FBI Seizes Seven Domains Supporting Flax Typhoon Scanning and Malware Operations

FBI seized domains allegedly supporting MicroScan and FishHub scanning and malware platforms attributed to China-linked Flax Typhoon operators.

FBI Seizes Seven Domains Supporting Flax Typhoon Scanning and Malware Operations
APT

Illustrative image generated with AI

A US law-enforcement operation has seized seven domains allegedly used to support MicroScan and FishHub, two cyberattack platforms attributed to China-linked operators tracked as Flax Typhoon.

The action was reported by BleepingComputer on October 8, 2026, at 05:42 PM. The available material does not specify when the FBI completed the seizures or when authorities issued the associated joint advisory.

US authorities linked the platforms to Integrity Technology Group, also known as Integrity Tech, a China-based company they say holds Chinese government contracts. The advisory nevertheless cautions that not every reported activity can be attributed to Integrity Tech.

Seven domains supported scanning, malware delivery and remote access

The FBI seized c0cc.cc, which investigators associated with access to the MicroScan platform. Law enforcement reportedly verified that the domain remained online in September 2026.

Five additional domains allegedly delivered malware:

  • 98aicai.com
  • 98aicode.com
  • outlook3650.com
  • youtubecard.com
  • linkedinns.net

The seventh domain, 98aiblog.com, was associated with SoftEther VPN software installed on compromised systems to preserve remote access.

According to the report, the domains displayed FBI seizure notices naming Flax Typhoon and Integrity Tech. The seizures disable specific infrastructure, but the available evidence does not establish that the operation eliminated every system or account connected with the activity.

The Department of Justice said the two platforms supported broad vulnerability scanning and, in some cases, intrusions into US and foreign critical infrastructure. Brett Leatherman, assistant director of the FBI Cyber Division, characterized contractors and private companies as a means by which the Chinese government expands its cyber capabilities.

The activity overlaps with clusters tracked as Flax Typhoon, Ethereal Panda and Red Juliett. These names describe observed activity sets and do not, by themselves, prove that one organization conducted every operation covered by the advisory.

MicroScan combined exploit scripts with a Mirai botnet

The joint advisory describes MicroScan as a Python-based vulnerability scanner containing more than 1,300 penetration-testing scripts. Operators used it to identify weaknesses in websites and exposed services, including Oracle WebLogic, Apache Struts, WordPress and Jenkins installations.

An FBI seizure affidavit, as summarized in the report, says MicroScan worked alongside a botnet of internet-connected devices infected with Mirai malware. Those devices supplied distributed scanning capacity for identifying possible targets.

Named targets included a South Carolina power company, airports in Japan and Poland, Taiwanese natural-gas and electricity providers, and universities. The FBI confirmed that the tools were involved in critical-infrastructure intrusions, but did not say that every named organization was successfully compromised.

The affidavit provides a more definite account for two Taiwanese universities. Their networks were scanned with MicroScan in August 2022 and March 2023, respectively, and were subsequently breached. It does not provide the dates of those intrusions.

This distinction matters: a scanning event shows that infrastructure was examined, not that exploitation succeeded. Only the two university cases are specifically described as breaches following MicroScan activity.

FishHub handled phishing, access and stolen information

FishHub served a different role. According to the advisory, operators used it for spear-phishing and for delivering additional malware into networks that had already been compromised.

The deployed malware reportedly enabled unauthorized remote access, searches for selected files and exfiltration to Integrity Tech-controlled servers. Investigators also found a custom web application through which third parties could browse stolen emails without signing directly into the compromised accounts.

An FBI affidavit reportedly says a FishHub-linked server contained files and data belonging to more than 20 organizations, including six Taiwanese universities. That figure counts organizations represented in the recovered material, not affected individuals.

Other elements of the toolkit included the open-source EBurst utility, used for password spraying against Microsoft Exchange. Additional tools stole email, collected Active Directory credentials and transferred data outside victim networks.

The advisory identifies targeting of US government bodies and organizations in critical manufacturing, healthcare, information technology, law enforcement, education and religious sectors. It also covers operations against organizations in Southeast Asia, Africa and North America. The available reporting does not quantify the total number of successful compromises.

