Thank you for reading or listening to The Realist Juggernaut. Independent journalism should be accessible to everyone.
WASHINGTON — The Justice Department and FBI have seized internet infrastructure tied to two cyber tools allegedly operated by China-linked hackers associated with Integrity Technology Group, disrupting systems used to scan for vulnerabilities, conduct spear-phishing operations and penetrate critical infrastructure networks in the United States and abroad.
The court-authorized action targeted infrastructure supporting tools known as “Microscan” and “FishHub,” which federal investigators attribute to cyber actors connected to Integrity Technology Group, a People’s Republic of China-based company with contracts involving the Chinese government.
Private-sector cybersecurity researchers have associated Integrity Technology Group’s activity with the advanced persistent threat designation Flax Typhoon.
According to federal court records unsealed in the Western District of Pennsylvania, investigators obtained authorization to seize seven internet domains connected to the operation: c0cc.cc, 98aiblog.com, 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com and linkedinns.net.
The seizures represent the Justice Department’s second publicly disclosed technical disruption of infrastructure associated with Integrity Tech in roughly two years.
The FBI alleges Integrity Tech developed and operated a large botnet built from internet-connected devices infected with a variant of Mirai malware. Mirai and its derivatives can compromise devices such as routers, internet cameras, digital video recorders and other internet-of-things equipment, converting them into remotely controlled systems that can be combined into a botnet.
Those infected devices can then be used as intermediaries for malicious activity, allowing attackers operating outside the United States to route traffic through compromised American devices and obscure their actual location.
The scale described in the newly unsealed court records extends substantially beyond the individual systems named in the public announcement.
An FBI examination of one command-and-control server found records associated with more than 1.2 million infected devices, including more than 385,000 unique U.S. victim devices. As of approximately June 5, 2024, investigators said more than 260,000 devices remained actively infected, including approximately 126,000 systems inside the United States.
The FBI previously disrupted that Mirai-based infrastructure in September 2024. Investigators seized a domain used by the botnet, accessed command-and-control servers under court authorization, blocked administrators from accessing those systems and issued commands terminating communications between the command infrastructure and infected devices.
The current operation moves deeper into the technical infrastructure allegedly used by Flax Typhoon to identify and exploit potential targets.
One of the principal tools, Microscan, was designed to conduct automated reconnaissance against internet-facing systems and identify vulnerabilities that could later be exploited.
According to the FBI affidavit, investigators discovered Microscan operating on infrastructure controlled by Flax Typhoon and determined that the tool could route vulnerability scans through the Mirai botnet, disguising the origin of the reconnaissance traffic.
The FBI connected the Microscan infrastructure to Integrity Tech after examining software known as Sparrow that managed portions of the botnet. Source code and documentation contained references to “KRlab,” which investigators traced to a subdivision of Integrity Technology Group. Federal authorities said Integrity Tech maintains contracts with the PRC government.
Microscan was allegedly used against a wide range of targets.
Federal investigators identified vulnerability scanning directed at a power company based in South Carolina, a multinational non-governmental organization, airports in Japan and Poland, Taiwanese companies operating in the natural gas and electric-power sectors and universities in Taiwan.
The FBI alleges that some organizations scanned through Microscan were later successfully compromised.
Two Taiwanese universities cited in the federal affidavit were scanned before Flax Typhoon actors allegedly gained unauthorized access to their networks. One university in Hsinchu was scanned in March 2023 and compromised soon afterward. A second university in Puli Township was scanned in August 2022 and was also subsequently penetrated.
The second major tool targeted in the October operation, FishHub, allegedly supported spear-phishing operations and post-compromise activity.
Investigators found FishHub source code on a server purchased by Flax Typhoon and determined that five of the seized domains — 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com and linkedinns.net — were incorporated into its intrusion process.
According to the FBI, FishHub could cause compromised systems to download additional malicious code. That malware was capable of creating file inventories, searching for designated files, compressing documents and sending selected information back to infrastructure controlled by the attackers.
The resulting access could also provide Flax Typhoon operators with remote entry into victim networks.
Investigators found data and files connected to more than 20 entities on one FishHub-associated server. FBI analysis further showed command activity involving at least six Taiwanese universities, and investigators concluded that files had been exfiltrated through the FishHub infrastructure.
