As reported by SecurityAffairs, the U.S. Department of Justice and FBI have seized two offensive tooling platforms — Microscan and FishHub — operated by Beijing-based Integrity Technology Group, a company with direct contracts to the PRC government. This is the DOJ's second disruption of Integrity Tech's operations in as many years, a detail that should give every defender pause.
What the Seizure Actually Tells Us
The most significant takeaway isn't what was seized — it's what the seizure reveals about the operational tempo and resilience of state-linked adversary infrastructure. Microscan had been active since at least 2017, ran over 1,300 penetration testing scripts against known vulnerabilities in OpenSSL, WordPress, Jenkins, and Apache Struts, and was still reachable as recently as September 9, 2026. That's nearly a decade of continuous offensive scanning capability powered by a botnet of more than 1.2 million compromised IoT devices.
When an adversary maintains offensive infrastructure for nine years and survives a previous government takedown, the lesson is clear: infrastructure seizures are speed bumps, not roadblocks.
The group behind this — tracked as Flax Typhoon (also Ethereal Panda / RedJuliett) — demonstrates a model where commodity IoT botnets serve as the backbone for sophisticated reconnaissance against critical infrastructure. The targets were not random: power companies in South Carolina and Taiwan, airports in Japan and Poland, natural gas facilities, universities, and NGOs. This is systematic mapping of attack surfaces in sectors that matter strategically.
Why This Matters Beyond the Headline
1. Takedown Fatigue Is Real
This is the second disruption in two years. The first, in late 2024, targeted the underlying botnet infrastructure. Yet the group rebuilt, repurposed, and continued operating. Defenders should assume that seized domains and infrastructure will be replaced within weeks. The adversary's playbook remains intact even when individual nodes are removed.
2. IoT Devices Are Offensive Infrastructure
With over 385,000 infected devices in the U.S. alone at peak, the botnet represents a weaponized consumer infrastructure problem. Mirai-variant malware on routers, cameras, and DVRs gave the operators a distributed scanning engine that blended into background internet noise — making detection by individual organizations nearly impossible without global visibility.
3. Known Vulnerabilities Remain the Primary Attack Surface
Microscan targeted well-documented CVEs in widely deployed software — OpenSSL, WordPress, Jenkins, Apache Struts. These are not zero-days. They are unpatched, legacy, or misconfigured systems that organizations have failed to remediate despite years of available patches. The adversary doesn't need innovation when defenders leave the door open.
Who Is Most at Risk
Shield53 Recommendations
Immediate Actions
- Audit external attack surface — inventory all internet-facing systems running Jenkins, WordPress, Apache Struts, and OpenSSL-based services. Patch or decommission immediately.
- Review DNS and proxy logs for historical connections to
c0cc.ccor associated Microscan/FishHub infrastructure. Any match indicates prior reconnaissance against your environment. - IoT segment isolation — ensure all IoT devices (cameras, routers, sensors) are on isolated network segments with strict egress filtering. Default credentials must be changed and management interfaces disabled.
Strategic Posture
- Assume continuous reconnaissance — treat internet-facing asset exposure as perpetually scanned by capable adversaries. Implement continuous attack surface management (CASM) tooling.
- Hunt for Mirai-variant indicators on internal IoT assets — review for known Mirai IoCs, unusual outbound connections, and devices communicating with command-and-control patterns.
- Patch management discipline — the vulnerabilities Microscan targeted are years old. If your organization hasn't patched OpenSSL CVEs or Jenkins advisories from 2017-2024, you are already compromised or will be. Prioritize by exposure, not just CVSS.
- Geopolitical threat modeling — organizations in energy, transportation, and academia should incorporate PRC-linked threat actor TTPs into their threat models. Review CISA's prior Flax Typhoon advisory and map detections accordingly.
The Bigger Picture
Integrity Tech's operations illustrate a mature state-sponsored ecosystem where a single contractor provides persistent offensive capability across multiple campaign years. The U.S. government's disruption is valuable for intelligence collection and norm-setting, but defenders cannot wait for law enforcement to solve what is fundamentally an exposure management problem. The vulnerabilities being exploited are known, the patches exist, and the attack patterns are documented. The gap is execution.
Until organizations close the gap between knowing their external exposure and remediating it, tools like Microscan will continue to find easy targets — and the next takedown announcement will sound exactly like this one.