US Seizes Seven Domains Behind Flax Typhoon Hacking Tools

Nancy Tyson  - Tech Writer
Last updated: October 10, 2026
Human Written
Share
FBI Seizes Seven Domains Linked to China-Backed Hacking Tools
Radar Rundown
  • The FBI and Justice Department seized seven domains running two hacking tools linked to a Chinese company with government contracts.

  • The tools allegedly helped attackers scan networks and break into critical infrastructure across the U.S., Taiwan, Japan, and Poland.

  • Experts and users online raise concerns that the seizure stops the tools but does not fix damage already done.

The FBI and the U.S. Department of Justice seized seven internet domains on October 8, 2026. Those domains powered two hacking tools called Microscan and FishHub. U.S. authorities say both tools were linked to Flax Typhoon, a cyber threat group connected to Integrity Technology Group, a Chinese company that holds government contracts.

A court approved the operation before it went ahead. Reuters and the Associated Press both reported on the seizure the following day, October 9.

According to the Justice Department, the goal was to stop bad actors from using the tools. Authorities also wanted to break up the setup supporting their attacks. Microscan helped attackers find weak spots in networks. FishHub helped them get deeper into systems they had already broken into.

How the two tools helped attackers break in

Court documents explain how the operation worked. Integrity Technology Group first built a botnet. A botnet is a large group of devices infected with harmful software. Here, the software was a version of Mirai malware, a known program that hijacks connected devices.

Microscan then used that botnet to scan networks for weak points. Attackers looked for gaps they could exploit later. Their targets were wide-ranging. They included a power company in South Carolina, airports in Japan and Poland, natural gas and power companies in Taiwan, and two universities in Taiwan. A multinational non-governmental organization was also on the list.

FishHub came in at a later stage. Once attackers were already inside a network, FishHub dropped more harmful software. That software could give attackers remote control of a system. It could also search for specific files and send them back to servers run by Integrity Technology Group. Data theft campaigns have also affected cloud-based customer environments, including a case in which a Canadian hacker pleaded guilty to a Snowflake data theft campaign affecting millions.

Authorities identified around 20 Taiwanese universities as victims of FishHub activity. The seven seized domains included addresses like c0cc.cc, 98aicai.com, outlook3650.com, youtubecard.com, and linkedinns.net, according to the Justice Department’s announcement.

This was not the first time U.S. authorities moved against Integrity Technology Group. In September 2024, the Justice Department disrupted a botnet tied to the same company. That earlier botnet had infected more than 200,000 consumer devices.

Online reactions and what they reveal

The announcement spread quickly on X. Responses, based on the posts provided, showed very different views about what the seizure actually means.

Patrick (@tributech_io_) raised a concern that many in security circles know well. He wrote that stopping a tool matters, but it does not show what the tool already changed. He warned that data touched by the attackers may no longer be intact. His point stands on its own: taking down a hacking setup cuts off future access, but it does not reverse what already happened. Any organizations targeted still need to check their systems for damage.

Yugal Hemane (@HemaneYugal) asked whether Flax Typhoons mainly went after poorly maintained internet-connected devices and equipment at the edge of networks. That question points to a real and ongoing problem in cybersecurity. However, the Justice Department’s documents describe a much broader effort, one that included scanning tools, fake login pages used for spear-phishing, and software that gave attackers long-term access.

Some users praised the action. CyberY57 (@CyberY57) welcomed the move, saying the FBI under Director Kash Patel seemed to be going after more criminal activity. Others pushed back on the framing.

Candy Walk (@CandyWalk98mk) questioned the focus on China, writing that blame was being placed on Beijing for things the writer felt others do too. These are individual reactions posted on a public platform. They do not speak for the broader security community.

Seizure cuts access, but defense work continues

Taking down the domains removes the specific tools authorities identified. However, the work does not stop there for organisations that may have been hit.

The FBI and its partner agencies released a cybersecurity advisory alongside the seizure. The advisory contains indicators of compromise, which are technical clues that help network teams spot related activity. Affected organisations need to review their systems, close any open doors left by attackers, and patch weak points that Microscan may have flagged.

China’s Foreign Ministry, according to Reuters, said Beijing opposed hacking and what it called politically driven misinformation. The ministry also called for cooperation with Washington on cybersecurity.

SecurityWeek noted that this latest move fits into a wider effort by U.S. authorities to disrupt suspected state-linked cyber activity. Whether it holds depends on two things: whether the operators can rebuild, and whether targeted organisations can find and contain any access that still remains.

Share this article

About the Author

Nancy Tyson

Nancy Tyson

Tech Writer

Nancy has been working as a Cybersecurity writer for over three years and contributes her expertise in the VPN area. Due to the technology element in Nancy’s education, she has acquired the ability to assess the online security environment objectively and explain concepts in simple terms to the readers of articles in the field. Besides using her time to learn about new VPN services, Nancy likes cooking, reading a good book, and often going to parties.

More from Nancy Tyson

Comments

No comments.