A U.S.-led coalition said Thursday it seized websites and infrastructure tied to Beijing-based Integrity Technology Group, removing Microscan and FishHub from use in the Flax Typhoon campaign. The Justice Department, FBI, CISA and NSA also issued a 58-page advisory that traces six years of activity and links the tooling more explicitly to Integrity as an enabling contractor.
Microscan was built to sweep internet-facing systems for known weaknesses, while FishHub helped move from phishing access to malware delivery after a foothold. Put together, they gave China-linked operators a way to find openings at scale and then turn those openings into intrusion support, so the same campaign could move from reconnaissance to access without all the work staying in-house.
The map that matters is the supply chain behind the campaign: if a state actor can outsource scanning, phishing support and botnet-backed reach, the practical blast radius is larger than any single intrusion. For defenders in the sectors named by the advisory, the exposure is not just one operation but the operator model that keeps showing up across targets.
International coalition seizes tools used by cyber firm behind Flax Typhoon
and other nations took down digital tools and infrastructure by Beijing-based Integrity Tech that allowed "widespread vulnerability scanning and, in some cases, intrusions" as part of the Flax Typhoon campaign.