· via dev.to (home feed)
FBI seizes seven domains behind Flax Typhoon scanning of critical infrastructure
US authorities seized seven domains feeding Flax Typhoon's scanning and intrusion platforms, run by Chinese contractor Integrity Technology Group against power, airport and university networks.

FBI seizes scanning infrastructure
The FBI and the U.S. Department of Justice have taken control of seven internet domains and cut off access to the scanning and intrusion platforms they supported, disrupting tooling used by the China-linked actor known as Flax Typhoon. According to reporting on dev.to, which draws on court documents, the platforms were operated by Beijing-based contractor Integrity Technology Group — the same firm tied to the Raptor Train botnet disrupted by a U.S. court-authorized operation in September 2024.
The victims named in the filings span several countries and sectors: a power company in South Carolina, airports in Japan and Poland, Taiwanese natural gas and electricity firms, a multinational NGO, and universities in Taiwan.
The seven domains
The seized domains are c0cc.cc, 98aiblog.com, 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com and linkedinns.net. Several of the names borrow the branding of Microsoft, YouTube and LinkedIn. An FBI affidavit cited in the report states that c0cc.cc still served as the access point for the group's scanning tool as recently as September 9, 2026 — roughly a month before the announcement.
MicroScan and FishHub
The primary scanning engine, MicroScan, is a Python-based web reconnaissance and vulnerability scanning tool that court documents trace to use as early as 2017. It bundles more than 1,300 penetration testing scripts that probe for known weaknesses in OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins and Apache Struts. The scanner was paired with open-source utilities including masscan, NMAP, wpscan, dirsearch, Fscan, BBScan, ksubdomain, OneForAll and ShuiZe to locate and triage targets.
A second tool, FishHub, allegedly enabled network intrusion through spear-phishing and follow-on payloads. The DoJ characterizes those payloads as giving Integrity Tech's customers unauthorized remote access to victim networks, or searching for specific files and sending them to servers the company controlled. That word "customers" is notable: this was access sold as a service to other operators, not a single team's private toolkit. Twenty Taiwanese universities are listed as confirmed FishHub victims.
The botnet behind the scanning
Court documents allege that Integrity Tech built and ran an IoT botnet based on a variant of Mirai malware, managed through an application named Sparrow with command-and-control traffic flowing through subdomains of w8510.com. A database recovered from a server at 202.182.109.151 held records for more than 1.2 million infected devices as of June 5, 2024, including over 385,000 unique U.S. victims. More than 260,000 devices were actively infected on that date, roughly 126,000 of them in the United States.
Joint advisory documents the tradecraft
Alongside the seizure, cybersecurity and intelligence agencies from the U.S., the U.K., Australia, Canada, Japan, New Zealand and Spain published a joint advisory describing activity dating back to at least mid-January 2021. The documented tradecraft includes initial access through Python- and Go-based command-line utilities, cross-site scripting to harvest credentials, SoftEther VPN client installs for persistence, the open-source brute-force tool EBurst aimed at Microsoft 365 accounts, and a command-line utility called office-cli used to access mailbox data.
The U.K.'s National Cyber Security Centre added that actors enabled by Integrity Tech combine AI-assisted automated scanning with large-scale botnets and manual exploitation to compromise organizations worldwide, including in critical sectors.
What the action does and does not accomplish
The seizure removes seven domains and blocks access to the platforms behind them, but the reporting describes no arrests, and the company itself remains in place. The timeline illustrates the limit of this kind of disruption: Raptor Train was taken down in September 2024, yet MicroScan remained reachable through c0cc.cc two years later. Because most of the scanning stack is open source and freely available, the seized domains are the easiest part of the operation for the actor to replace.
FBI Cyber Division Assistant Director Brett Leatherman framed the action as pressure on the contractor ecosystem, arguing that China relies on contractor and enabling companies to scale its cyber operations, and that exposing those enablers makes targeting American networks harder.
The announcement coincided with a related move: the State Department is offering up to $10 million for information on Zhang Yu, a Chinese national charged in connection with the 2021 Microsoft Exchange Server attacks attributed to Silk Typhoon, formerly Hafnium. Co-defendant Xu Zewei was extradited from Italy to the U.S. in April 2026.
Why it matters
There is no vendor patch here, because this is not a single CVE. Three points stand out for defenders. First, the reconnaissance is industrialized: 1,300-plus scripts aimed at common web platforms, fed by a botnet of compromised small-office and IoT devices, means malicious scanning traffic arrives from ordinary residential addresses rather than obvious hosting providers. Second, the tooling is largely commodity — masscan, NMAP and wpscan look the same in logs whether the operator is a security researcher or a state contractor. Third, the post-access tradecraft concentrates on cloud identity and mail: brute force against Microsoft 365 accounts, mailbox access via a command-line utility, and a legitimate VPN client repurposed for persistence.
The seized domains and the two IP addresses in the court documents are useful historical indicators, but they are also the most disposable element of the operation. The durable takeaway is the business model: a contractor selling scanning, phishing and access as a service, aimed at power, gas, aviation and university networks across at least four countries.
- #security
- #critical-infrastructure
- #botnet
- #china
- #fbi