On October 8, 2026, the Department of Justice and FBI executed court-authorized seizures to disrupt two hacking platforms - “Microscan” and “FishHub” - operated by Integrity Technology Group, a China-based company with PRC government contracts. Investigators allege Microscan used a Mirai-variant botnet of infected IoT devices to conduct large-scale vulnerability scanning and reconnaissance of critical networks, while FishHub enabled spear-phishing campaigns that delivered follow-on malware for remote access and file exfiltration. The action aims to deny state-sponsored cyber actors the infrastructure they used to target U.S. and foreign critical infrastructure and to signal continued U.S. enforcement against PRC-linked cyber operations.
Court filings identify specific targets and indicators: Microscan scanning hit a South Carolina power company, a multinational NGO, airports in Japan and Poland, Taiwanese gas and power firms, and two Taiwanese universities, with access tied to the domain c0cc.cc. FishHub activity reportedly affected about 20 Taiwanese universities and used domains including 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, and linkedinns.net. This is the second public disruption of Integrity Tech - following a September 2024 takedown of a Mirai botnet of over 200,000 devices - and was accompanied by an FBI cybersecurity advisory with indicators of compromise for defenders.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.