FBI seizes Flax Typhoon hacking-tool domains
Law Enforcement
Summary
Hide ▲
Show ▼
The FBI seized seven domains tied to Flax Typhoon's MicroScan and FishHub hacking tools, disrupting infrastructure used in breaches against critical infrastructure and other organizations worldwide.
Related Happenings
MicroScan and FishHub tool activity used for scanning, phishing, and exfiltration
Malware Activity
H score68
First: 09.10.2026 00:42
Last: 09.10.2026 00:42
Sources 1
How related:
The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide.
About this happening:
MicroScan and FishHub were used to support vulnerability scanning, spear-phishing, and data exfiltration, expanding intrusion reach against critical infrastr...
MicroScan and FishHub tool activity used for scanning, phishing, and exfiltration
Malware ActivityHow related: The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide.
About this happening: MicroScan and FishHub were used to support vulnerability scanning, spear-phishing, and data exfiltration, expanding intrusion reach against critical infrastr...
FBI seizure of NetNut proxy domains
Law Enforcement
H score33
First: 03.07.2026 12:35
Last: 03.07.2026 12:35
Sources 1
About this happening:
The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...
FBI seizure of NetNut proxy domains
Law EnforcementAbout this happening: The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...
FBI seizes NetNut and Popa botnet domains
Law Enforcement
H score34
First: 02.07.2026 22:27
Last: 02.07.2026 22:27
Sources 1
About this happening:
The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...
FBI seizes NetNut and Popa botnet domains
Law EnforcementAbout this happening: The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...
SocGholish malware downloader hijacking WordPress sites
Malware Activity
H score57
First: 18.06.2026 16:25
Last: 18.06.2026 16:25
Sources 1
About this happening:
SocGholish is a long-running JavaScript-based malware downloader also tracked as FakeUpdates that hijacks compromised WordPress sites to push fake browser update...
SocGholish malware downloader hijacking WordPress sites
Malware ActivityAbout this happening: SocGholish is a long-running JavaScript-based malware downloader also tracked as FakeUpdates that hijacks compromised WordPress sites to push fake browser update...
Silent Ransom Group US law firm IT impersonation campaign
Campaign
H score36
First: 29.05.2026 16:00
Last: 29.05.2026 16:00
Sources 1
About this happening:
Silent Ransom Group (SRG), also tracked as UNC3753, Chatty Spider, and Luna Moth, is running a financially motivated data theft extortion campaign against do...
Silent Ransom Group US law firm IT impersonation campaign
CampaignAbout this happening: Silent Ransom Group (SRG), also tracked as UNC3753, Chatty Spider, and Luna Moth, is running a financially motivated data theft extortion campaign against do...
Timeline
-
09.10.2026 00:42 2 articles · 1h ago
FBI seizes seven Flax Typhoon domains used for MicroScan and FishHub
Legal Policy Action UpdateThe FBI seized seven domains used by Flax Typhoon and China-based Integrity Technology Group to run MicroScan and FishHub, cutting off infrastructure used for vulnerability scanning, spear-phishing, remote access, and data theft against critical infrastructure and other organizations worldwide. The FBI, CISA, NSA, and international partners also issued a joint cybersecurity advisory describing the tooling, listing indicators of compromise, and urging organizations to patch vulnerable systems, disable unnecessary exposed services, and enforce multifactor authentication.
Show sources
- FBI disrupts Chinese hacking tools used to breach critical infrastructure — www.bleepingcomputer.com — 09.10.2026 00:42
- FBI disrupts Chinese hacking tools used to breach critical infrastructure — www.bleepingcomputer.com — 09.10.2026 00:42