Security

Five US domains seized in global crackdown on Chinese hacking tools

(yesterday) · 8 min read · By Future Technology · Edited by Nath Connell

Key takeaways

  • The FBI seized seven domains linked to Chinese firm Integrity Technology Group and its Flax Typhoon botnet
  • Five vulnerabilities added to CISA's Known Exploited Vulnerabilities Catalog date back as far as 2015
  • Seven governments issued a joint warning about PRC-linked data theft from critical infrastructure

The headline numbers

The most striking detail in this week's announcement is not the seizure itself, but the age of the vulnerabilities involved. CISA added five CVEs to its Known Exploited Vulnerabilities Catalog, and the oldest dates back to 2015. That is more than a decade of unpatched exposure, still being actively used to breach networks in 2026.

Data pointDetail
Domains seized7 (including c0cc[.]cc, 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, linkedinns[.]net)
Botnet size before takedown260,000 infected devices
Operation window2021 until FBI disruption in September 2024
CVEs added to KEV catalog5, ranging from 2015 to 2023
Taiwanese universities infected via FishHubAbout 20
Governments issuing the joint advisory7 (US, UK, Australia, Canada, Japan, New Zealand, Spain)
Named victim sectorsPower, natural gas, aviation, academia, NGOs

The FBI's court-authorised seizures targeted infrastructure allegedly operated by Integrity Technology Group, a Chinese security firm the bureau has long linked to a state-backed cyber operation known as Flax Typhoon. According to unsealed court documents, the firm developed a vulnerability scanner called Microscan and a post-compromise tool called FishHub, both of which were used to scan and infiltrate victim networks.

Victims named in the documents include a university in Hsinchu, Taiwan, compromised in March 2023, and a second university in Puli Township breached in August 2022. Flax Typhoon actors also scanned a South Carolina power company's network, a multinational NGO, Japanese and Polish airports, and at least two Taiwanese critical infrastructure companies in the natural gas and power sectors.

What the data actually shows

Read the numbers carefully and a pattern emerges that is more uncomfortable than the headline suggests. This is not a story about sophisticated zero-day exploitation. It is a story about persistence, patience and the sheer volume of unpatched systems.

Consider the five CVEs in isolation. CVE-2015-3306 affects ProFTPD, a file transfer server. CVE-2015-5477 is a BIND DNS flaw. CVE-2016-3081 is a Struts vulnerability. CVE-2021-3199 and CVE-2023-22894 are more recent, but none are novel. Every one of these has had a patch available for years. The attackers are not breaking in through the front door with a master key; they are walking through windows that have been left open since the Obama administration.

That is the core insight. Flax Typhoon's effectiveness depends less on technical brilliance than on the vast attack surface created by organisations that cannot or will not patch legacy systems. The South Carolina power company, the Japanese airports and the Taiwanese gas firms were not targeted because they were uniquely vulnerable in a technical sense, but because they were reachable through known, documented weaknesses.

The botnet itself reinforces this. A Mirai-based network of 260,000 devices is not a precision instrument. Mirai, a type of malware that turns internet-connected devices such as routers and cameras into remotely controlled bots, is almost a decade old. Variants have been circulating since 2016. Yet Flax Typhoon allegedly used a version of it from 2021 until the FBI stepped in, hiding the true IP addresses and physical locations of PRC government hackers behind a layer of compromised consumer hardware.

The FishHub tool tells a similar story. According to an affidavit from FBI special agent Adam James, FishHub was named because it facilitated phishing activity, not because it was technically exotic. Once installed, it downloaded additional malware, created file listings, compressed documents and exfiltrated selected files to an attacker-controlled server. That is standard post-compromise tradecraft, executed at scale.

What the data does not tell us

For all the detail in the court documents, several important questions remain unanswered.

First, attribution is asserted rather than proven in public. The FBI states that Integrity Tech has contracts with the PRC government and that Flax Typhoon actors used its tools. But the precise command-and-control relationship between the firm, the hackers and the Chinese state is not laid out in the unsealed documents. Independent researchers have previously linked Flax Typhoon to Integrity Tech, and the US government has treated that link as established since at least 2024, but the evidentiary chain is not fully public.

