FBI seizes websites supporting Chinese contractor’s hacking operations

namussi/Getty Images

U.S. agencies targeted tools used to find security weaknesses and break into networks, warning of threats to critical infrastructure.

The Justice Department and FBI seized six internet domains supporting a major Chinese government contractor’s hacking operations, officials announced Thursday, alongside issuing a warning about the company’s role in targeting critical infrastructure worldwide.

The court-authorized seizures targeted two tools, Microscan and FishHub, operated by China-based Integrity Technology Group. Microscan searched networks for security weaknesses, while FishHub supported deceptive emails and delivered malicious software that could steal files or let hackers remotely control affected systems, according to the DOJ.

The action coincided with an advisory from the Cybersecurity and Infrastructure Security Agency, FBI, National Security Agency and international partners warning that the company supplies tools and technical support to China-linked hackers. 

Officials said the activity has targeted government, manufacturing, healthcare, law enforcement and education organizations.

“The [People’s Republic of China] relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity,” FBI Cyber Division Assistant Director Brett Leatherman said. “By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure.”

According to court documents, Integrity Tech used a network of hacked internet-connected devices, known as a botnet, to help Microscan search other networks for weaknesses its clients could exploit.

Scanning targets included a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and power companies, two Taiwanese universities and a multinational nongovernmental organization. 

Being scanned does not necessarily mean those organizations were successfully breached, but the digital reconnaissance can help intruders identify security weaknesses they could use to gain access.

FishHub helped hackers expand their access after an initial break-in. It delivered additional malicious software that allowed Integrity Tech’s clients to remotely access a network or search for specific files and send them to company-controlled servers, prosecutors said. Confirmed victims included approximately 20 Taiwanese universities.

The accompanying advisory describes how hackers supported by Integrity Tech seek to remain inside networks without being noticed. They target equipment that connects organizations to the internet, including devices that receive limited security monitoring. They also misuse legitimate system tools, making their activity harder to distinguish from routine work.

Thursday’s operation follows the September 2024 disruption of an Integrity Tech botnet made up of more than 200,000 compromised consumer devices worldwide. The company also faced U.S. sanctions in January 2025 for its role in facilitating hacking operations.

“Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing,” said Chris Butera, CISA’s acting executive assistant director for cybersecurity.