A separate domain, 98aiblog.com, was allegedly used in connection with SoftEther remote-administration software installed after Flax Typhoon gained access to compromised university networks. Federal investigators said the domain directed infected systems toward infrastructure controlled by the threat actors.
The seized domains also produced a financial trail linking portions of the infrastructure to overseas payments.
According to court records, several domains were purchased or renewed through accounts funded from outside the United States. Investigators identified payments involving Hong Kong financial information, Chinese yuan and PRC-based Alipay accounts.
The FBI affidavit states that the government developed probable cause to believe funds originating outside the United States had been transferred into the country to support infrastructure used in violations of federal computer-crime statutes.
Those allegations led investigators to pursue the domains not only as infrastructure allegedly used to violate the Computer Fraud and Abuse Act but also as property connected to an international promotional money-laundering conspiracy.
Federal authorities allege the domains were used or intended to be used to facilitate unauthorized access to protected computers, obtain information without authorization and intentionally damage protected systems.
The October 6 seizure warrant directed domain registry operator Verisign to redirect the targeted domains to FBI-controlled name servers, prevent their modification or transfer and propagate those changes through the Domain Name System. Visitors to the seized domains are to be redirected to a federal seizure notice identifying Integrity Technology Group and the FBI operation.
Assistant Attorney General for National Security John A. Eisenberg said the United States would continue targeting infrastructure that allows China-linked cyber operators to threaten American networks and critical systems.
U.S. Attorney Troy Rivetti for the Western District of Pennsylvania said the operation represents the second disruption of Integrity Tech infrastructure in approximately two years and reflects an effort to impose continuing operational costs on state-sponsored cyber actors.
FBI Cyber Division Assistant Director Brett Leatherman said the PRC relies on contractors and enabling companies to increase the scale of its cyber operations and said targeting those companies can reduce their ability to attack U.S. networks.
FBI San Diego Special Agent in Charge Mark Remily said the bureau would continue coordinating with domestic and international partners to disrupt PRC-linked cyber activity directed at critical infrastructure and national-security targets.
The case also illustrates the layered structure of state-sponsored cyber operations. Rather than relying on a single server or malware family, the alleged Flax Typhoon infrastructure combined compromised consumer devices, command-and-control servers, vulnerability scanners, phishing systems, remote-access tools, malicious domains and overseas financial transactions.
Such architecture can make attribution and disruption considerably more difficult because each component performs a separate function. Compromised consumer devices can mask the attacker’s true location. Vulnerability scanners identify entry points. Spear-phishing infrastructure delivers malware. Remote-access tools establish persistence. Separate servers then collect stolen information.
The Justice Department’s action targeted several of those layers at once.
The FBI also joined U.S. and foreign partners in issuing a cybersecurity advisory containing indicators of compromise associated with Integrity Tech activity, allowing network defenders to search their environments for signs of previous intrusion or continuing exposure.
FBI San Diego and Baltimore Field Offices are investigating the case in coordination with the FBI Cyber Division.
Assistant U.S. Attorney Brendan McKenna for the Western District of Pennsylvania and Trial Attorney Jacques Singer-Emery of the Justice Department National Security Division’s National Security Cyber Section are handling the matter. Assistant U.S. Attorney Thomas Sullivan for the District of Maryland and Japan’s National Police Agency provided substantial assistance.
The October action does not end the broader investigation into Integrity Technology Group or Flax Typhoon. The unsealed affidavit specifically states that the seizure application was intended to establish probable cause and did not contain everything known to investigators about the ongoing case.
The disruption removes infrastructure the FBI says supported vulnerability scanning, phishing, remote access and data theft against organizations spanning the United States, Taiwan, Japan, Poland and other jurisdictions.
U.S. District Court for the Western District of Pennsylvania — In the Matter of the Seizure of Internet Domain Names: c0cc.cc, 98aiblog.com, 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com, and linkedinns.net, Affidavit in Support of Application for Seizure Warrants, Magistrate No. 26-1564, dated October 6, 2026. (Free Download)
U.S. District Court for the Western District of Pennsylvania — Warrant to Seize Property Subject to Forfeiture, Case No. 26-mj-1564, issued October 6, 2026. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



