The US Justice Department and the FBI announced the seizure of seven domain used targeting critical‑infrastructure networks in the US, Asia and Europe.
The US Federal Bureau of Investigation (FBI) seizure of two hacking tools linked with Flax Typhoon, Microscan and FishHub, and of seven domain, on 8 October 2026, illustrates how governments are increasingly using judicial and technical measures to disrupt the infrastructure supporting transnational cyber operations.
Announced by the FBI and the Department of Justice (DOJ), the operation targeted tools that US authorities allege were operated by Integrity Technology Group, a China-based information-security company associated by the FBI with the cyber threat campaign known as Flax Typhoon. The action sought to deny the operators access to infrastructure used for reconnaissance, phishing and subsequent network intrusions. It follows a September 2024 FBI operation against a related botnet, demonstrating the continuing challenge of disrupting cyber capabilities that can be rebuilt after enforcement action.
The two tools supported different stages of the alleged intrusion process. Microscan was designed to scan networks for vulnerabilities that could subsequently be exploited, using a botnet composed of internet-connected devices infected with a variant of Mirai malware. US authorities say its targets included a South Carolina power company, airports in Japan and Poland, Taiwanese natural-gas and electricity-sector organisations, a multinational non-governmental organisation and two Taiwanese universities.
FishHub, by contrast, facilitated spear-phishing attacks and the delivery of additional malware following an initial compromise. According to the DOJ, this malware could enable unauthorised remote access or identify and transfer selected files to servers controlled by Integrity Technology Group. Approximately 20 Taiwanese universities were identified as confirmed victims of FishHub activity. The operation involved court-authorised seizures of seven internet domains associated with these tools and related remote-access infrastructure.
The operation also reflects a broader strategy of targeting the enabling infrastructure behind cyber threats rather than focusing exclusively on individual attacks. By seizing domains used to access or distribute malicious tools, authorities can interrupt communications between operators and their infrastructure, restrict malware delivery and complicate the continuation of an intrusion campaign.
However, domain seizures do not automatically remove malware from already compromised devices or networks, nor do they prevent operators from establishing replacement domains, servers or access mechanisms. The effectiveness of such interventions therefore depends on complementary measures, including identifying compromised systems, removing persistent access, sharing indicators of compromise and improving network defences. Alongside the seizures, the FBI and partner agencies issued a cybersecurity advisory to help organisations identify and respond to activity associated with Integrity Technology Group.
The action also carries geopolitical significance. US authorities allege that Integrity Technology Group supported cyber activities linked to Chinese state interests, describing the company as an enabling actor whose infrastructure expanded the reach of malicious operations. China, however, rejected the US allegations and called for cybersecurity risks to be addressed through dialogue, accusing Washington of politicising the issue.
These competing positions underline the difficulties of establishing shared understandings of state responsibility in cyberspace, particularly when operations involve private companies, compromised third-party devices and infrastructure distributed across several jurisdictions. Although the seizure demonstrates the reach of US investigative and judicial powers, the extent of all successful compromises and the longer-term impact on the alleged operators’ capabilities remain uncertain.
Why does it matter?
The operation illustrates the intersection of cybercrime enforcement, state-linked cyber operations and critical-infrastructure protection. The alleged use of compromised consumer routers and other internet-connected devices as reconnaissance infrastructure demonstrates how insecure devices outside critical networks can become part of a wider threat against power systems, transportation, education and other essential services.
The case also highlights both the value and limitations of disruptive law-enforcement measures: removing malicious infrastructure can impose operational costs, but durable resilience requires coordinated international action, timely threat intelligence, vulnerability remediation, multifactor authentication and effective incident response.
More broadly, the operation raises questions about accountability when private companies allegedly enable state-linked cyber activity, and about how states can cooperate against cross-border threats despite disagreements over attribution.
