On 8 October 2026 the US Justice Department and FBI seized seven domains used to run two tools tied to Integrity Technology Group and the Flax Typhoon campaign. Microscan scanned targets. FishHub followed with spear-phishing, remote access, and file theft.
What happened
Court filings in the Western District of Pennsylvania say Integrity Tech, a China-based firm with PRC government contracts, operated both tools. Microscan was reached through c0cc.cc and was paired with a Mirai-variant botnet of IoT devices. Named scan targets include a South Carolina power company, airports in Japan and Poland, Taiwanese gas and power firms, and universities.
FishHub delivered follow-on malware after an initial compromise. Investigators recovered files from more than 20 organizations on a FishHub-linked server. Seized delivery domains include 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, and linkedinns.net. A seventh domain, 98aiblog.com, was tied to SoftEther VPN used for persistence.
The same day, CISA, FBI, NSA, and partners published advisory AA26-281A. It says the actors favor poorly monitored edge devices, living-off-the-land tools, and a custom web app that let third parties browse stolen email. Overlap names include Ethereal Panda and Red Juliett. This is the second public US disruption of Integrity Tech infrastructure after the September 2024 botnet takedown.
Who is affected
US and foreign critical infrastructure, government, manufacturing, healthcare, IT, education, and law enforcement were named. Geography in the advisory includes North America, Southeast Asia, and Africa. South African operators are not named as victims, but the same edge-device pattern applies to any internet-facing VPN, router, or file service.
- Microscan: Python scanner with more than 1,300 scripts, aimed at Oracle WebLogic, Apache Struts, WordPress, Jenkins, and similar stacks.
- FishHub: spear-phishing plus malware for remote access and selective file theft.
- Persistence: SoftEther VPN on compromised hosts, plus password spraying against Microsoft Exchange with the EBurst tool.
- Newly KEV-listed bugs called out as commonly targeted: CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, and CVE-2023-22894.
What to do now
Pull the AA26-281A indicators and hunt for SoftEther, unexpected VPN listeners, and mailbox-export jobs before you treat this as someone else's problem. Patch or isolate the old edge bugs the advisory lists, especially internet-facing ProFTPD, Pulse Connect Secure, GitLab, and ONLYOFFICE. Enforce MFA on email and VPN. Disable services that do not need to face the internet.
Source: US Department of Justice, 8 October 2026, Justice Department and FBI seize Microscan and FishHub. Joint advisory: CISA AA26-281A.
Also on the blog
- CVE-2026-104286: FortiMail unauthenticated file write, CVSS 9.8
- Cisco NX-OS CVE-2026-76471 scores 9.8 on Nexus 3000 and 9000
- ASOS breach: stolen employee login exposed customer contacts
- Red Lion N-Tron 700: seven flaws, upgrade to firmware 3.11.1
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.