DOJ and FBI Seized Seven Hacking Domains

The operation disrupts state-linked tools used to target critical infrastructure and academic networks globally.

Updated on Oct. 9, 2026 in Cybersecurity

DOJ and FBI Seized Seven Hacking Domains

Live Poll

Do you trust the U.S. government to adequately protect critical infrastructure from foreign cyber attacks?

The U.S. Department of Justice and the FBI seized seven internet domains associated with Microscan and FishHub hacking tools. These tools were operated by the China-based Integrity Technology Group to infiltrate power utilities and universities.

Why it matters

These seizures aim to neutralize state-contracted intrusion activities that target global infrastructure through botnets and spear phishing. The action follows a prior U.S. effort to dismantle a larger botnet managed by the same group.

Integrity Technology Group leveraged a botnet—a network of compromised devices controlled remotely—using a variant of Mirai malware to scan for vulnerabilities. The seizure targeted infrastructure that facilitated the exploitation of 20 Taiwanese universities and a South Carolina power firm.

The players

Justice Department

The U.S. federal executive department responsible for the enforcement of law and administration of justice, frequently leading large-scale infrastructure seizure operations.

FBI

The domestic intelligence and security service of the United States that handles federal cybersecurity investigations.

Integrity Technology Group

A China-based entity that operates under government contracts using malware to infiltrate international infrastructure and academic networks.

The details

Microscan acted as a reconnaissance engine, probing victim networks to identify exploitable software flaws. Once a target was identified, the FishHub platform enabled attackers to deploy additional malware via spear phishing—a targeted email attack meant to trick recipients into revealing sensitive data or executing code. The Integrity Technology Group performed these operations under contracts with the PRC government to extract files and gain unauthorized network access.

Timeline

  1. September 2024: The Department of Justice disrupted a prior Integrity Tech botnet.

  2. October 8, 2026: The Justice Department and FBI seized seven domains associated with the hacking tools.

The Tech Race

This operation marks a continued effort by the U.S. to degrade the capabilities of state-linked threat actors targeting civilian infrastructure. It follows a direct trajectory from the September 2024 botnet shutdown, signaling an expanded focus on secondary tools like Microscan and FishHub.

The seizure forces operators of critical infrastructure and academic networks to identify potential prior infections from Microscan or FishHub. While the domains are currently offline, IT administrators should scan logs for Mirai-variant signatures to ensure no persistent unauthorized access remains.

The takeaway

Authorities are increasingly focused on identifying and neutralizing the specific toolchains used by foreign-contracted hacking groups. Readers should monitor future FBI cybersecurity advisories for indicators of compromise related to the Integrity Technology Group's evolving tactics.

Further reading

For more on the defense of digital infrastructure, visit the Cybersecurity section.

Live Poll

Do you trust the U.S. government to adequately protect critical infrastructure from foreign cyber attacks?