Yaamlabs

Threat intel

FBI seizes Flax Typhoon's scanner and phishing tools

The FBI seized seven domains behind Microscan and FishHub. What the joint advisory AA26-281A says to patch, hunt for and rotate now.

On October 8, the Justice Department and FBI announced the court-authorized seizure of seven domains behind two hacking tools, Microscan and FishHub. The FBI attributes both to Integrity Technology Group, a Beijing company the US Treasury sanctioned in 2025 for its role in the activity Microsoft tracks as Flax Typhoon. Microscan is a vulnerability scanner. FishHub ran spear-phishing and pushed follow-on malware to victims who had already been breached. The case was brought in the Western District of Pennsylvania.

According to the Justice Department and court filings reported by CyberScoop and The Record, Microscan was pointed at a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and power companies and a multinational non-governmental organisation. The DOJ says about 20 Taiwanese universities were confirmed FishHub victims; BleepingComputer, citing the FBI's seizure affidavit, describes files from more than 20 organisations on a FishHub server, six of them Taiwanese universities. The same day, the FBI, CISA, NSA and agencies from the UK, Australia, Canada, Japan, New Zealand and Spain published advisory AA26-281A, a 58-page guide to the group's tooling, and CISA added five old CVEs it uses to the Known Exploited Vulnerabilities (KEV) catalog.

How it works

The advisory describes a split between automated scanning and hands-on intrusion. Microscan is a Python web application, in use since at least 2017, holding more than 1,300 penetration testing scripts that check websites for specific flaws in OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins and Apache Struts. According to court documents, a Mirai-variant botnet of compromised internet of things (IoT) devices ran the scans. Operators logged in through c0cc.cc, one of the seized domains. Alongside it, the actors run open source scanners such as Nmap, masscan, Fscan and dirsearch, mostly against ports 21, 22, 53, 80, 443 and 1080.

Getting in relies on old, unpatched software and on stolen passwords. The advisory lists eight CVEs it saw exploited successfully, the oldest from 2014. It also describes a cross-site scripting (XSS) payload, script injected into a vulnerable third-party site, that draws fake username and password fields on the page. Whatever the visitor types is captured, and the page then offers a password-protected .zip holding live700_v1.exe, which starts a process named DiagTrack.exe that talks to dns.studiocloud[.]xyz and contains code for reading mailboxes. For mail accounts, the actors use EBurst, an open source Python tool that password-sprays Exchange and Microsoft 365 through every interface it can reach: ECP, EWS, OAB, OWA, RPC, MAPI, PowerShell, Autodiscover and ActiveSync. FishHub delivered the second stage, using look-alike domains such as outlook3650.com and linkedinns.net to drop remote access tools or file collectors that sent data back to Integrity Tech servers.

What attackers are doing after they get in

Persistence comes from SoftEther, a legitimate open source VPN client. The actors fetch the installer with PowerShell on Windows or curl and wget on Linux, set it to reconnect at startup, and often rename it conhost.exe or dllhost.exe. Because SoftEther is legitimate software, endpoint tools rarely flag it. The seized domain 98aiblog.com was one of the SoftEther hubs.

Then they go after credentials and mail. DC.exe performs DCSync, asking a domain controller through the directory replication service to hand over password hashes, group memberships and trust relationships as if it were another domain controller. Curlc4.txt is a PHP bot that pulls mail, calendars and contacts through Exchange Web Services (EWS), stages it in /var/tmp/.sess.zip, encrypts it with RC4 or AES-128-CBC and uploads it to natcloudservice[.]com. A Linux tool called office-cli reads Microsoft 365 mailboxes using an app registration's client_id, tenant_id and secret, which looks like ordinary API traffic. The advisory also describes a separate web portal through which third parties could read the stolen mail.

