Seven Domains, Two Tools, One Familiar Foe
On Thursday, the Justice Department and the FBI announced the court-authorized seizure of seven internet domains, cutting off access to two hacking tools — “Microscan” and “FishHub” — that Chinese state-linked hackers used to scan and, in some cases, breach American and foreign critical infrastructure. According to Reuters, a federal court in the Western District of Pennsylvania authorized the seizures, which targeted infrastructure run by hackers working with Beijing-based Integrity Technology Group — a company the FBI says is the true identity behind the hacking group known in the industry as Flax Typhoon, carrying out intelligence collection and reconnaissance for China’s security agencies.
As the Justice Department’s statement lays out, Microscan was the reconnaissance arm — a vulnerability-scanning platform reached through one of the seized domains — while FishHub handled spear phishing and, after an initial foothold, downloaded malware that gave the hackers remote access to victim networks or searched for specific files and exfiltrated them.
The Hit List: Power Grids, Airports, Universities
The court documents name the targets. Microscan probed a power company in South Carolina, a multinational nongovernmental organization, airports in Japan and Poland, Taiwanese natural-gas and electricity companies, and two Taiwanese universities. FishHub’s confirmed victims included roughly 20 Taiwanese universities; its malware arrived through five of the seized domains, and a seventh domain supported remote-administration software that kept the hackers connected to victim networks.
One caveat the FBI was careful to include: scanning is not proof of compromise. The bureau says the tools were used to hack some targets — but did not say which of the named power companies, airports, or utilities were successfully breached. Being scanned is not the same as being owned.
Why This Matters: Seizures Buy Time — They Don’t Buy Security
Here is what the straight incident reports skip. Every official called the seizure a blow to the hackers, and it is — temporarily. But domains are cheap, and Mirai-style botnets rebuild from the same millions of unpatched routers and cameras. The 2024 takedown removed 200,000 devices and the group kept operating. Seizures disrupt; they don’t disinfect.
The part of the story that actually matters for the networks the hackers target is the one buried in the fine print: alongside the seizures, the FBI, CISA, the NSA, and partner agencies in six other countries published a joint cybersecurity advisory with indicators of compromise — the digital fingerprints network defenders need to hunt Integrity Tech’s activity in their own systems.
The advisory’s advice is almost aggressively ordinary: disable unused services and ports, sanitize web inputs, turn on multi-factor authentication everywhere, patch on time. That’s the quiet indictment at the heart of this story — Flax Typhoon’s targets fell to vulnerabilities that had been publicly documented for years. No zero-days were needed.
China’s foreign ministry said Friday it firmly opposes hacking, and Beijing routinely denies state-backed operations. Meanwhile the FBI’s own framing concedes the contest is ongoing — Assistant Attorney General John A. Eisenberg promised the department will “continue to respond decisively” against the threat. This was round two. Plan for round three.
Meanwhile in Tech News: Microsoft’s H-1B green card suspension is reshaping who builds and defends America’s tech infrastructure — just as the government says it needs more of both.


