On October 8, the US Justice Department and FBI seized domains tied to two tools called Microscan and FishHub, and the FBI, CISA, NSA, the UK’s NCSC and six other agencies published a 58-page advisory on the company the US says operated them. Read together, the two documents describe an intrusion chain that starts with cheap scanning and ends with someone reading your mail through a VPN client your endpoint tools treat as legitimate.
Every statement about Integrity Technology Group below is the allegation or assessment of the named agency. The documents we reviewed contain no response from the company.
What the Justice Department says it seized
According to the Justice Department’s announcement, the seizures were court-authorized, and the court documents were unsealed in the Western District of Pennsylvania. The department says, citing court documents, that malicious cyber actors working for Integrity Technology Group, a company based in the People’s Republic of China that has contracts with the PRC government, operated and used both tools.
The department describes Microscan as a reconnaissance tool. Per the court documents, it was built to scan victim networks for vulnerabilities that the company’s clients would later exploit, and the department says a botnet of internet-of-things devices infected with a variant of Mirai malware supported that scanning. The department lists the networks Microscan scanned: a US power company based in South Carolina, a multinational non-governmental organization, Japanese and Polish airports, Taiwanese natural gas and power companies, and two Taiwanese universities.
FishHub is described as the second stage. The department alleges it supported spear phishing and, after an initial compromise, downloaded additional malware that gave the company’s clients remote access to the victim network or searched for specific files and sent them to servers the company controlled. Confirmed FishHub victims included roughly 20 Taiwanese universities. Five of the seized domains helped deliver that malware, and a sixth, which the department names, was how the company reached Microscan.
This is the department’s second public technical disruption of the company’s infrastructure. In September 2024 it announced a court-authorized disruption of a Mirai botnet of more than 200,000 consumer devices. The FBI’s Cyber Division put the strategy plainly. “The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity,” said Brett Leatherman, Assistant Director of the FBI’s Cyber Division. “By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure.”
What the joint advisory adds for defenders
The seizure removes infrastructure. The advisory, numbered AA26-281A and published on the FBI’s IC3 site, is where defenders get the behavior to hunt for. The authoring organizations are the FBI, CISA and NSA in the US, the UK’s NCSC, and agencies from Australia, Canada, Japan, New Zealand and Spain. The advisory says its content comes from technical evidence recovered in multiple FBI investigations related to Integrity Tech.
It also carries a caveat worth keeping in view. The advisory says the activity is consistent with what the industry calls Flax Typhoon, Ethereal Panda and Red Juliett, but that the same actors may also carry out activity unrelated to Integrity Tech, and that security vendors track and attribute actors differently, so the labels may not map one to one onto the US government’s view.
Scanning is broad and mostly uses open tools
The advisory says the actors use open-source scanners, including BBScan, dirsearch, Fscan, ksubdomain, masscan, Nmap, OneForAll, ShuiZe and WPScan, and concentrate on ports 21, 22, 53, 80, 443 and 1080. The advisory reads that tool choice as a sign the actors go looking for the easier targets, which is its inference rather than an observed fact about intent.
Microscan is the proprietary piece. The advisory describes it as a Python-based web application containing more than 1,300 penetration-testing scripts, in use since as early as 2017, aimed at services such as OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins and Apache Struts. A dashboard in the advisory shows detected vulnerabilities per account, which fits the Justice Department’s description of a tool whose output went to the company’s clients.
The CVE list is old
Appendix B lists eight vulnerabilities the actors successfully exploited. The oldest is CVE-2014-6278, a Bash flaw. The newest is CVE-2023-22894, in Strapi. Five of the eight carry an asterisk that the advisory defines as newly added to CISA’s Known Exploited Vulnerabilities catalog. All eight are years old. The advisory’s own mitigation list opens with disabling unused services and ports, patching and replacing end-of-life products, which is consistent with a campaign that works through exposure and neglect rather than novelty.
Persistence through a VPN client that looks legitimate
For persistence the advisory says the actors install SoftEther VPN clients on victim machines, configured to reconnect on startup, and often name the installer after common Windows executables. Because SoftEther is legitimate software, the advisory notes, endpoint detection is less likely to flag it. The VPN also obscures command-and-control traffic, which the advisory says makes it harder for victims to attribute malicious network activity.
