Cybersecurity Policy Report, Prolific Chinese Hacking Group Disrupted by DoJ Domain Seizure, (Oct 8, 2026)

Internet domains used by a Chinese company accused of hacking critical infrastructure have been seized by the Department of Justice and Federal Bureau of Investigation, DoJ announced today.
DoJ secured a warrant from the U.S. District Court for the Western District of Pennsylvania enabling it to order U.S.-based domain registrars redirect traffic from several domains used by China-based Integrity Technology Group, the department said in a news release.
DoJ alleged that Integrity Tech was associated with the Flax Typhoon cyber espionage group, which targeted U.S. critical infrastructure, and had developed tools for vulnerability scanning and spear phishing.
“Integrity Tech created and used a botnet of internet-of-things devices infected with a variant of Mirai malware. Among other things, this botnet facilitated Integrity Tech’s computer vulnerability scanning using Microscan. Integrity Tech developed Microscan to conduct reconnaissance, via the botnet and otherwise, of victim computer networks for vulnerabilities that its clients would later exploit,” DoJ said.
“A second Integrity Tech tool, FishHub, is alleged to have facilitated the exploitation of computer networks through spear phishing,” it said.
Integrity Tech’s targets included a U.S. power company based in South Carolina, a multi-national nongovernmental organization, Japanese and Polish airports, and critical infrastructure and universities in Taiwan, according to DoJ.
“Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure,” said Brett Leatherman, head of the FBI’s Cyber Division.
“The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure,” Mr. Leatherman said.
The Treasury Department imposed economic sanctions on Integrity Tech last year (CPR, Jan. 6, 2025).
In conjunction with DoJ’s seizure of Integrity Tech’s domains, the FBI, Cybersecurity and Infrastructure Security Agency, and National Security Agency, along with cyber defense agencies in Australia, Canada, Japan, New Zealand, Spain, and the United Kingdom, published an advisory to help critical infrastructure organizations identify Integrity Tech’s activities.
“Integrity Technology Group, a China-based company with links to the Chinese government, enables China-linked threat actors to exploit U.S. and foreign organization networks across multiple sectors using various tools and techniques,” the advisory says.
“The threat actors targeted victims across multiple U.S. critical infrastructure sectors, including: Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology,” it says. “The actors also targeted victims in U.S. law enforcement, education, and religious organizations, as well as organizations across Southeast Asia, Africa, and North America,” it adds.
“Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing,” Chris Butera, CISA’s acting executive assistant director–cybersecurity said in a news release.
“CISA urges organizations to review this advisory to be aware of the wide range of tactics used by these actors and implement recommended actions and mitigations,” Mr. Butera added. “The advisory underscores the critical role of collaboration between government agencies and the private sector.”
MainStory: TopStory FederalLegislation InternationalLegislation LitigationEnforcement DataSecurity