Skip to content

BuildNot yet confirmed elsewhere1 publisher2 min readPublished

After the Flax Typhoon domain seizure, operators are left to hunt the group's tradecraft

FBI and Justice Department investigators seized seven domains that China-linked Flax Typhoon used to scan and in some cases infiltrate critical infrastructure. The risk remains, and with no patch to install, exposed operators have to hunt the group's tradecraft themselves.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying After the Flax Typhoon domain seizure, operators are left to hunt the group's tradecraft
Generated illustration
No vendor patch for targets of Flax Typhoon's tooling Who the Flax Typhoon tooling reaches and how, per court documents, the Justice Department and the joint advisory

Targets: a South Carolina power firm, Japanese and Polish airports, Taiwanese gas and power firms. No vendor patch exists. 20 Taiwanese universities confirmed FishHub victims. Microsoft 365 tenants exposed. Tooling sold to clients. Advisory lists SoftEther VPN, cross-site scripting, EBurst.

No vendor patch for targets of Flax Typhoon's tooling
WhoHowKindClaim
Infrastructure operatorsCourt documents name a South Carolina power company, Japanese and Polish airports and Taiwanese gas and power firmsexposure2
Justice DepartmentNo vendor patch; mitigation is the court-authorized domain seizure plus a seven-country joint advisorydecision3
Taiwanese universities20 Taiwanese universities are confirmed victims of FishHub-related activityexposure15
Microsoft 365 tenantsNamed as exposed, as is anyone running internet-facing web apps or SOHO and IoT devicesexposure4
Clients of the serviceThe tooling was a service sold to other operators ('clients'), not a single team's private toolkitcapability17
Victim devices and accountsAdvisory: SoftEther VPN installed for persistence, cross-site scripting to harvest credentials, EBurst brute-forcing accountsexposure23

What happened

  • Court documents name the targets as a South Carolina power company, airports in Japan and Poland, a multinational NGO, and Taiwanese natural gas and power companies.
  • Integrity Technology Group ran the platforms, and it is the same operation behind Raptor Train, the botnet a U.S. court-authorized action took down in September 2024.
  • An FBI affidavit says the domain c0cc.cc was still serving the group's scanning tool as recently as September 9, 2026, a month before the announcement.
  • Agencies from the U.S., U.K., Australia, Canada, Japan, New Zealand and Spain issued a joint advisory alongside the seizure.

Why it matters

  • cost No central fix exists to push, so the cost of closing the exposure falls on each operator's own staff, who have to find and patch the systems the scanner probed.
  • exposure The tooling was sold to clients, so the capability sits with buyers the seizure never reached.
  • decision Operators now have to search their own networks for the advisory's markers, such as SoftEther VPN installed for persistence and credentials harvested through cross-site scripting.

The piece that explains why there is nothing to patch is a scanner called MicroScan. It is a Python web tool, in use since about 2017, that ships with more than 1,300 penetration-testing scripts. [11] Each script checks a target for a specific published vulnerability in software such as OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins or Apache Struts. [12] The operators ran it next to standard open-source tools, masscan, NMAP, Fscan, wpscan, dirsearch and OneForAll among them. [13]

MicroScan hunts for holes the vendors have already shipped fixes for, and it is pointed at operators who have not installed them. Taking the delivery domains offline removes a path to the scanner, [1] and an exposed WebLogic server stays unpatched. With no single product to update, the Justice Department's remedy is the seizure plus a joint advisory. [3] The exposed set is wide: internet-facing web apps, Microsoft 365 tenants, universities, NGOs, and SOHO or IoT devices. [4]

Behind the tools is Integrity Technology Group, a Beijing company that contracts with the Chinese government; the group it serves is tracked as Flax Typhoon, Ethereal Panda or RedJuliett. [6][5] According to the Justice Department, the payloads either gave Integrity Tech's clients remote access to a victim network or searched for specific files and sent them to servers Integrity Tech controlled. [16] The tooling was sold to other operators as a service. [17] A second tool, FishHub, worked through spear-phishing and follow-on payloads, with 20 Taiwanese universities among its confirmed victims. [14][15] Several of the seized domain names imitate Microsoft, YouTube and LinkedIn, outlook3650.com and youtubecard.com among them. [8][9]

The advisory describes Integrity Tech as a for-profit company that acquires or builds cyber tools for sale and compromises networks directly, with activity traced to at least mid-January 2021. [22] The same operation has run at scale before: court documents allege Integrity Tech built an IoT botnet on a variant of Mirai, managed through an application called Sparrow and signalled through subdomains of w8510.com. [18] A database on one of its servers held records for more than 1.2 million infected devices as of June 5, 2024, over 385,000 of them in the United States. [19] More than 260,000 were actively infected that day, roughly 126,000 in the U.S. [20]

What to watch

  • Whether the seized tooling reappears on new domains, since the clients who bought it still hold it.
  • Whether the seven-country advisory is updated with indicators operators can match against their own logs.
  • Any U.S. sanctions or indictment of Integrity Technology Group beyond the domain seizure.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence45
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The FBI and the Department of Justice seized seven domains and blocked access to the scanning and intrusion platforms Integrity Technology Group ran for the China-linked group Flax Typhoon.

    ReportedSupportedView cited source
  2. [2]

    Targets named in court documents include a U.S. power company based in South Carolina, airports in Japan and Poland, a multinational NGO, and Taiwanese natural gas and power companies.

    ReportedSupportedView cited source
  3. [3]

    There is no vendor patch; the Justice Department says the mitigation is the court-authorized domain seizure plus a joint advisory from seven countries documenting the group's tools and tradecraft.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 11, 2026

    FBI Seizes 7 Domains Tied to Flax Typhoon Scanning of Critical Infrastructure

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories