DOJ and FBI Seized Domains Linked to Hacking Tools
The operation targeted infrastructure used by a Chinese state-linked group for global cyberattacks.
Updated on Oct. 9, 2026 in Cybersecurity

Live Poll
Do you trust the U.S. government to adequately protect critical infrastructure from foreign cyber attacks?
The Justice Department and FBI have seized seven internet domains used to host Microscan and FishHub hacking tools. These tools were utilized by the China-based Integrity Technology Group to exploit networks worldwide.
Why it matters
The seizure disrupts a sophisticated operation that used malware-infected devices to target critical infrastructure and academic institutions. By dismantling these domains, federal authorities aim to neutralize the reconnaissance and exploitation capabilities of a group acting under contract for the PRC government.
The disruption targeted seven domains associated with Microscan and FishHub tools. These tools relied on a botnet of devices infected with a variant of Mirai malware to conduct reconnaissance and facilitate network exploitation.
The players
Justice Department
The executive department of the U.S. government responsible for the enforcement of federal law and the administration of justice.
FBI
The domestic intelligence and security service of the United States that serves as the nation's principal federal law enforcement agency.
Integrity Technology Group
A China-based entity that operates under contracts with the PRC government to perform cyber intrusion activities.
The details
Integrity Technology Group used Microscan to identify vulnerabilities in networks, such as a U.S. power company in South Carolina and airports in Japan and Poland. Once inside, they employed FishHub to initiate spear phishing attacks and download additional malicious software, affecting approximately 20 universities in Taiwan.
Timeline
In September 2024, the Justice Department disrupted a previous Integrity Tech botnet.
On October 8, 2026, the Justice Department and FBI seized the seven domains.
The Tech Race
This action follows the pattern set by the September 2024 disruption, targeting the evolving infrastructure of the same threat actor. It illustrates the ongoing arms race between state-sponsored cyber operations and international efforts to neutralize malicious botnet networks.
While this seizure specifically targets high-value infrastructure, it serves as a reminder for organizations to patch known vulnerabilities that tools like Microscan exploit. Users remain at risk from similar botnet-driven attacks that leverage compromised internet-connected devices.
The takeaway
The dismantling of these domains underscores the persistent threat posed by state-contracted hacking groups utilizing automated scanning tools. Strengthening network security and monitoring for irregular traffic from consumer devices are essential steps in mitigating these broad-reaching intrusions.
Further reading
Learn more about the evolving landscape of Cybersecurity.
Live Poll
Do you trust the U.S. government to adequately protect critical infrastructure from foreign cyber attacks?







