On October 8, 2026, the Justice Department announced a court-authorized seizure of domains supporting two tools, Microscan and FishHub, operated by actors working for Beijing-based Integrity Technology Group. The same day, CISA, the FBI, NSA and international partners released a joint advisory tracing activity enabled by the company back to at least 2016. The company is the contractor behind the intrusion set Microsoft calls Flax Typhoon. This is the clearest recent example of a model that works better than its critics admit and worse than its sponsors hope.
What was actually taken down
According to the Justice Department release, Microscan is a reconnaissance tool that uses a Mirai-based botnet to scan victim networks for exploitable weaknesses. FishHub is a spear-phishing tool that downloads further malware, which gives an attacker remote access or exfiltrates files. The department listed six seized domains, one for Microscan access and five for FishHub malware delivery. Help Net Security reports seven, so the exact count is not settled in public reporting.
The documented victims span sectors. According to the Justice Department, between April and December 2022, Microscan was used to scan a South Carolina power company, a multinational non-governmental organization, airports in Japan and Poland, and Taiwanese natural gas and power companies. Two Taiwanese universities were scanned in August 2022 and March 2023, and the attackers broke into both networks soon after. FishHub was active as of March 2026, and the department says about 20 Taiwanese universities were confirmed victims.
The CISA announcement describes targets in government, critical manufacturing, healthcare, law enforcement and education across North America, Southeast Asia and Africa. Its language on intent is blunt: Chinese government-affiliated actors "continue to position themselves within critical infrastructure networks" to disrupt critical functions "at a future time of their choosing."
The strongest case for this approach
The case for aggressive, public disruption is serious and should be stated fairly. Contractors like Integrity Tech let a state scale intrusion work without carrying all of it on its own books, and tooling is the shared resource that makes that scale possible. As FBI Assistant Director Brett Leatherman put it, per The Record, "The PRC relies on contractors and enabling companies to expand the reach and scale of its malicious cyber activity." If the enabler is exposed, its clients lose infrastructure, and the contractor's reputation and commercial value suffer in a way that a defender's quiet patching never achieves. A multi-country advisory also gives network defenders indicators and vulnerability lists they could not assemble alone.
The department itself notes this is its second public technical disruption of Integrity Tech. In September 2024 it disrupted a Mirai botnet of more than 200,000 consumer devices, including routers, IP cameras, DVRs and network-attached storage. Repeating the exercise suggests the first one imposed cost but did not end the activity.
Why seizures alone do not protect anyone
That repetition is the main evidence for proportion. Domains are cheap to replace, and a scanner built on compromised consumer hardware can be rebuilt on the next batch of unpatched devices. The seized domains include look-alike names evoking Outlook, YouTube and LinkedIn, which tells you how easily the infrastructure can be re-registered under new brands. A takedown is a tempo-setting tool. It is not a durable fix.
The real exposure sits in the edge devices and unpatched systems that Microscan was built to find. The advisory's own mitigations are unglamorous: hunt for indicators of compromise, secure edge devices, patch the known exploited vulnerabilities it lists, and report suspicious activity to the FBI. That is where a policy agenda that favours innovation should concentrate. Manufacturers who ship consumer routers and cameras with default credentials and no update path create the raw material for Mirai-style botnets. Pressure there, through procurement standards and clear liability for negligent security, raises the cost for every attacker, not only this one.
Process matters for the open internet
Court-authorized seizure is also the right form for this kind of action. A judge reviewed the domain seizures, and the public record names the infrastructure and the victims. This is more accountable than informal pressure on registrars, and it avoids the collateral blocking that has plagued broader content-control regimes. The principle worth defending is narrowness: specific domains, specific malware, specific judicial authorization. Governments that want to copy the model for speech-related purposes should be reminded that its legitimacy comes from targeting operational attack infrastructure, not content.
The transparency of the multinational advisory deserves credit too. Public attribution to a named company is a lower-risk escalation than sanctions or retaliation, and it lets victims in Japan, Poland and Taiwan understand what happened to them years after the fact. The 2022 scanning was disclosed in 2026, which also shows how slow the loop remains.
What to watch
Three questions will show whether this is more than a news cycle. First, whether Integrity Tech or its clients reconstitute the tooling, as the 2024 precedent invites. Second, whether partner governments pair advisories with domestic requirements for device security and incident reporting. Third, whether private-sector defenders, especially small utilities and universities that were the confirmed victims, get usable help rather than a PDF.
Disruption is worth doing, and doing it with allies and a court order is the right way. But a policy that measures success by seized domains will keep seizing them. Success looks like fewer vulnerable devices for the next scanner to find.