The FBI and the Justice Department seized seven domains on the authority of a federal magistrate's order dated 6 October. The domains supported two platforms operated by Integrity Technology Group, a Chinese cybersecurity company with government contracts, and a remote-access tool. The activity is associated with the espionage cluster commonly called Flax Typhoon.
One platform, MicroScan, searched exposed systems for weaknesses. The other, FishHub, delivered malware after targeted phishing and gave remote access and selective file theft. A seventh domain was tied to SoftEther VPN software installed on compromised systems to keep access alive.
According to an FBI affidavit, MicroScan was paired with a Mirai botnet of infected devices to probe targets including a South Carolina power company, airports in Japan and Poland, Taiwanese gas and electricity firms, and universities. The Justice Department says confirmed FishHub victims include around twenty Taiwanese universities. The FBI has not said whether the named power company, airports or energy providers were actually breached.
This is the second US action in two years against this company's infrastructure. In September 2024 the FBI dismantled a Flax Typhoon botnet built from more than 200,000 compromised consumer devices.
The part nobody printed
Reporting of this noted that CISA added five identifiers to its Known Exploited Vulnerabilities catalog in the same week, on the strength of exploitation tied to this activity. None of the coverage we read named them.
They are in CISA's own feed, which is public. Exactly five entries were added on 8 October, all with a remediation deadline of 11 October:
- CVE-2015-5477 — ISC BIND
- CVE-2016-3081 — Apache Struts, command injection
- CVE-2015-3306 — ProFTPD, improper access control
- CVE-2021-3199 — ONLYOFFICE Docs, path traversal
- CVE-2023-22894 — Strapi, cleartext storage of sensitive information
A note on those five: CISA's catalog entries do not name an actor. Five additions on the day, all sharing the deadline, matches what reporting describes, and that is a match rather than an attribution. We are naming the identifiers, not assigning them.
Three of them predate the campaign by a decade
Look at the years. 2015. 2016. 2015. The newest is from 2023.
A state-linked contractor built an internet-scale scanning platform, pointed it at power companies, airports and universities, and the things it was worth scanning for included a BIND flaw from 2015 and a Struts command injection from 2016.
That is not a statement about the attacker's sophistication. It is a statement about what is reachable. A scanning platform exists to find the cheapest way in across a very large number of hosts, and it found that the cheapest way in, in 2026, is frequently software that was patched eleven years ago and never updated.
The three-day deadline CISA attached is the other half of the signal. An agency does not give federal bodies seventy-two hours to patch something from 2015 unless it expects to find it installed.
What the seizure actually achieves
Seven domains and a scanning platform's access point. That is real and it is bounded.
The seized domains now serve FBI notices. The platform's operators lose the infrastructure named in the order and keep everything else — the code, the target lists, the knowledge of which hosts answered. Infrastructure is the cheapest thing to replace in an operation like this, which is why the same company appears in two US actions two years apart.
What a seizure does well is impose cost, document attribution publicly, and break the current campaign's tooling mid-flight. What it does not do is end the capability. Reading it as a defeat of the actor rather than a disruption of one deployment sets up the wrong expectation for the next one.
Seven governments — the US, UK, Australia, Canada, Japan, New Zealand and Spain — issued a joint advisory the same week warning that China-linked actors are targeting critical infrastructure.
What to do
- Patch the five. Three of them are old enough that the honest first step is finding out whether you are running the software at all, which for BIND, Struts and ProFTPD is often a question about something nobody owns any more.
- Treat the deadline as the signal it is. CISA set three days because it expects these to be present.
- Look for SoftEther VPN on systems that have no reason to run it. That is the persistence mechanism named here, and it is legitimate software, which is why it survives.
- Inventory what is internet-facing and old. A scanning platform does not care how long ago you deployed something.
What is not established
- Whether the five KEV additions are formally tied to this campaign. CISA's entries name no actor; the timing and the shared deadline match the reporting.
- Whether the named power company, airports and energy firms were breached, as opposed to probed.
- Who directed the activity. Integrity Technology Group holds government contracts, which is not the same as a tasking relationship being documented.
- What happens to the company. A domain seizure is not a charge.
- How much of the infrastructure was actually taken. Seven domains is what the order covers, not necessarily what exists.
