US Hits China-Linked Hackers With Domain Seizures After Attacks Target Power, Airports and Universities

Benzinga · 2d ago

The U.S. Department of Justice and FBI seized seven internet domains allegedly used by China-linked hackers to scan networks and, in some cases, hack critical infrastructure systems.

The agencies announced the court-authorized seizures on Thursday, saying the tools were operated and used by cyber actors working for China-based Integrity Technology Group. According to court documents unsealed in the Western District of Pennsylvania, the company has contracts with the Chinese government.

Two Hacking Tools Targeted

The seized domains were linked to two tools, Microscan and FishHub, which authorities said were used to identify network weaknesses and, in some cases, gain unauthorized access to computer systems.

Microscan was developed to scan networks for vulnerabilities that clients could later exploit. Court documents listed targets including a South Carolina-based power company, Japanese and Polish airports, Taiwanese natural gas and power companies, two Taiwanese universities and a multinational nongovernmental organization.

FishHub allegedly helped attackers exploit networks through spear phishing, a method that uses targeted deceptive messages to trick victims. After an initial breach, the tool could download additional malware to provide unauthorized remote access or search for specific files and send them to servers controlled by Integrity Technology Group. Authorities identified approximately 20 Taiwanese universities as confirmed victims of FishHub activity.

The Justice Department, FBI and Integrity Technology Group did not immediately respond to Benzinga’s request for comment.

Part Of Broader Cybersecurity Efforts

The Justice Department said the latest action marks its second public technical disruption of Integrity Technology Group’s hacking infrastructure. In September 2024, authorities disrupted a separate botnet involving more than 200,000 internet-connected consumer devices infected with Mirai malware.

The latest operation follows another U.S. action in August targeting QTFY, a separate China-linked hacking platform whose tools allegedly scanned vulnerable devices and helped conceal attack origins.

Separately, an August report described suspected China-linked hackers using artificial intelligence agents in an attack targeting Taiwanese government systems. Researchers at an Israeli cybersecurity firm said they uncovered an AI-assisted operation in which attackers compromised at least 85 accounts and stole more than 2,500 personnel records.

The FBI said its San Diego and Baltimore field offices are investigating the Integrity Technology Group case with the agency’s Cyber Division. The FBI and international partner agencies also released a cybersecurity advisory containing indicators that network defenders can use to identify and respond to the alleged activity.

Disclaimer: This content was partially produced with the help of AI tools and was reviewed and published by Benzinga editors.

Photo courtesy: Shutterstock