SharpPostWorld

The US Justice Department said on October 8 that it had seized seven internet domains to disrupt access to two hacking tools allegedly operated and used by China-based cybersecurity company Integrity Technology Group against networks in the United States and elsewhere.

The tools, Microscan and FishHub, were linked to activity attributed by US authorities to the hacking group Flax Typhoon. In its announcement, the department said Integrity Technology Group had contracts with Chinese government agencies.

A seizure warrant issued on October 6 by a federal court in the Western District of Pennsylvania listed the seven domains and directed their registries to route them to FBI-designated servers and prevent further changes or transfers. The action targeted those domains, rather than placing the company's entire business under US control.

In an affidavit supporting the warrant, the FBI said Microscan was used to search target networks for security vulnerabilities. Operators launched scans through compromised routers and other devices to conceal their source. Targets included a power company in South Carolina, airports in Japan and Poland, and Taiwanese gas and electricity companies.

Microscan account dashboard reproduced in the joint advisory, showing scan statistics and redacted target sites.
Microscan dashboard reproduced in the joint cybersecurity advisory. Source: FBI and partner agencies, October 8, 2026.

The affidavit also described scans of two Taiwanese universities: one in Puli in August 2022 and another in Hsinchu in March 2023. Investigators subsequently found evidence that both universities' networks had been breached.

FishHub was used for spear phishing, the FBI alleged, sending deceptive messages tailored to particular recipients to spread malware. That malware could give attackers remote access to devices, search for files and transmit data out of the network. On a server obtained during the investigation, agents found data and files from more than 20 organisations. Command records allowed them to identify six Taiwanese universities.

Investigators traced the tools' operators through software code, server records and domain registrations. The affidavit said KRlab branding appeared in code and user manuals, while public websites linked KRlab to a unit of Integrity Technology Group. As recently as September 9, 2026, the FBI could still access a Microscan login page on one of the domains; its interface matched material previously obtained from a server during the investigation.

The seizures followed a US operation in September 2024 against a botnet linked to the company. That network comprised more than 200,000 consumer devices, which US authorities alleged were used to conceal hacking activity.

Integrity Technology Group has previously rejected US allegations. Responding to US Treasury sanctions in a January 6, 2025, company announcement, it said it operated lawfully and that its inclusion on the sanctions list had no factual basis. It also said it had no branches, business operations or assets in the United States.

Alongside the October 8 seizure announcement, the FBI, the US Cybersecurity and Infrastructure Security Agency, the National Security Agency and partner agencies in several countries published a 58-page joint cybersecurity advisory. It detailed technical indicators associated with the activity and recommended patching vulnerabilities, enabling multi-factor authentication and disabling unused network services and ports.