BuildNot yet confirmed elsewhere1 publisher2 min readPublished
After the Flax Typhoon domain seizure, operators are left to hunt the group's tradecraft
FBI and Justice Department investigators seized seven domains that China-linked Flax Typhoon used to scan and in some cases infiltrate critical infrastructure. The risk remains, and with no patch to install, exposed operators have to hunt the group's tradecraft themselves.
The Engineer · Build desk

Targets: a South Carolina power firm, Japanese and Polish airports, Taiwanese gas and power firms. No vendor patch exists. 20 Taiwanese universities confirmed FishHub victims. Microsoft 365 tenants exposed. Tooling sold to clients. Advisory lists SoftEther VPN, cross-site scripting, EBurst.
- exposure Infrastructure operators Court documents name a South Carolina power company, Japanese and Polish airports and Taiwanese gas and power firms, claim 2
- decision Justice Department No vendor patch; mitigation is the court-authorized domain seizure plus a seven-country joint advisory, claim 3
- exposure Taiwanese universities 20 Taiwanese universities are confirmed victims of FishHub-related activity, claim 15
- exposure Microsoft 365 tenants Named as exposed, as is anyone running internet-facing web apps or SOHO and IoT devices, claim 4
- capability Clients of the service The tooling was a service sold to other operators ('clients'), not a single team's private toolkit, claim 17
- exposure Victim devices and accounts Advisory: SoftEther VPN installed for persistence, cross-site scripting to harvest credentials, EBurst brute-forcing accounts, claim 23
| Who | How | Kind | Claim |
|---|---|---|---|
| Infrastructure operators | Court documents name a South Carolina power company, Japanese and Polish airports and Taiwanese gas and power firms | exposure | 2 |
| Justice Department | No vendor patch; mitigation is the court-authorized domain seizure plus a seven-country joint advisory | decision | 3 |
| Taiwanese universities | 20 Taiwanese universities are confirmed victims of FishHub-related activity | exposure | 15 |
| Microsoft 365 tenants | Named as exposed, as is anyone running internet-facing web apps or SOHO and IoT devices | exposure | 4 |
| Clients of the service | The tooling was a service sold to other operators ('clients'), not a single team's private toolkit | capability | 17 |
| Victim devices and accounts | Advisory: SoftEther VPN installed for persistence, cross-site scripting to harvest credentials, EBurst brute-forcing accounts | exposure | 23 |
What happened
- Court documents name the targets as a South Carolina power company, airports in Japan and Poland, a multinational NGO, and Taiwanese natural gas and power companies.
- Integrity Technology Group ran the platforms, and it is the same operation behind Raptor Train, the botnet a U.S. court-authorized action took down in September 2024.
- An FBI affidavit says the domain c0cc.cc was still serving the group's scanning tool as recently as September 9, 2026, a month before the announcement.
- Agencies from the U.S., U.K., Australia, Canada, Japan, New Zealand and Spain issued a joint advisory alongside the seizure.
Why it matters
- cost No central fix exists to push, so the cost of closing the exposure falls on each operator's own staff, who have to find and patch the systems the scanner probed.
- exposure The tooling was sold to clients, so the capability sits with buyers the seizure never reached.
- decision Operators now have to search their own networks for the advisory's markers, such as SoftEther VPN installed for persistence and credentials harvested through cross-site scripting.
The piece that explains why there is nothing to patch is a scanner called MicroScan. It is a Python web tool, in use since about 2017, that ships with more than 1,300 penetration-testing scripts. [11] Each script checks a target for a specific published vulnerability in software such as OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins or Apache Struts. [12] The operators ran it next to standard open-source tools, masscan, NMAP, Fscan, wpscan, dirsearch and OneForAll among them. [13]
MicroScan hunts for holes the vendors have already shipped fixes for, and it is pointed at operators who have not installed them. Taking the delivery domains offline removes a path to the scanner, [1] and an exposed WebLogic server stays unpatched. With no single product to update, the Justice Department's remedy is the seizure plus a joint advisory. [3] The exposed set is wide: internet-facing web apps, Microsoft 365 tenants, universities, NGOs, and SOHO or IoT devices. [4]
Behind the tools is Integrity Technology Group, a Beijing company that contracts with the Chinese government; the group it serves is tracked as Flax Typhoon, Ethereal Panda or RedJuliett. [6][5] According to the Justice Department, the payloads either gave Integrity Tech's clients remote access to a victim network or searched for specific files and sent them to servers Integrity Tech controlled. [16] The tooling was sold to other operators as a service. [17] A second tool, FishHub, worked through spear-phishing and follow-on payloads, with 20 Taiwanese universities among its confirmed victims. [14][15] Several of the seized domain names imitate Microsoft, YouTube and LinkedIn, outlook3650.com and youtubecard.com among them. [8][9]
The advisory describes Integrity Tech as a for-profit company that acquires or builds cyber tools for sale and compromises networks directly, with activity traced to at least mid-January 2021. [22] The same operation has run at scale before: court documents allege Integrity Tech built an IoT botnet on a variant of Mirai, managed through an application called Sparrow and signalled through subdomains of w8510.com. [18] A database on one of its servers held records for more than 1.2 million infected devices as of June 5, 2024, over 385,000 of them in the United States. [19] More than 260,000 were actively infected that day, roughly 126,000 in the U.S. [20]
What to watch
- Whether the seized tooling reappears on new domains, since the clients who bought it still hold it.
