FBI Seizes Microscan and FishHub Domains Behind File-Theft Operations

Brendan Smith
Brendan Smith - Cybersecurity Analyst
8 Min Read
A teal network cable is disconnected beside Botnet Tools Seized, Microscan / FishHub.
Domain seizures disrupt access to the hacking tools without establishing that victim systems are clean.

The FBI and US Justice Department have seized domains supporting Microscan and FishHub, two tools used by China-linked hackers to find vulnerable networks and steal files. The October 8 announcement describes an operation against the machinery behind the intrusions: infected consumer devices helped disguise reconnaissance, while a separate delivery tool brought additional malware into compromised networks. Seizing that infrastructure interrupts access; it does not establish that affected networks have been cleaned. [1]

According to the newly unsealed court documents, the tools were operated and used by actors working for Integrity Technology Group, a China-based company with government contracts. The activity is associated with the group commonly called Flax Typhoon. The evidence spans several years; this week’s development is the domain seizure and publication of investigative findings, rather than a claim that all the attacks happened in October.

Microscan put borrowed devices between the scanner and its targets

Investigators traced a Mirai-variant botnet back to servers containing source code and documentation for its control application. Those compromised internet-of-things devices were useful for more than generating traffic: the FBI says Microscan sometimes sent vulnerability scans through the botnet to hide their origin. A request reaching an organization’s website could therefore come from someone else’s infected device instead of an obvious attacker-controlled server. [2]

Microscan itself was a web application with a login page. The affidavit says the FBI still found that page at x.c0cc[.]cc on September 9, 2026, and matched it to the interface previously recovered during a server search. Provider records connected the domain to the server infrastructure. The seized c0cc[.]cc domain was an access point for the tool, rather than the name of a vulnerable product that everyone needs to uninstall.

The accompanying joint advisory describes MicroScan as a Python-based application containing more than 1,300 penetration-testing scripts. These checked websites for particular weaknesses in services including WordPress, Jenkins, Apache Struts and Oracle WebLogic. That is the size of a script collection, not a count of newly discovered vulnerabilities or successfully breached organizations. [3]

MicroScan account dashboard with vulnerability categories and host names redacted by the publishing agencies.
MicroScan results in the dashboard published in the joint advisory, Figure 1. Host names are redacted in the source; counters describe this captured view, not a global victim count. Source: FBI, CISA, NSA and partners.

The published dashboard makes the workflow tangible: scan results were organized into a central interface, with vulnerability categories and host records. The original source redacts host names. Its counters describe that captured account view; they are not a current global victim total.

The court record connects scanning to two later intrusions

The affidavit gives two specific historical examples. A university in Hsinchu, Taiwan, was scanned around March 21, 2023; another in Puli Township was scanned around August 7, 2022. Investigators say both were compromised soon afterward. Records also showed scanning of a South Carolina power company, Japanese and Polish airports, a multinational NGO, and Taiwanese gas and electricity organizations.

Those findings need different labels. The university examples connect reconnaissance with subsequent compromise. Inclusion in the wider scanning list does not, by itself, establish that every listed organization was breached. For a defender, a suspicious scan is a reason to examine the exposed service and subsequent activity, rather than evidence of file theft on its own.

This use of other people’s devices also explains why a familiar-looking source IP is a weak basis for trust. Our account of LeakySensey’s rented router proxies describes a separate operation exploiting the same general advantage: internet traffic can borrow a compromised device’s address without its owner being the attacker.

FishHub turned delivery into a search for selected documents

FishHub served a different part of the operation. DOJ describes it as a spear-phishing tool that downloaded additional malware after an initial compromise. The affidavit’s code analysis found a download saved as a script under the victim’s temporary directory, followed by additional malicious components. Investigators identified a sequence that listed files, searched for particular documents, compressed them, and sent the selected material to an actor-controlled server.

Five domains supported that delivery: 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com and linkedinns[.]net. They are historical indicators from the investigation, shown here in non-clickable form. A recognizable service name inside a domain does not make it an official login or download destination.

DOJ reports approximately 20 Taiwanese universities as confirmed victims of FishHub activity. The important distinction is what the tool enabled after entry: selective document theft and unauthorized access, rather than merely a deceptive webpage. The announcement does not publish an authentic victim email that readers can use as a universal template for identifying this campaign.

A seized domain closes a route, not the incident

The joint advisory asks defenders to hunt for compromise, review web-application and account activity, and investigate unexpected remote access and outbound transfers. It also describes actors installing legitimate SoftEther VPN software for persistence. A legitimate program can therefore become part of unauthorized access; context and authorization matter more than the product name alone.

If an organization’s logs match the published indicators, preserve the relevant records and involve its incident-response team before removing components. Correlate the initial access, later processes and file transfers; blocking a listed domain alone leaves those questions unanswered. Review internet-facing services, patch software and firmware, restrict unused remote access, and require multifactor authentication where supported.

For home and small-office device owners, the transferable action is to keep router and camera firmware supported and disable unnecessary internet-facing administration. A Windows scan cannot establish that a router is clean. If a suspicious download actually ran on a personal Windows PC, a Gridinsoft Anti-Malware scan can help check for malicious files and persistence; it cannot recover stolen documents or replace an organization’s investigation.

The seizure targets a useful junction in the attackers’ workflow. Its value is disruption plus newly public evidence that defenders can check against their own systems—not a declaration that every previously compromised device is now safe.

References

  1. US Department of Justice, Office of Public Affairs. “Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers.” October 8, 2026. Official announcement.
  2. Federal Bureau of Investigation. Affidavit supporting domain seizure, Western District of Pennsylvania; paragraphs 29–37. Released with the October 8, 2026 announcement. Unsealed affidavit (PDF).
  3. FBI, CISA, NSA and international partners. “Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data.” Joint Cybersecurity Advisory AA26-281A, October 8, 2026; accessed October 11, 2026. Technical findings and defensive guidance (PDF).
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT, a remote access tool used in malware campaigns—helping readers make sense of the threat and work through cleanup without the extra headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?