Particle.news

U.S. Seizes Domains That Disabled China‑Linked Hacking Tools Microscan and FishHub

The seizures aim to deny operators the scanning, phishing, data‑exfiltration infrastructure used to target critical networks.

Overview

  • The Justice Department and FBI obtained court authorization in the Western District of Pennsylvania and on Oct. 8, 2026 seized seven domains that now display FBI notices and have rendered Microscan and FishHub inoperable.
  • Microscan is a large Python‑based vulnerability scanner that investigators say was paired with a Mirai‑variant botnet of infected internet‑connected devices to locate flaws in targets such as a South Carolina power company and airports in Japan and Poland.
  • FishHub was used to run spear‑phishing campaigns that delivered malware for remote access and data theft, and FBI investigators recovered files from more than 20 organizations on a FishHub‑linked server, including six universities in Taiwan.
  • The FBI, CISA, and NSA issued a joint advisory that published indicators of compromise, detailed commonly exploited vulnerabilities and tools, and urged organizations to patch systems, disable exposed services, and enforce multifactor authentication.
  • Officials framed the action as a continuity of disruption efforts against Integrity Technology Group and the Flax Typhoon campaign, citing a prior September 2024 botnet takedown and saying they will monitor attempts to rebuild infrastructure and limit the actors' operational reach.