INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

FBI Disrupts Chinese Hacking Tools Used to Breach Infrastructure

| 2026-10-08 21:55 LOW HIGH DATA BREACH CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
The FBI has disrupted Chinese state-sponsored hackers known as Flax Typhoon, seizing seven domains used to operate two hacking tools, MicroScan and FishHub. These tools were used in attacks that breached critical infrastructure and other organizations worldwide. The operation involved phishing tactics, with the compromised domains including [IOC HIDDEN • LOGIN REQUIRED], [IOC HIDDEN • LOGIN REQUIRED], [IOC HIDDEN • LOGIN REQUIRED], [IOC HIDDEN • LOGIN REQUIRED], [IOC HIDDEN • LOGIN REQUIRED], [IOC HIDDEN • LOGIN REQUIRED], and [IOC HIDDEN • LOGIN REQUIRED]. The FBI attributed the attack to Chinese hackers, indicating China as the origin country of the operation. MicroScan and FishHub are identified entities involved in the attacks, which were carried out by Flax Typhoon.
Technical Mitigations AI-generated
• Block domains <a href="/auth/login?next=/detail/JewxH6EBAhlSTKR_2JBF" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/JewxH6EBAhlSTKR_2JBF" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/JewxH6EBAhlSTKR_2JBF" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/JewxH6EBAhlSTKR_2JBF" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> and <a href="/auth/login?next=/detail/JewxH6EBAhlSTKR_2JBF" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>. • Hunt for indicators of compromise: <a href="/auth/login?next=/detail/JewxH6EBAhlSTKR_2JBF" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/JewxH6EBAhlSTKR_2JBF" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/JewxH6EBAhlSTKR_2JBF" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>, <a href="/auth/login?next=/detail/JewxH6EBAhlSTKR_2JBF" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> and <a href="/auth/login?next=/detail/JewxH6EBAhlSTKR_2JBF" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> • Patch vulnerabilities in FishHub and MicroScan tools.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

98•••••.com
98•••••.com
c0•••••.cc
98•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
‎2026/10/08
The FBI seized seven domains associated with Chinese state-sponsored hackers known as Flax Typhoon, who used hacking tools MicroScan and FishHub to breach critical infrastructure worldwide.
organisation MicroScan
organisation FishHub
Intelligence Sources