Threats · 7h ago

Coalition seizes Flax Typhoon’s contractor tools

A U.S.-led coalition said Thursday it seized websites and infrastructure tied to Beijing-based Integrity Technology Group, removing Microscan and FishHub from use in the Flax Typhoon campaign. The Justice Department, FBI, CISA and NSA also issued a 58-page advisory that traces six years of activity and links the tooling more explicitly to Integrity as an enabling contractor.

Microscan was built to sweep internet-facing systems for known weaknesses, while FishHub helped move from phishing access to malware delivery after a foothold. Put together, they gave China-linked operators a way to find openings at scale and then turn those openings into intrusion support, so the same campaign could move from reconnaissance to access without all the work staying in-house.

The map that matters is the supply chain behind the campaign: if a state actor can outsource scanning, phishing support and botnet-backed reach, the practical blast radius is larger than any single intrusion. For defenders in the sectors named by the advisory, the exposure is not just one operation but the operator model that keeps showing up across targets.

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-10-08

Editions

Related stories