Overview
- Federal prosecutors and the FBI obtained court authorization to seize seven domains used to run the Microscan vulnerability scanner and the FishHub spearphishing platform, an action unsealed Thursday that placed FBI seizure notices on the sites.
- U.S. agencies say the tools were operated by Integrity Technology Group, a Beijing-based contractor the government links to the threat actor tracked as Flax Typhoon and to Chinese government customers.
- Investigators allege Microscan worked with a Mirai-variant IoT botnet to probe targets and that FishHub delivered malware that granted remote access and enabled file theft from victim networks.
- The seizure affidavit and agencies report confirm Microscan probes targeted U.S. and foreign critical infrastructure including a South Carolina power company and airports in Japan and Poland, and that FishHub-linked servers held data from more than 20 organizations including multiple Taiwanese universities.
- The FBI, CISA and NSA issued a joint advisory with indicators of compromise and step-by-step defenses such as patching, disabling exposed services, enforcing multifactor authentication, hunting listed IoCs, and isolating IoT devices to limit rebuilding or migration of the tools.