Integrity Technology Group's Microscan and FishHub Tools Abused by Flax Typhoon APT
In October 2026, law‑enforcement seized the infrastructure of Integrity Technology Group, a Shanghai‑listed firm that operated MicroScan—a Mirai‑variant IoT botnet vulnerability scanner with >1,300 penetration‑testing scripts—and FishHub, a spear‑phishing platform that harvested Exchange Web Services mail via a custom PHP bot and hosted a browsable web portal for stolen email. The tools enabled credential‑spraying against Microsoft 365/Exchange, persistence via SoftEther VPN clients masquerading as legitimate Windows processes, and large‑scale scanning of government, healthcare, critical‑infrastructure, and educational targets across North America, Europe, Asia, and Africa. The disruption halted ongoing data exfiltration but defenders must assume reconstitution risk and enforce patching, MFA, and EWS monitoring.
-
Incident/Breach Overview
- Coordinated takedown by FBI, DOJ, CISA, NSA, and international partners (UK, AUS, CAN, JPN, NZ, ESP) seized seven domains including c0cc.cc.
- Operation exposed a multi‑year campaign active since at least 2021 targeting power companies, universities, hospitals, law‑enforcement, NGOs, and religious institutions.
- Over 20 Taiwanese universities and multiple U.S. critical‑infrastructure entities were scanned or compromised.
- MicroScan botnet comprised hundreds of thousands of hijacked IoT devices; FishHub indexed exfiltrated email for third‑party access.
-
Attack Vector/Campaign Mechanics
- MicroScan leveraged a Mirai‑based botnet to run automated vulnerability scans using >1,300 custom scripts against exposed IoT and edge devices.
- FishHub deployed spear‑phishing lures delivering malicious links; successful clicks triggered a PHP bot that pulled mail via Exchange Web Services (EWS) and stored it in a searchable web app.
- Credential‑spraying scripts targeted Microsoft 365/Exchange accounts, employing low‑and‑slow password guessing to evade lockouts.
- Post‑exploitation persistence achieved by installing SoftEther VPN clients and disguising them as legitimate Windows services (e.g., svchost.exe mimics).
-
Threat Group Profile/Scale of Impact
- Flax Typhoon (also tracked as Ethereal Panda, RedJuliett) operates as a Chinese state‑sponsored APT with commercial front‑end cover via Integrity Technology Group.
- Campaign scope spans North America, Europe, Asia, and Africa, affecting government agencies, healthcare, critical infrastructure, education, and NGOs.
- Impact includes exfiltration of email archives, potential credential harvesting for further lateral movement, and IoT‑based scanning capacity used to identify additional victims.
- Linked historically to the Raptor Train botnet (>200k compromised routers/IP cameras/NAS), indicating recycled infrastructure.
-
Indicators of Compromise (IoCs)/Defensive Actions
- Domains: c0cc.cc and six additional seized domains; monitor for any re‑registration or similar naming patterns.
- File artifacts: SoftEther VPN executables with atypical command‑line arguments; custom PHP mail‑harvesting scripts; Mirai variant binaries.
- Network signals: Unusual EWS traffic (elevated EWS GetItem, FindItem requests) from internal hosts; spikes in outbound SMTP or HTTP to suspicious domains.
- Mitigation: Enforce MFA on all Microsoft 365/Exchange accounts, patch IoT firmware, disable unused services, monitor VPN client creation, and block traffic to known C2 domains.
- Recommendation: Deploy EWS anomaly detection, credential‑spraying throttling, and IoT network segmentation.
-
Conclusion
- The seizure disrupts a significant APT toolset but does not eradicate the threat; Flax Typhoon retains reconstitution capability through residual infrastructure and alternative C2 channels.
- Organizations must treat the incident as an ongoing risk, prioritize hardening of Exchange environments, maintain rigorous IoT device management, and integrate threat‑intel feeds for the identified IoCs.
- Continued collaboration between government agencies and private sector defenders remains essential to counter similar commercial‑front APT operations.
Related posts
- DEV Community — Flax Typhoon Unmasked: Inside the FBI's Global Takedown of China's Hacking-for-Hire Empire
- cyberscoop.com — DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub
- Nextgov
- Seguridadpy
- Ic3
- thehackernews.com — FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions
- Cyberscoop
- Justice
- Clickorlando