- Whether the seven-country advisory is updated with indicators operators can match against their own logs.
- Any U.S. sanctions or indictment of Integrity Technology Group beyond the domain seizure.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence45
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The FBI and the Department of Justice seized seven domains and blocked access to the scanning and intrusion platforms Integrity Technology Group ran for the China-linked group Flax Typhoon.
- [2]
Targets named in court documents include a U.S. power company based in South Carolina, airports in Japan and Poland, a multinational NGO, and Taiwanese natural gas and power companies.
- [3]
There is no vendor patch; the Justice Department says the mitigation is the court-authorized domain seizure plus a joint advisory from seven countries documenting the group's tools and tradecraft.
- [4]
Those exposed include critical infrastructure operators, universities, NGOs, Microsoft 365 tenants, and anyone running internet-facing web applications or SOHO and IoT devices.
- [6]
Integrity Technology Group is a Beijing-based company that contracts with the Chinese government.
- [7]
Integrity Tech is the same organization tied to Raptor Train, the SOHO and IoT botnet taken down in a U.S. court-authorized operation in September 2024.
- [8]
The seven seized domains are c0cc.cc, 98aiblog.com, 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com and linkedinns.net.
- [9]
Several of the seized domain names imitate Microsoft, YouTube and LinkedIn branding.
- [10]
According to an FBI affidavit, c0cc.cc was the access point for the group's scanning tool as recently as September 9, 2026, one month before the announcement.
- [11]
MicroScan is a Python-based web tool for reconnaissance and vulnerability scanning, originally hosted on 198.13.53.226 and believed to have been in use as early as 2017.
- [12]
MicroScan ships with more than 1,300 penetration-testing scripts that check websites for specific vulnerabilities in OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins and Apache Struts.
- [13]
The scanner was paired with open-source tooling including BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe and wpscan.
- [14]
FishHub, a second Integrity Tech tool, allegedly enabled network exploitation through spear-phishing and the deployment of follow-on payloads.
- [15]
Confirmed victims of FishHub-related activity include 20 Taiwanese universities.
- [16]
The Justice Department said the payloads either gave Integrity Tech's clients unauthorized remote access to the victim network, or searched for specific files and sent them to servers controlled by Integrity Tech.
- [17]
The source states the tooling was a service sold to other operators ('clients'), not a single team's private toolkit.
- [18]
Court documents allege Integrity Tech created and operated an IoT botnet built on a variant of the Mirai malware, using domains including subdomains of w8510.com for command-and-control and managed through an application named Sparrow.
- [19]
As of June 5, 2024, a database on the server at 202.182.109.151 held records for more than 1.2 million infected devices, including over 385,000 unique U.S. victim devices.
- [20]
More than 260,000 devices were actively infected on June 5, 2024, approximately 126,000 of them in the U.S.
- [21]
Cybersecurity and intelligence agencies from the U.S., U.K., Australia, Canada, Japan, New Zealand and Spain issued a joint advisory alongside the seizure.
- [22]
The advisory calls out Integrity Tech as a for-profit company that acquires or builds cyber tools for use and sale and compromises networks directly, describing activity going back to at least mid-January 2021.
- [23]
The advisory documents SoftEther VPN client software installed on victim devices for persistence, cross-site scripting attacks used to harvest user credentials, Python- and Go-based command-line utilities for initial access, and EBurst, an open-source Python brute-force tool aimed at accounts.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toFBI Seizes 7 Domains Tied to Flax Typhoon Scanning of Critical Infrastructure
1 article · October 11, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.