Skip to main content

FBI disrupts Chinese hacking tools used to breach critical infrastructure

0
High
Breach
Published: 10/08/2026 (10/08/2026, 21:42:51 UTC)
Source: Bleeping Computer

Description

The FBI disrupted Chinese state-sponsored hacking operations by seizing seven domains used by the Flax Typhoon group and its contractor, Integrity Technology Group. The seized infrastructure supported two hacking tools, MicroScan and FishHub, which were used to scan for vulnerabilities, breach critical infrastructure, and conduct spear-phishing attacks globally. The tools targeted organizations including power companies, airports, universities, and government agencies across multiple countries. The FBI and international partners issued a joint advisory detailing the attackers' methods, targeted vulnerabilities, and indicators of compromise. The disruption aims to hinder China-linked cyber operations against U.S. and allied networks.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 21:48:42 UTC

Technical Analysis

Chinese state-sponsored hackers known as Flax Typhoon, operating through the contractor Integrity Technology Group, used two main hacking platforms: MicroScan, a Python-based vulnerability scanner with over 1,300 penetration-testing scripts targeting software such as Oracle WebLogic, Apache Struts, WordPress, and Jenkins; and FishHub, used for spear-phishing and delivering malware to maintain unauthorized remote access and exfiltrate data. The FBI seized seven domains supporting these platforms, which were involved in scanning and breaching critical infrastructure networks in the U.S., Taiwan, Japan, Poland, and other countries. Investigations revealed targeted exploitation of at least eight known vulnerabilities (e.g., CVE-2016-3081, CVE-2019-11510) and use of additional tools like EBurst for password spraying. The FBI coordinated with CISA, NSA, and international partners to issue a cybersecurity advisory with indicators of compromise and mitigation recommendations. This action follows previous disruptions of Integrity Tech's infrastructure and sanctions by the UK and EU.

Potential Impact

The hacking tools enabled widespread vulnerability scanning and successful breaches of critical infrastructure and other organizations worldwide, including U.S. government agencies, critical manufacturing, healthcare, IT, law enforcement, educational institutions, and religious organizations. The attackers gained unauthorized remote access, exfiltrated sensitive data, and compromised networks across multiple countries. The disruption of the infrastructure and seizure of domains significantly impairs the operational capabilities of the Flax Typhoon group and its contractor, reducing their ability to conduct further intrusions.

Defensive Guidance

The FBI and international partners have seized the domains supporting the hacking tools, disrupting their operation. Organizations are urged to review the joint cybersecurity advisory containing indicators of compromise, patch known vulnerabilities exploited by these tools, disable unnecessary exposed services, and enforce multifactor authentication. These measures help protect against similar attacks. The disruption of the infrastructure serves as a significant mitigation step by law enforcement.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.67,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/","fetched":true,"fetchedAt":"2026-10-08T21:48:33.644Z","wordCount":1168}

Threat ID: 6ac80fb32cdf04f65639a89f

Added to database: 10/08/2026, 21:48:35 UTC

Last enriched: 10/08/2026, 21:48:42 UTC

Last updated: 10/09/2026, 04:03:23 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses