What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

On October 8, 2026, the U.S. Department of Justice and FBI announced court-authorized seizures of domains supporting two tools authorities say were used by actors working for China-based Integrity Technology Group: MicroScan, for vulnerability reconnaissance, and FishHub, for spear-phishing and malware delivery. The action was intended to disrupt access to those tools; it was not a shutdown of all Integrity Tech activity. The FBI and international partners also issued guidance for network defenders. DOJ announcement · joint advisory

What was seized—and what the action means

The DOJ said the seizure targeted domains that supported MicroScan and FishHub and was designed to deny malicious actors access to the tools. The warrant affidavit lists seven domain names, but they did not all serve the same function: the DOJ announcement identifies one domain used to access MicroScan and five that helped deliver malware associated with FishHub. DOJ announcement · warrant affidavit

The DOJ described the operators as malicious cyber actors working for Integrity Technology Group, a China-based company it says had contracts with the PRC government. It called the October 2026 action the department’s second public technical disruption of Integrity Tech infrastructure. These are government statements about an ongoing investigation, not a final court finding of liability. The affidavit sets out probable-cause allegations supporting the seizure warrants. DOJ announcement · warrant affidavit

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The announcement was accompanied by a joint advisory authored by U.S. and international agencies, including the FBI, CISA and NSA, as well as the U.K. National Cyber Security Centre, Australia’s Australian Cyber Security Centre, Canada’s Centre for Cyber Security, Japan’s National Police Agency and National Center of Incident Readiness and Strategy for Cybersecurity, New Zealand’s National Cyber Security Centre, and Spain’s National Intelligence Centre. joint advisory

What MicroScan and FishHub reportedly did

MicroScan: vulnerability reconnaissance

The joint advisory says actors used MicroScan, a Python-based web application, as early as 2017. It contained more than 1,300 penetration-testing scripts for scanning websites for specific vulnerabilities. The DOJ says Integrity Tech developed it to conduct reconnaissance on victim networks, with vulnerabilities later exploited by clients. The reported role here is scanning and discovery; a scan does not by itself establish that a network was successfully breached. joint advisory · DOJ announcement

FishHub: phishing and follow-on malware

The DOJ says FishHub facilitated exploitation through spear-phishing. After an initial compromise, it could download additional malware that provided unauthorized remote access or searched for particular files and sent them to servers controlled by Integrity Tech. The DOJ identified approximately 20 Taiwanese universities as confirmed FishHub victims. DOJ announcement

Related activity is broader than the two tools

The joint advisory describes other techniques associated with Integrity Tech-enabled actors, including vulnerability scanning, cross-site scripting, password spraying against Microsoft Exchange, persistence through VPN software, and theft of emails and credentials. These behaviors are campaign context; they should not all be attributed specifically to MicroScan or FishHub. The advisory also cautions that actors may operate beyond Integrity Tech’s support and that labels used by external cybersecurity companies do not always correspond exactly to U.S. government attribution groupings. joint advisory

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which organizations were identified as targets?

The DOJ and reporting identified a South Carolina power company, a multinational nongovernmental organization, Japanese and Polish airports, Taiwanese natural-gas and power infrastructure companies, and two Taiwanese universities as targets of MicroScan scanning. That list describes identified scanning targets; it does not establish successful intrusion at every organization. Separately, the DOJ reported confirmed FishHub activity affecting approximately 20 Taiwanese universities. DOJ announcement · The Record

The Record says Flax Typhoon activity has mainly targeted Taiwanese government and education organizations, critical manufacturing, and IT, with victims also observed in Southeast Asia, North America, and Africa. The joint advisory describes a broader set of global activity. These are attributed descriptions of observed targeting, not a campaign-wide count of confirmed victims. The Record · joint advisory

What network defenders should do

The advisory urges organizations to hunt for potential compromise and reduce exposure. Its recommendations apply to organizational networks, not as consumer-device cleanup instructions. joint advisory

  1. Check for relevant exposure. Review internet-facing services and products against the advisory’s affected-product details and indicators of compromise. Investigate suspicious activity with the organization’s security or incident-response team.
  2. Patch affected systems promptly. The advisory lists eight CVEs observed in this activity: CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, and CVE-2023-22894. Consult the advisory’s appendix for affected products and versions; this is a list of vulnerabilities observed in the campaign, not a new vulnerability disclosure.
  3. Reduce unnecessary exposure. Disable unused services and ports, and limit access to services that must remain available.
  4. Harden web applications. Sanitize input to help prevent injection attacks, including cross-site scripting.
  5. Strengthen identity controls. Apply identity, credential, and access-management policies, and require multifactor authentication where possible.
  6. Use the advisory’s response materials. Its incident-response guidance and downloadable indicators of compromise can support threat hunting and investigation.

How this differs from the 2024 disruption

The October 2026 action targeted domains supporting MicroScan and FishHub. The earlier September 2024 disruption targeted Mirai botnet infrastructure. In its 2026 account of that operation, the DOJ said the botnet involved more than 200,000 consumer devices in the United States and worldwide; The Record reported a different figure, more than 260,000. Those counts refer to the earlier botnet, not the current seizure. DOJ announcement · The Record

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What remains unknown

The available announcements do not establish how long the seizure will disrupt the tools, whether the operators will replace the infrastructure, or the investigation’s eventual outcome. The DOJ said the FBI investigation was ongoing. The sources also do not provide a campaign-wide victim total or a complete count of successful intrusions. DOJ announcement

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.