Mail is the target
The advisory’s collection section is about email. It describes an open-source tool used for password guessing and spraying against Exchange interfaces, a PHP script that talks to the Exchange Web Services API to pull mail, and a Linux command-line utility, office-cli, that uses configuration files holding client, tenant and secret values to access Microsoft 365 mailboxes through legitimate access methods. The FBI also recovered a credential-harvesting page and an Active Directory replication tool used to copy account data from domain controllers.
Per the advisory, the actors also maintain a custom web application that gives third parties access to stolen email content, and in some cases limited access to the exfiltrated data to IP addresses in Xiamen, China. Observed email-theft victims included government organizations, law enforcement agencies, healthcare systems and religious institutions in Southeast Asia. The advisory lists targeted US sectors as government services and facilities, critical manufacturing, healthcare and public health, and information technology.
Our reading of why mail features so heavily is practical, and the advisory does not say it: a mailbox holds password-reset links, vendor contracts and the names of everyone a target talks to, so one successful logon yields intelligence on several organizations. That makes tenant-level controls, such as conditional access and an audit of connected applications, worth more than another mail-filter rule.
How the UK frames it
The NCSC’s release stresses a different angle than the US documents. It says the company has been “exposed by the UK and international partners for enabling cyber actors to target organisations worldwide,” notes that the UK government sanctioned the company last year, and describes the actors as using AI tools such as automated scanning alongside botnets and hands-on exploitation. The US advisory describes automated scanning, botnets and hands-on exploitation, and the text we reviewed does not mention AI. Defenders should plan around the behaviors both documents agree on.
“The extensive malicious cyber activities, and services by Integrity Tech, that have been exposed today should be extremely concerning for all network defenders,” said Paul Chichester, NCSC Director of Operations. The NCSC release also says the advisory was co-sealed by agencies from Australia, Canada, Japan, New Zealand, Spain and the United States.
What it means for the security leader
Three things stand out for anyone who has to decide where to spend the next quarter.
The expensive part of this chain is the part you do not control. Scanning infrastructure, a botnet and a library of exploit scripts are the attacker’s investment. The defender’s exposure is a list of internet-facing services and the patch level of each. The UK’s NCSC makes the same point about operational technology in a separate alert: “Organisations should not assume that their OT is inaccessible from the internet without verifying it, as unintended exposure can arise through misconfigurations, legacy connections, or unmanaged assets.” That alert is about OT, not this actor, but the advice transfers. We argued the same case from the incident-response side in our opinion on exposure inventories.
Allow-listed software is not trusted software. A legitimate VPN client, a command-line mail utility that uses valid credentials and an Exchange API call all look like normal traffic to tools tuned for malware signatures. Detection here comes from asking whether a machine should be running a VPN client at all and which applications hold mailbox permissions in your tenant. The advisory recommends monitoring cloud accounts for connected applications with access to email and file data.
Edge devices keep showing up in the same conversation. This advisory sits alongside recent warnings about firewalls and gateways. Our coverage of the FBI and Secret Service advisory on FortiGate devices and our opinion on replacing an exploited edge appliance cover the same exposure from the perimeter side.
What defenders should do this week
The advisory’s actions are specific enough to schedule. None of them is new, which is the point.
- Hunt first. Pull the indicators from the advisory’s STIX files and Appendix A, and review web, firewall and mail logs for the scanning and spraying behavior it describes. The advisory recommends hunting before eviction so you know the scope.
- Cut the surface. Disable unused services and ports, use an attack-surface or internet-search platform to see what you expose, and replace end-of-life products. Check your estate against the eight CVEs in Appendix B, including the old ones.
- Harden mail. Require MFA for webmail, VPNs and accounts that reach critical systems, and review which applications hold access to mailboxes and files in your cloud tenant.
- Watch for the quiet tools. Alert on unexpected VPN clients, on unexpected Active Directory replication, and on large outbound uploads from machines that rarely upload.
- Use the eviction guidance. If you find a compromise, the advisory points to CISA’s Eviction Strategies Tool for building a systematic plan and tells organizations to follow their own country’s rules for reporting cyber incidents.
- Test your controls. The advisory maps the activity to MITRE ATT&CK techniques and recommends picking one, aligning your technologies against it and testing how they perform.
A second seizure in two years suggests takedowns are repeated maintenance rather than endings. That is our reading, not the Justice Department’s.