80
A US-led coalition seized Flax Typhoon tools Microscan and FishHub operated by China's Integrity Tech.
- · 2h ago
Vulnerabilities in this storyAll →
- CVE-2015-330610.097%Arbitrary file read/write via ProFTPD 1.3.5 mod_copypublished · ProFTPD KEV PoC ×2