Eight recurring vulnerabilities span web servers, VPNs and developer platforms

The advisory lists eight vulnerabilities as commonly targeted. Their technical impact varies considerably:

Vulnerability Product and reported impact CVSS v3
CVE-2015-3306 ProFTPD 1.3.5 mod_copy permits remote arbitrary file reads and writes through site cpfr and site cpto. 10
CVE-2015-5477 ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 can be crashed remotely using TKEY queries. 7.5
CVE-2016-3081 Apache Struts 2.3.19–2.3.20.2, 2.3.21–2.3.24.1 and 2.3.25–2.3.28 permit code execution through the method: prefix when Dynamic Method Invocation is enabled. 8.1
CVE-2021-3199 ONLYOFFICE Document Server before 5.6.3 can allow directory traversal and remote code execution through /upload when JWT is used. 9.8
CVE-2023-22894 Strapi allows an admin-panel user to infer sensitive information through query filtering. Super-admin access can expose password hashes and reset tokens. 4.9
CVE-2014-6278 GNU Bash through 4.3 bash43-026 can execute commands supplied through crafted environment variables, including in some CGI, OpenSSH and DHCP-related contexts. 8.8
CVE-2019-11510 Pulse Connect Secure 8.2 before 8.2R12.1, 8.3 before 8.3R7.1 and 9.0 before 9.0R3.4 permit unauthenticated arbitrary file reads. 10
CVE-2021-22205 GitLab CE/EE from version 11.9 improperly validates images passed to a file parser, enabling remote command execution. 10

For CVE-2023-22894, one supplied affected-product field covers Strapi versions earlier than 4.8.0, while the NVD description says “through 4.5.5.” Defenders should therefore rely on the vendor’s applicable remediation guidance rather than resolving that discrepancy by assumption.

CVE-2014-6278 resulted from an incomplete correction for CVE-2014-6271, CVE-2014-7169 and CVE-2014-6277. Its CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.

Three listed flaws have documented exploitation in CISA’s KEV catalog

CVE-2014-6278 entered CISA’s Known Exploited Vulnerabilities catalog on October 2, 2025. The federal remediation deadline was October 23, 2025. CISA’s prescribed action is: “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.”

Two other vulnerabilities on the advisory’s list have older KEV records and documented ransomware use:

  • CVE-2021-22205 entered KEV on November 3, 2021, with a federal deadline of November 17, 2021. CISA requires updates according to vendor instructions.
  • CVE-2019-11510 entered KEV on November 3, 2021, with a federal deadline of May 3, 2022. CISA likewise requires vendor updates.

Verified archive data flags both vulnerabilities as used in ransomware campaigns. This does not mean ransomware was part of the Flax Typhoon activity described here; it is separate operational context showing that the same flaws have been exploited by other threat actors.

The archive also records CVE-2026-85706 as entering KEV on September 11, 2026, in recent vendor-related context involving GNU, GitLab and Ivanti. That record does not establish a connection to the seized infrastructure.

Defenders should search for evidence before treating patching as sufficient

The joint advisory reportedly provides IP addresses, domains, malware hashes and details about attacker tools. Organizations should compare those indicators with DNS, proxy, endpoint, authentication and network records, while treating the seven seized domains as investigation leads rather than proof of compromise.

Authorities also recommend patching vulnerable systems, disabling exposed services that are not required and enforcing multifactor authentication. Internet-facing Exchange, GitLab, Pulse Connect Secure, Apache Struts, ProFTPD, BIND, ONLYOFFICE, Strapi and Bash-dependent services warrant particular review where the listed versions or conditions apply.

Investigators should also look for password-spraying activity against Microsoft Exchange, unexpected SoftEther VPN installations, unauthorized Active Directory credential access and unusual outbound transfers.

The disruption follows an earlier US operation against an Integrity Tech-operated Mirai botnet in September 2024. That botnet reportedly contained more than 200,000 compromised consumer devices worldwide. The UK sanctioned Integrity Tech in 2025, while the European Union imposed sanctions in 2026 over alleged involvement in cyberattacks against Europe and its allies.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →