The Department of Justice on Thursday announced the court-ordered seizure of hacking tools used by a China-nexus actor against U.S. and other critical infrastructure providers.
The tools, dubbed FishHub and Microscan, were used by a company called Integrity Technology Group (ITG) to exploit vulnerabilities in critical infrastructure networks in North America, Southeast Asia and Africa.
The FBI and the Cybersecurity and Infrastructure Security Agency warned in a related advisory that ITG was using automated scanning along with the malicious tools in a campaign targeting government organizations, critical manufacturing, healthcare and information technology companies. The attack campaign mimics previously identified threat activity by China-nexus groups Flax Typhoon, Ethereal Panda and Red Juliette.
According to documents filed in the U.S. District Court, ITG built a botnet consisting of compromised internet-of-things devices the organization infected with a variant of Mirai. The attackers employed the Microscan tool to scan for vulnerabilities on targeted networks, using the botnet and other methods.
The targets included a South Carolina-based power company, a multinational non-government organization, airports in Japan and Poland and gas and power companies in Taiwan, according to court documents. The FishHub tool was used to conduct spear-phishing operations against 20 different universities in Taiwan.
China’s cyber threat
Federal authorities previously disrupted a botnet linked to the same actors in September 2024.
“It is a reminder that China is targeting a wide swath of the U.S. economy and critical infrastructure and that these campaigns are ongoing and persistent,” said Annie Fixler, director of the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies.
Microscan is a Python-based web application with more than 1,300 penetration testing scripts. The tool has been used to check for vulnerabilities in services like Oracle WebLogic, WordPress, Juniper ScreenOS, Jenkins and Apache Struts, according to the CISA advisory.
The hackers used a command-line utility called office-cli to target Microsoft Outlook 365 accounts and steal emails.
Security teams can take several measures to defend against these attacks, according to the CISA and FBI advisory: Disable unused services and ports, including remote access and automatic configuration and replace default passwords with strong, complex passwords. In addition, monitor for signs of unauthorized use of living-off-the-land tools and investigate logs for unusual IP addresses and ports.