According to the Justice Department announcement, Integrity Tech built a botnet of internet-connected devices infected with a Mirai malware variant. The company used this network, alongside other infrastructure, to run Microscan against potential targets and identify weaknesses its clients could later exploit.
It is important to note that a scan can find possible entry points into a network, but it does not prove that the network has been breached. Some of the targets for these scans included a power company in South Carolina, airports in Japan and Poland, natural gas and power companies in Taiwan, a multinational NGO, and two universities in Taiwan.
The joint cybersecurity advisory describes MicroScan as a Python-based web application containing more than 1,300 penetration testing scripts. These scripts checked websites and services for specific vulnerabilities, including weaknesses affecting Oracle WebLogic Server, WordPress, Jenkins, Apache Struts, OpenSSL, and Juniper ScreenOS. Investigators traced its use back to at least 2017.
The dashboard reproduced in the advisory shows vulnerability totals, scan status, and plugin rankings. It illustrates how operators could manage large numbers of findings through a central interface. The seized domain c0cc[.]cc provided access to Microscan, making it a direct target for disrupting that scanning workflow.
FishHub Supported Spear Phishing Attack
FishHub served a different purpose. Prosecutors allege that the tool supported spear phishing, then downloaded additional malware after attackers gained an initial foothold. That malware could give Integrity Tech clients remote network access or locate specific files and transfer them to servers controlled by the company.
Confirmed FishHub victims included approximately 20 Taiwanese universities. This is separate from the two Taiwanese universities named among Microscan scanning targets; the announcement does not establish whether those groups overlap. Keeping those figures distinct avoids confusing systems checked for weaknesses with networks confirmed as victims of FishHub activity.
Five seized domains supported malware delivery: 98aicai[.]com, 98aicode[.]com, linkedinns[.]net, outlook3650[.]com, and youtubecard[.]com.
A seventh domain, 98aiblog[.]com, was tied to SoftEther VPN software used to maintain unauthorized remote access. Together with c0cc[.]cc, these domains covered scanning access, malware delivery, and persistent connections to compromised systems.
The latest seizures follow the September 2024 court-authorized disruption of an Integrity Tech botnet containing more than 200,000 consumer devices worldwide. That earlier network included routers, IP cameras, digital video recorders, and network-attached storage devices. Attackers used those compromised devices to disguise malicious activity as ordinary internet traffic.
Cybersecurity News previously reported Flax Typhoon’s botnet exploitation of 66 vulnerabilities, providing background on the group’s use of weaknesses in routers, connected devices, and web-facing applications. The new action focuses on infrastructure supporting scanning and intrusion tools, showing why disrupting one botnet does not necessarily end the wider hacking operation

Leave a Reply