- The Justice Department seized websites behind two hacking tools, Microscan and FishHub. Officials say Beijing-based Integrity Tech built them for China-linked hackers.
- The FBI says China relies on contractors to widen its reach. CISA and the NSA say the group favored edge devices that few teams watch.
- Leaders should ask who watches their edge devices and mail servers, and whether they would notice quiet scanning or password guessing.
Before an intruder breaks in, someone has to find out which doors are unlocked. This week, U.S. officials went after a company that built tools for that job.
The Justice Department seized multiple websites that underpin two hacking tools, Microscan and FishHub. The Record reported that Integrity Tech, a Beijing-based security company, built them. It says China's Ministry of State Security hired the firm. Agencies in several countries took part in the wider action.
The tools are tied to Flax Typhoon. Microsoft researchers first described that campaign publicly in 2023.
The attack now has a supplier
FBI Assistant Director Brett Leatherman put the problem in one line: "The PRC relies on contractors and enabling companies to expand the reach and scale of its malicious cyber activity."
That sentence is the story. The lesson here is that scouting, phishing and password guessing can be built and sold like products. A state does not need every skill in-house if a company will make the tools and keep them running.
For a defender, that changes the picture. You may not face one crew with one trick. You may face a toolset that several groups can use. The Record reports that Integrity Tech acquired, sold or hosted tools for more than one group.
What the two tools did
Court documents and advisories, as cited by The Record, say Integrity Tech built Microscan for reconnaissance. It runs scripts that check websites for specific weaknesses. It has been in use since 2017.
Named victims of the scanning include a South Carolina power company and airports in Japan and Poland. They also include Taiwanese natural gas and power companies. A scan that finds nothing leaves little behind, so this kind of activity is easy to miss.
FishHub was built to speed up phishing. The Record reports it also let hackers place malware on a victim's network after a breach. Authorities said its remote access was used against about 20 universities in Taiwan.
Why edge devices keep coming up
CISA and the NSA said the group went after edge devices that get little attention. Those devices let the hackers stay inside a network for a long time without being seen.
Edge devices sit where a network meets the internet. In 2024, then-FBI Director Christopher Wray said the group grew skilled at infecting internet-connected hardware. He named cameras, video recorders and storage devices.
That is a budget problem as much as a technical one. Few teams own these devices from end to end. Few run security tools on them. They can fall out of patching, logging and review.
The advisory also describes EBurst. This tool targets email accounts on Microsoft Exchange servers. It uses password spraying, which tries common passwords across many accounts. It also uses plain password guessing.
The agencies listed victims of email theft. They included government bodies, law enforcement, healthcare systems and religious institutions in Southeast Asia. In some cases, the stolen data could be reached only from IP addresses in Xiamen, China.
A seized website is not a cleaned network
U.S. agencies have used sanctions and takedowns against Integrity Tech for three years, The Record reports. In September 2024, the DOJ disrupted its botnet. The FBI used a court order to remove the malware from infected devices.
The new advisory runs 58 pages. It covers tools Chinese actors have used over six years. The FBI built it from incident response investigations at affected organizations.
The reporting does not say how many organizations remain compromised. A seized website does not by itself remove an intruder who is already inside a network.
CISA's Chris Butera said Chinese government hackers "continue to position themselves within critical infrastructure networks." That is the agency's assessment. It is not a finding from the seizure.
Questions for your security team
Start with the edge. Ask for a list of every internet-facing device, including cameras, recorders and storage. Ask who owns each one and who reads its logs.
Ask whether anyone would notice slow, patient scanning of your websites. Ask whether failed logins on any on-premise Exchange server raise an alert. Ask whether password spraying would stand out.
Have the team read the advisory's technical details and check them against your logs.
Finally, ask about your own suppliers. Attackers can buy their toolkit from a contractor. Defenders should know just as well who sits behind their own tools.
A company built these tools. Defence is built by choices: who watches the edge, and who is paid to look.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Record.