Second, the seizures may not be as damaging as they sound. Seven domains is not a large number, and the advisory notes that FishHub delivered malware as recently as March 2026. The takedown of a handful of domains does not necessarily disable an operation that has demonstrated the ability to rebuild infrastructure. When the FBI disrupted the 260,000-device botnet in September 2024, Integrity Tech and Flax Typhoon tore it down themselves. By early this year, private sector researchers were warning that Chinese hackers had simply rebuilt, turning compromised routers and IoT devices into new botnets.

Third, the data does not quantify the damage. We know that emails and credentials were exfiltrated. We do not know how many records, how many organisations, or what proportion of the stolen data related to critical infrastructure versus academic or commercial targets. The advisory mentions US critical infrastructure networks specifically, but the victim list is broad enough that the strategic impact is difficult to assess.

Fourth, there is a conspicuous gap in the timing. The court documents reference activity from 2022 and 2023. The seizures were announced on 8 October 2026. That is a long gap between alleged intrusion and public disruption, and it raises questions about how long the FBI was monitoring the infrastructure before moving.

How this compares

The Flax Typhoon case sits within a broader pattern that security researchers have been documenting for years. In April 2026, a ten-country joint advisory warned that essentially every Chinese "Typhoon" group was using botnets strategically and at scale. Some of those networks, including the so-called Raptor Train, were allegedly built and maintained by Chinese infosec companies, Integrity Tech among them. This is not a single crew; it is an ecosystem.

The comparison with Volt Typhoon, another PRC-linked group, is instructive. Volt Typhoon has been accused of pre-positioning inside US critical infrastructure for potential disruptive attacks, a tactic that suggests preparation for conflict rather than simple espionage. Flax Typhoon's profile is different: it scans, phishes and exfiltrates. The South Carolina power company scan in April 2022 and December 2022 was reconnaissance, not sabotage. But the distinction may matter less than it appears. Access obtained today can be used tomorrow, and the same infrastructure that steals emails can be repurposed for disruption.

The UK's involvement in the joint advisory is also notable. The National Cyber Security Centre has been increasingly vocal about PRC-linked activity, and the inclusion of Spain alongside the Five Eyes nations plus Japan signals a widening coalition. This is no longer an Anglo-American concern. The targeting of Polish and Japanese airports makes that clear.

There is a useful parallel in the private sector. Dragos, the operational technology security firm, reported in February 2026 that a group overlapping with Flax Typhoon was focusing on long-term access to OT engineering workstations, targeting manufacturing, defence, automotive, electric power and oil and gas organisations across the US, Europe and Asia-Pacific. That is a shift from data theft toward potential operational disruption, and it is more worrying than any single domain seizure.

So what?

The practical implications for security teams are blunt. The five CVEs added to the KEV catalog are not exotic; they are old. CISA's KEV catalog exists precisely to force prioritisation, and the addition of 2015 and 2016 vulnerabilities in 2026 is an indictment of patch management in critical sectors. Organisations that have not addressed ProFTPD, BIND or Struts flaws should treat this as a direct warning.

The second implication is that domain seizures are a temporary measure. They disrupt, they do not deter. The 2024 botnet takedown was followed by rebuilding within months. Expect the same here. The advisory's language about "persistence through VPN software" and "exfiltrating emails and credentials using scripts" describes tradecraft that will survive the loss of seven domains.

Third, the targeting of Taiwan's universities and critical infrastructure companies is a reminder that this campaign is not solely about US interests. The roughly 20 Taiwanese universities infected via FishHub represent a sustained effort to compromise academic and research networks, which often hold sensitive defence-adjacent research and have weaker security postures than government or corporate targets.

For UK organisations, the advisory is a signal to review exposure to the listed CVEs, audit VPN configurations for signs of persistence, and treat Microsoft Exchange servers as high-priority targets for password spraying and cross-site scripting attacks. The seven-government coalition is a useful political statement, but the operational lesson is simpler: the attackers are using known tools against known weaknesses, and the defence is unglamorous patch management.

Key takeaways

The Flax Typhoon disruption is a genuine win for the FBI and its partners, but it is a tactical one. The operation's reliance on a decade-old vulnerability, a years-old botnet family and standard phishing tradecraft shows that the greatest risk to critical infrastructure is not cutting-edge attack technology but the vast estate of unpatched, internet-facing systems that organisations continue to run. Watch for rebuilding within months, and watch for the OT-focused activity Dragos described, which points toward a more dangerous phase.

The single most important takeaway: if an organisation is still running a system vulnerable to CVE-2015-3306, no amount of government disruption of Chinese hacking tools will protect it.

Sources

More from Future Technology