What to do

1. Patch the old flaws

CISA's five new KEV entries are CVE-2015-3306 in ProFTPD 1.3.5, CVE-2015-5477 in ISC BIND 9 (before 9.9.7-P2 and 9.10.x before 9.10.2-P3), CVE-2016-3081 in Apache Struts 2.3.19 to 2.3.28, CVE-2021-3199 in ONLYOFFICE DocumentServer 5.1.5 to 5.6.2, and CVE-2023-22894 in Strapi up to 4.5.5. The federal deadline is October 11. The advisory also lists CVE-2014-6278 in GNU Bash, CVE-2019-11510 in Pulse Connect Secure and CVE-2021-22205 in GitLab. Search your asset inventory and external scans for these product versions. Anything still running them is probably also end of life, so plan a replacement rather than a patch.

2. If you cannot patch today

Take the affected service off the internet or put it behind a VPN that requires multifactor authentication (MFA). Turn on MFA for webmail and Exchange, and block legacy authentication protocols in Microsoft 365 so that EBurst-style spraying against EWS, ActiveSync and Autodiscover cannot succeed with a password alone. Enable protective DNS so lookups of known bad domains are refused.

3. Check whether you were hit

  • Search DNS, proxy and firewall logs for the seven seized domains: c0cc.cc, 98aicai.com, 98aicode.com, 98aiblog.com, linkedinns.net, outlook3650.com and youtubecard.com. Any hit from inside your network is a lead worth following.
  • Load the STIX files from the CISA advisory into your SIEM or EDR. Several indicators date back to 2016, and the agencies ask you to vet them before blocking.
  • Look for conhost.exe or dllhost.exe running from anywhere other than C:\Windows\System32, any SoftEther install nobody requested, and connections to *.softether.net names, which the advisory lists among its indicators.
  • On domain controllers, enable Directory Service Access auditing and review event ID 4662 for the replication rights DS-Replication-Get-Changes (1131f6aa-9c07-11d1-f79f-00c04fc2dcd2) and DS-Replication-Get-Changes-All (1131f6ad-9c07-11d1-f79f-00c04fc2dcd2) requested by an account that is not a domain controller.
  • In Exchange IIS logs, look for one source IP producing failed logins across many mailboxes on /EWS, /Autodiscover, /Microsoft-Server-ActiveSync, /owa and /ecp. In Entra ID sign-in logs, error 50126 spread across many users is the cloud equivalent.
  • In Entra ID, list app registrations and enterprise apps holding Mail.Read or full_access_as_app permissions, and any client secret added recently.
  • On Linux web servers, check for /var/tmp/.sess.zip, hidden .run files and a storage/fm directory, plus outbound traffic to natcloudservice[.]com or 149.28.132[.]137.

4. If something matches

Isolate the host and scope the intrusion before you start removing things, as the advisory recommends; CISA's Eviction Strategies Tool can help build the plan. If DCSync is confirmed, reset the krbtgt account twice, with replication in between, and reset every privileged and service account. Remove unknown app registrations and their secrets, reset passwords for mailboxes that were sprayed, and review perimeter firewall rules for entries that let outside hosts reach internal ones.

The wider lesson

Integrity Tech has been scanning since 2017, and its operators kept working after the FBI took down its botnet in September 2024 and after the 2025 sanctions. The seized domains will be replaced. CISA's Chris Butera said Chinese government-affiliated actors "continue to position themselves within critical infrastructure networks." Microscan's scripts and EBurst look for an unpatched 2015 FTP server or a mailbox that accepts a password without MFA, and a replacement scanner will look for the same things.

Our attack surface management work finds the forgotten FTP, Struts and DocumentServer hosts that scanners like Microscan look for, and our security operations team can run the DCSync, SoftEther and spraying hunts above. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: CISA advisory AA26-281A, Advisory PDF on IC3, CISA KEV catalog, US Attorney's Office, Western District of Pennsylvania, CyberScoop, The Record, BleepingComputer, Hackread.

Back to the blog, or read this post on the full site.