BREAKING · NATION-STATE / EMAIL

DOJ seized Integrity Tech's Microscan and FishHub. Same day, CISA dropped the Flax Typhoon enablement playbook

On Oct 8 the Justice Department and FBI announced court-authorized seizures of two hacking tools, Microscan and FishHub, that China-based Integrity Technology Group operated for clients tied to PRC state-sponsored activity the U.S. associates with Flax Typhoon. The same day, CISA, FBI, NSA and partners in the UK, Australia, Canada, Japan, New Zealand and Spain published joint advisory AA26-281A on how Integrity Tech-enabled actors scan, spray Exchange and Microsoft 365, install SoftEther for persistence, and run a web app that gives third parties access to stolen email. Overall breached-organization count: Undisclosed.

Oct 8, 2026 · 3 min read

What got seized. Per DOJ court filings in the Western District of Pennsylvania, Integrity Tech built Microscan as a vulnerability-scanning front end fed by a Mirai-variant IoT botnet and by other recon. Targets of that scanning include a U.S. power company in South Carolina, a multinational NGO, Japanese and Polish airports, Taiwanese natural-gas and power companies, and two Taiwanese universities. Operators reached Microscan through seized domain c0cc.cc. FishHub handled post-compromise spear-phish delivery: more malware for remote access or for pulling specific files to Integrity Tech servers. Confirmed FishHub victims: about 20 Taiwanese universities. Five FishHub delivery domains seized: 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, and linkedinns.net. DOJ says Integrity Tech has contracts with the PRC government. This is the department’s second public technical disruption of the firm after the September 2024 takedown of a Mirai botnet of more than 200,000 consumer devices.

What the advisory actually teaches operators. AA26-281A is the hunt sheet. Actors enabled by Integrity Tech use TTPs consistent with activity tracked publicly as Flax Typhoon, Ethereal Panda and Red Juliett (the agencies note those labels are not always 1:1 with U.S. government tracking). Initial access mixes open-source scanners, MicroScan’s 1,300+ scripts, XSS credential-harvest pages that drop live700_v1.exe / DiagTrack.exe, and EBurst password spraying against Exchange interfaces (ECP, EWS, OAB, OWA, RPC, MAPI, PowerShell, Autodiscover, ActiveSync). Persistence is often SoftEther VPN, renamed to look like conhost.exe or dllhost.exe and set to reconnect on boot. Credential theft includes DCSync via DC.exe. Email collection uses a PHP bot (Curlc4.txt) over EWS and a recurring office-cli pull against Microsoft 365 using client ID, tenant ID and secret. Some stolen mail was restricted to Xiamen, China IP ranges. The advisory lists eight successfully exploited CVEs recovered from their scripts, including Pulse Connect Secure CVE-2019-11510 and GitLab CVE-2021-22205. Treat “newly added to KEV” claims carefully until they show in CISA’s published catalog.

Why enterprise buyers should care this afternoon. This is not a consumer-gadget story. The named Microscan targets sit in power, airports and NGOs. The advisory’s U.S. focus sectors are government services, critical manufacturing, healthcare and IT, plus law enforcement, education and religious orgs. If you run on-prem Exchange or hybrid M365 with weak MFA on those spray surfaces, or SoftEther that nobody inventory-owns, you are in the blast radius the agencies wrote for. Pull the STIX IOCs, hunt SoftEther and unexpected AD replication, lock MFA on every Exchange path EBurst can hit, and ask your MSSP whether they already alert on SoftEther installers masquerading as Windows system binaries.

What we still don’t know. Total organizations compromised worldwide: Undisclosed. Identity of the third parties using the stolen-email portal: Undisclosed. Whether FishHub’s ~20 Taiwanese universities overlap the Microscan university targets: not stated. Integrity Tech rejected U.S. sanctions claims in January 2025 filings cited by secondary press; the company’s response to today’s seizures: not in the DOJ release we reviewed.

Desk sheet: DOJ/FBI seizures Oct 8, 2026 (W.D. Pa.); tools Microscan + FishHub; Integrity Technology Group; Flax Typhoon association per DOJ; CISA AA26-281A same day with FBI/NSA and six partner agencies; SoftEther, EBurst, EWS/office-cli email theft; third-party email portal; overall victim count Undisclosed; FishHub ~20 Taiwanese universities; prior Sep 2024 200k+ device botnet disruption.

Sources