Operation MicroScan & FishHub: FBI Takedown of Integrity Tech Infrastructure and Emergency CISA KEV Order
On October 8, 2026, the United States Department of Justice and the Federal Bureau of Investigation, in coordination with international cybersecurity agencies from the United Kingdom, Australia, Canada, New Zealand, Japan, and Spain, announced the court-authorized seizure of seven internet domains used to host and control MicroScan and FishHub. The two weaponized platforms were developed and managed by Beijing-based government contractor Integrity Technology Group to support state-backed cyber espionage campaigns conducted by threat actors known as Flax Typhoon.
Disrupted Infrastructure: MicroScan & FishHub
The joint advisory published by CISA, FBI, and international partners reveals the operational architecture deployed by Integrity Technology Group to support Chinese military and intelligence reconnaissance:
- MicroScan: A distributed vulnerability scanning and automated exploitation platform containing over 1,300 pre-packaged penetration testing scripts. The platform was used to mass-scan government agencies, telecommunications providers, universities, and defense contractors across North America, Europe, and the Indo-Pacific, automatically probing perimeters for known unpatched flaws.
- FishHub: A credential harvesting and spear-phishing management framework that automated target enumeration, email lure delivery, two-factor authentication proxying, and automated exfiltration of sensitive victim documents.
Emergency CISA KEV Catalog Additions (BOD 26-04)
Following the takedown, CISA issued an urgent update to its Known Exploited Vulnerabilities (KEV) catalog on October 8–9, ordering Federal Civilian Executive Branch (FCEB) agencies to remediate five specific legacy flaws weaponized by Flax Typhoon within 72 hours (by October 11, 2026):
CVE-2015-3306: ProFTPD mod_copy improper access control allowing arbitrary file upload and remote code execution.
CVE-2021-3199: ONLYOFFICE Docs path traversal in JWT handling leading to remote code execution.
CVE-2023-22894: Strapi CMS cleartext storage of sensitive information exposing administrative credentials.
CVE-2016-3081: Apache Struts command injection via Dynamic Method Invocation (DMI).
CVE-2015-5477: ISC BIND reachable assertion denial-of-service triggered by malformed TKEY queries.
Operational Impact & Strategic Analysis
This action follows the September 2024 disruption of the "Raptor Train" botnet, which compromised over 200,000 SOHO routers and IoT devices under Integrity Tech's control. By seizing the command domains for MicroScan and FishHub, law enforcement has severed the command pipeline used by Flax Typhoon to orchestrate zero-day discovery and high-velocity exfiltration against Western critical infrastructure.
Actionable Enterprise Defensive Guidance
- Audit for KEV Flaws: Immediately scan all internet-facing systems for the five KEV vulnerabilities listed above. Legacy instances of ProFTPD, old Strapi backends, or unpatched ONLYOFFICE document servers must be isolated or decommissioned immediately.
- Block Seized Command Domains: Ingest the indicators of compromise published in the FBI/CISA joint advisory and ensure DNS sinkholing is configured for all domain names associated with the MicroScan and FishHub command infrastructure.
- Monitor for SOHO Proxy Botnets: Flax Typhoon frequently routes administrative access through consumer routers. Enforce behavioral geofencing and inspect inbound administrative traffic originating from residential ISP ranges.