Overview
- The Justice Department and FBI executed court‑authorized seizures of seven domains on Thursday to deny access to the MicroScan vulnerability scanner and the FishHub spear‑phishing platform, and they say the actions rendered both platforms inoperable.
- U.S. agencies attribute the tools and infrastructure to Integrity Technology Group, a Beijing‑based contractor linked to the Flax Typhoon threat cluster that has been sanctioned by the U.S., U.K., and EU and previously had a Mirai‑variant IoT botnet disrupted in 2024.
- MicroScan is a Python‑based web scanner with more than 1,300 penetration‑testing scripts that investigators say used a Mirai‑style botnet to distribute large‑scale probing, and FishHub was used to deliver malware, give remote access, and exfiltrate files from victims.
- Authorities published a joint advisory with CISA, NSA and allied partners that includes IPs, domains, malware hashes, and step‑by‑step mitigations such as patching, disabling unused services, enforcing multifactor authentication, and hunting for the supplied indicators of compromise.
- Network defenders are urged to search historical logs for MicroScan probes, FishHub delivery domains and SoftEther VPN persistence, because officials warn they will monitor for attempts to reconstitute the infrastructure and that disruption does not end the broader campaign.