Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Crime & Justice

FBI disables phishing toolkit used by China-linked hackers in wide-scale attacks

The FBI and Justice Department have confiscated the Microscan and FishHub tools that a China-affiliated hacking group used to target power grids, airports and universities worldwide.

The FBI, together with the Justice Department, has taken control of two cyber-attack utilities known as Microscan and FishHub, which were used by a hacking outfit associated with the Chinese government. These tools enabled the group to scan networks, launch phishing schemes and breach targets that included a U.S. power company, airports in Japan and Poland, Taiwanese universities, a multinational NGO and several Taiwanese critical-infrastructure firms.

FBI Cyber Division Deputy Assistant Director Jason Bilnoski labeled the campaign "indiscriminate and reckless" and said the seizure removes a key capability from the threat actors. The hackers operate under the banner of Integrity Technology Group, which the FBI says is the real identity behind the Flax Typhoon operation. This follows a September 2024 disruption of a botnet that infected over 200,000 consumer devices to facilitate data theft. San Diego Supervisory Special Agent Brett Lally warned that authorities will keep monitoring the group for any attempts to rebuild its infrastructure.

Why it matters

Disabling these tools reduces the risk of large-scale cyber attacks on essential services and critical infrastructure.

How this story developed

  1. Oct 4 FBI detains California realtor accused of spying on Taiwanese president’s son in Seattle
  2. Oct 5 A criminal complaint has been filed against Zhang.
  3. Oct 5 Authorities obtained Zhang’s iCloud data showing WeChat communications with Chinese officials.

In this story

phishing toolsChinese hackersFlax Typhooncritical infrastructurebotnetMicroscanFishHubcyber operationIntegrity Technology Group
Get the beta ↗