HomeCybersecurityThe FBI Takes Down Two Hacking Tools Tied to "Flax Typhoon": What...

The FBI Takes Down Two Hacking Tools Tied to “Flax Typhoon”: What Happened and Why It Matters

On 8 October 2026 the US Justice Department and FBI announced that they had seized web domains used to run two hacking tools, “Microscan” and “FishHub”. According to court documents, the tools were operated by Integrity Technology Group, a China-based company with Chinese government contracts that the Justice Department links to the “Flax Typhoon” hacking activity. On the same day, security agencies from seven countries published a joint advisory for network defenders, and the US cyber agency CISA added five vulnerabilities to its list of flaws known to be exploited. This explainer covers what was done and what it means. It contains no attack instructions.

What was seized, and what is alleged

Confirmed: the seizures. Alleged: the conduct. The Justice Department says the court-authorised seizures were meant “to deny malicious cyber actors access” to the two tools [1]. As alleged in court documents unsealed in the Western District of Pennsylvania, people working for Integrity Technology Group (“Integrity Tech”), a company based in China that “has contracts with the PRC government”, operated and used them [1]. These are allegations; no court has ruled on them.

The two tools did different jobs, according to the Justice Department [1]:

  • Microscan scanned networks for weaknesses that Integrity Tech’s clients “would later exploit”. It was partly run through a botnet of infected internet-connected devices. Targets named by the department include a US power company based in South Carolina, a multinational non-governmental organisation, Japanese and Polish airports, Taiwanese natural gas and power companies, and two Taiwanese universities.
  • FishHub supported spear phishing, meaning tailored fake emails. After a break-in, it downloaded further malware that gave clients remote access or searched for files and sent them back. The department says “approximately 20 Taiwanese universities” were confirmed victims.

The department seized one domain used to reach Microscan and five that helped deliver FishHub’s malware [1]. It calls this its “second public technical disruption” of Integrity Tech, after the September 2024 takedown of a botnet of “more than 200,000 consumer devices” [1]. Japan’s National Police Agency gave “substantial assistance”, the department says [1].

The joint advisory: AA26-281A

Confirmed (joint advisory dated 8 October 2026). The advisory was written by the FBI, CISA and NSA in the US, the UK’s National Cyber Security Centre, Australia’s ACSC, Canada’s Cyber Centre, Japan’s National Police Agency and National Cybersecurity Office, New Zealand’s NCSC and Spain’s national intelligence centre (CNI) [2]. It says actors enabled by Integrity Tech targeted US government, manufacturing, healthcare and IT organisations, as well as law enforcement, education and religious groups and organisations in Southeast Asia, Africa and North America [2].

Its advice to defenders is basic but important [2]:

  • switch off services and ports that are not needed;
  • check and clean what users type into web applications;
  • require multi-factor authentication wherever possible;
  • apply patches promptly.

Five old flaws added to CISA’s list

Confirmed (CISA catalogue). On 8 October CISA added five vulnerabilities, all listed in the advisory among flaws these actors successfully exploited, to its Known Exploited Vulnerabilities (KEV) catalogue [2][3]. US federal civilian agencies must fix them by 11 October [3]:

  • CVE-2015-3306, ProFTPD (file-transfer software)
  • CVE-2015-5477, ISC BIND (internet name-lookup software)
  • CVE-2016-3081, Apache Struts (a web framework)
  • CVE-2021-3199, ONLYOFFICE Docs (an office-document server)
  • CVE-2023-22894, Strapi (a content-management system)

The oldest dates from 2015. Their inclusion is a reminder that old, unpatched software stays useful to attackers for years.

What this does not prove

  • That Integrity Tech is guilty. The conduct is alleged in court documents [1].
  • That the activity has stopped. Seizing domains disrupts tools; it does not arrest anyone, and the advisory still urges defenders to hunt for compromises [1][2].
  • That the named targets were breached. Most were scanned; the department confirms FishHub victims only among Taiwanese universities [1].
  • How many organisations were hit. Neither the department nor the advisory gives a total [1][2].

The Bottom Line

The US has, for the second time, disrupted infrastructure that it says a Chinese contractor used to scan and break into networks worldwide. Eleven agencies from seven countries backed the warning, and five long-known flaws now carry a federal fix-by date of 11 October. For organisations, the advice is unglamorous: switch off what you do not need, use multi-factor authentication and patch old software.

Sources

  1. US Department of Justice, Office of Public Affairs, “Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers”, 8 October 2026 (official release; conduct alleged in court documents). https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-vulnerability-scanning-and-spear-phishing-tools-operated
  2. FBI, CISA, NSA and partners, “Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data”, joint cybersecurity advisory AA26-281A, 8 October 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
  3. CISA, Known Exploited Vulnerabilities catalogue (JSON feed checked 9 October 2026: five entries added 8 October 2026, due 11 October 2026). https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Share this story

More in this category

Latest on TSN

Free TSN tools: crypto calculator, Flux dashboard and more.