Justice Department Seizes 7 Domains Used by China-Linked Flax Typhoon as Integrity Tech Targets U.S. Critical Infrastructure


Oct. 9, 2026, 6:42 a.m.

Views: 1173


US announces effort to disrupt hacking infrastructure run by China's Integrity Tech Group

Justice Department Seizes 7 Domains Used by China-Linked Flax Typhoon as Integrity Tech Targets U.S. Critical Infrastructure

The Justice Department and FBI have seized seven internet domains used by hackers associated with China’s Integrity Technology Group, marking a new U.S. effort to dismantle cyber infrastructure used to scan and penetrate American critical systems. Federal authorities say the Beijing-based company supported hacking activity known in the cybersecurity industry as Flax Typhoon and provided capabilities that could be used to identify vulnerabilities in power networks, universities, airports and other sensitive systems. The operation is especially significant because it follows an earlier U.S. disruption of a massive Integrity Tech-controlled botnet involving more than 200,000 compromised consumer devices in the United States and abroad.

The new seizures show why China’s cyber threat cannot be understood only as a series of isolated hacking incidents. According to the Justice Department, Integrity Tech developed and operated infrastructure used by state-sponsored Chinese hackers to conduct reconnaissance, identify vulnerable systems and, in some cases, gain unauthorized access to networks. Federal officials said Integrity Tech has contracts with the Chinese government and supplied technical capabilities that expanded the reach of China-linked cyber operations.

The seven seized domains supported tools known as Microscan and FishHub. Microscan was used to identify weaknesses in computer networks that could later be exploited. FishHub allegedly helped hackers compromise networks through spear-phishing attacks and then deploy additional malware capable of providing remote access or searching for specific files. These tools gave cyber operators the ability to move from broad reconnaissance into targeted exploitation, creating a pipeline from vulnerability discovery to actual network compromise.

One of the targets identified by the Justice Department was a power company in South Carolina. Other targets included airports in Japan and Poland, Taiwanese natural gas and electric infrastructure companies, universities and other organizations. That list matters because it demonstrates the strategic character of the activity. Power utilities, transportation systems and communications networks are not ordinary commercial targets. They form the infrastructure that keeps modern economies functioning and become especially important during military, political or economic crises.

This is where the threat to the United States becomes especially serious. A foreign adversary does not need to immediately shut down an electric grid to gain strategic value from penetrating or mapping it. Identifying network architecture, vulnerabilities, administrative systems and potential access points can create options for later exploitation. Cyber reconnaissance conducted today can become operational leverage during a future confrontation.

Integrity Tech’s previous infrastructure offers an even clearer picture of the scale involved. In 2024, U.S. authorities disrupted a botnet created from compromised routers, internet-connected cameras, digital video recorders and storage devices. The infected devices were located around the world, including large numbers inside the United States. By routing malicious activity through ordinary consumer equipment, hackers could disguise their operations as normal internet traffic originating from homes and businesses rather than directly from China.

That technique creates a major defensive problem. When Chinese state-sponsored hackers operate through an American household’s router or an office surveillance camera, the apparent source of malicious traffic can look domestic. The compromised device becomes an unwilling relay point, giving attackers another layer of concealment while forcing investigators to distinguish ordinary consumer traffic from hostile cyber activity.

The FBI previously attributed that botnet activity to Flax Typhoon and assessed that Integrity Technology Group was responsible for developing and controlling the infrastructure. Federal officials have described Flax Typhoon as a China-based hacking operation engaged in reconnaissance and intelligence collection for Chinese security interests. The latest Justice Department action strengthens the picture of a commercial technology company serving as an important technical enabler for state-backed cyber operations.

This model should concern every country that depends on commercially connected infrastructure. Governments no longer need to rely exclusively on uniformed military cyber units or intelligence officers operating directly from government facilities. Contractors and technology companies can provide scanning systems, malware infrastructure, botnets and operational support that expand a state’s ability to conduct cyber activity while adding layers of organizational distance.

For the United States, that contractor ecosystem complicates both attribution and defense. A company may outwardly present itself as an information-security business while simultaneously developing tools that federal investigators say are being used to support state-sponsored hacking. Commercial infrastructure, legitimate-looking domains and compromised consumer devices can all become components of the same operational network.

The latest seizures also demonstrate why protecting American critical infrastructure requires more than installing security software after a breach occurs. Flax Typhoon’s reported methods emphasize reconnaissance. Scanning thousands of networks for weaknesses allows operators to identify systems that are poorly patched, improperly configured or exposed to the public internet. Once those weaknesses are cataloged, attackers can select the most useful targets and return later with more specialized tools.

Power companies are especially attractive because electricity supports nearly every other sector of modern life. Communications networks, hospitals, water systems, financial institutions, transportation hubs and military installations all depend on reliable power. A successful compromise can therefore have consequences far beyond a single company’s computer network.

The use of spear phishing through FishHub adds another layer of risk. Even organizations with sophisticated security infrastructure remain vulnerable when attackers can convince an employee to open a malicious file, enter credentials into a fraudulent website or interact with a carefully crafted message. Once initial access is obtained, malware can be used to establish persistence, search for information or provide remote control of compromised systems.

The Justice Department’s decision to seize the domains is therefore more than a symbolic action. Removing infrastructure forces hostile cyber operators to rebuild parts of their system, acquire new domains and establish new command-and-control pathways. Each disruption can raise costs, expose additional infrastructure and provide investigators with intelligence about how the network operates.

At the same time, the fact that the United States has now conducted two major public disruptions involving Integrity Tech illustrates the persistence of the threat. The 2024 botnet takedown did not end the company’s alleged cyber activity. By 2026, federal authorities were again targeting infrastructure associated with the same organization. Cyber operations can be rebuilt quickly, particularly when the actors behind them have significant technical expertise, funding and institutional support.

The broader lesson is that America’s conflict with hostile cyber networks increasingly takes place through everyday technology. Routers, cameras, storage devices, cloud infrastructure and domain names can become part of an intelligence-gathering system without their owners ever realizing it. A compromised household device may seem insignificant, yet thousands of such devices operating together can provide hackers with a global platform for reconnaissance and intrusion.

American companies operating critical systems must therefore treat China-linked cyber reconnaissance as a long-term strategic risk rather than an occasional IT problem. Regular patching, network segmentation, monitoring of unusual outbound traffic, stronger authentication and rapid response to federal cybersecurity advisories are now basic elements of national resilience.

The latest Flax Typhoon disruption offers a clear warning. The Justice Department says a Beijing-based technology company with Chinese government contracts provided tools used by state-sponsored hackers to examine and penetrate sensitive networks, including American critical infrastructure. The FBI and Justice Department have now dismantled parts of that infrastructure twice in two years.

That pattern deserves continued attention. The most dangerous cyberattack may begin long before anything visibly breaks. It can start with quietly scanning a power company, mapping a network, compromising an ordinary router and waiting for the moment when that access becomes strategically valuable. The seven seized domains are only pieces of a much larger contest over who can enter, map and control the digital systems on which the United States depends.


Return to blog