On October 8, 2026, the FBI and U.S. Department of Justice seized seven web domains connected to two hacking tools—Microscan and FishHub—allegedly run by China-based Integrity Technology Group. Court approval was granted for the operation in the Western District of Pennsylvania. The goal: disrupt infrastructure used to scan for vulnerabilities, deliver malware via spear phishing, and exfiltrate data from compromised networks.
What Microscan & FishHub Did
Microscan is a vulnerability-scanning toolkit built to identify weak points in systems and services. It includes over 1,300 penetration-testing scripts assessing exposed targets for flaws in Oracle WebLogic, WordPress, Apache Struts, OpenSSL, and Juniper ScreenOS, among others. Investigators traced its usage back to 2017. The service fed on a botnet of devices infected with a variant of Mirai malware, enabling ongoing scans of critical infrastructure—power and gas companies, airports, universities, NGOs across Taiwan, South Carolina, Japan, Poland, and more.
FishHub took a more direct adversarial role. It was used to send spear-phishing emails which, after victims engaged, installed malware offering remote access or enabling targeted file theft. Nearly 20 universities in Taiwan are confirmed FishHub victims. The affected institutions from Microscan scans and FishHub attacks may overlap, though the authorities have kept their tallies separate to avoid confusion between discovery and confirmed intrusion.
Seized Domains & Technical Disruption
The domains seized include five used for malware delivery—98aicai[.]com, 98aicode[.]com, linkedinns[.]net, outlook3650[.]com, and youtubecard[.]com—and one domain, 98aiblog[.]com, tied to SoftEther VPN software used to maintain persistence in compromised environments. The domain c0cc[.]cc was used to access Microscan directly. These seizures target the supporting infrastructure for the tools, not necessarily to close every exploited vulnerability.
This action follows a September 2024 prosecution of Integrity Tech’s prior botnet, which compromised over 200,000 devices globally. That earlier botnet was used to route malicious traffic through everyday internet-connected devices like routers, cameras, and network storage to disguise and distribute harmful activity.
The FBI led the move to disrupt not just attacks but the tools that empower them. Investigators’ advisory outlines a range of tactics—password spraying of Microsoft Exchange services, VPN persistence, and automated email exfiltration among them—some used by Integrity Tech beyond FishHub or Microscan.
Advice for Defenders
Organizations are urged to patch exposed software, disable unused services, enforce multifactor authentication, and scrutinize cloud apps with broad access. They should monitor for strange VPN installations, unusual logins, and large outgoing data flows. If signs of compromise appear, isolate affected systems, preserve logs, and locate all access vectors before removing malware or adversarial control.
The FBI’s seizures do not claim that every targeted network has been breached. Instead, by cutting off key infrastructure the group used for scanning and intrusion, the hope is to raise the hurdle for further attacks.
These developments highlight the increasing sophistication of state-linked threat actors who provide scanning, phishing, and network access tools as a service. The targeting of contractor-type cyber-infrastructure shows a shift: rather than always going after individual attacks, disrupting supply chains of hacking capabilities can have outsized effects. Going forward, companies and governments alike will need to monitor both threat actors and their supporting platforms—because disabling the latter may be a more sustainable strategy for reducing cyber risk.