supply-chaintrade-pressNewsThe Broadside2 min read

DOJ Seizes Integrity Tech Tools in Second Flax Typhoon Disruption

The seizure reframes supply chain risk: Integrity Tech wasn't a compromised vendor but a state-contracted enabler building purpose-built tools for campaigns dating to 2017.


TL;DR

The Justice Department and FBI obtained court-authorized seizures of Microscan, a vulnerability scanning tool in use since 2017, and FishHub, a spear-phishing platform, both built by Beijing-based Integrity Technology Group for the Flax Typhoon campaign. Integrity Tech holds PRC government contracts; this is the second disruption of its operations in two years, following the 2024 botnet takedown. CISA, the NSA, and agencies from six allied nations issued a joint advisory warning that Integrity Tech-enabled actors are positioned inside OT systems with the aim of disrupting critical functions at a future time of their choosing.

The Justice Department and FBI announced court-authorized seizures Thursday of two hacking tools, Microscan and FishHub, that Beijing-based Integrity Technology Group built and operated for state-directed intrusions into U.S. and allied critical infrastructure. It's the second disruption of Integrity Tech's operations in two years, following the September 2024 takedown of a botnet of more than 200,000 consumer devices the company controlled.

Microscan, in use since 2017, is a vulnerability reconnaissance tool that runs penetration-testing scripts against target websites. Its victims include a South Carolina power utility, Japanese and Polish airports, and Taiwanese natural gas and power-sector operators. FishHub streamlined spear-phishing: once attackers breached a network, FishHub let them deposit malware and maintain remote access. That remote access was used against roughly 20 Taiwanese universities, according to court documents.

The operational logic is methodical. Integrity Tech's actors target edge devices that organizations rarely monitor closely, aiming for long-term, quiet persistence. Chris Butera, CISA's acting executive assistant director for cybersecurity, put it bluntly: "Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology systems, with the aim of disrupting critical functions at a future time of their choosing."

The contractor-as-proxy problem

CISA, the NSA, and agencies from Australia, Japan, the U.K., Spain, New Zealand, and Canada issued a joint 58-page advisory alongside the seizure. It documents Integrity Tech's role as what the FBI's Brett Leatherman called an "enabler": a contractor that expands the reach and scale of PRC cyber operations by acquiring, developing, and hosting tools other groups then use. The advisory ties Integrity Tech-enabled activity to Flax Typhoon, Ethereal Panda, and Red Juliett.

For organizations that treat vulnerability scanning logs as noise or assume edge-device telemetry is benign, the advisory is a hard reset. The threat isn't a compromised vendor slipping malware into a software update. It's a state-contracted company building purpose-built offensive tooling, operating it for years, and handing access to government-directed intrusion campaigns. That's a supply chain problem of a different shape entirely.


Published ·Deep Fathom