Federal agents moved swiftly last week. They seized seven internet domains that powered two sophisticated hacking platforms run by a China-based company with deep government ties. The action, announced October 8, struck at the heart of a sprawling operation that fed stolen data to Beijing while masking its origins behind networks of compromised routers, cameras and other everyday devices.
Integrity Technology Group operated the tools known as Microscan and FishHub. Court documents describe the firm as a for-profit contractor that built and sold cyber capabilities to Chinese intelligence and military clients. Its work reached far beyond any single breach. One platform scanned for weaknesses across thousands of networks. The other delivered phishing lures and helped maintain long-term access once inside.
But the real power lay in the infrastructure those tools fed. Hackers assembled massive collections of hijacked internet-connected devices. They turned them into exit nodes that made Chinese-originated attacks appear to come from residential addresses in the United States or allied countries. Traffic blended with legitimate proxy services. Defenders faced difficulty distinguishing friend from foe. And the company profited from it all.
The latest seizures build on earlier efforts. In 2024 authorities disrupted a botnet of more than 200,000 consumer devices linked to the same actors. That action targeted similar residential proxy capabilities. Yet the operation adapted. New domains surfaced. Scanning continued. The pattern shows a contractor model that lets Beijing expand its reach while maintaining distance.
“Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure,” said Brett Leatherman, assistant director of the FBI’s Cyber Division, in the Department of Justice announcement.
Targets spanned sectors. A power company in South Carolina. Airports in Japan and Poland. Natural gas and electricity providers in Taiwan. Universities there as well. A multinational nongovernmental organization. Government agencies, manufacturers, healthcare providers, law enforcement and schools all appeared in the crosshairs, according to the joint advisory from the FBI, CISA, NSA and partners in the UK, Australia, Canada, Japan, New Zealand and Spain.
The hackers combined speed with patience. Automated scanners probed for exposed services on ports used by FTP, SSH, web applications and Microsoft Exchange. They tested more than 1,300 scripts against common software like WordPress, Jenkins, Oracle WebLogic and Apache Struts. When automated tools found a way in, hands-on operators took over. They deployed custom webshells, dumped credentials, and installed legitimate SoftEther VPN software to blend into normal traffic.
One especially troubling discovery involved a web application. It gave third parties direct access to mailboxes the hackers had already compromised. Emails from government organizations, law enforcement, healthcare systems and religious institutions in Southeast Asia flowed through this portal. The FBI and six partner agencies detailed the setup in their October 8 advisory, first covered by The Hacker News.
So the espionage served multiple masters. Some data went to Chinese state clients. Other material apparently fed a commercial marketplace. The contractor model blurs lines between government direction and private profit. It also complicates attribution. Traffic from a hacked home router in Ohio looks nothing like an attack launched from a server in Shanghai.
This approach echoes an earlier campaign dismantled in August. That one involved platforms called QScan and QTRouter, run by a different Nanjing company. QScan infected IoT devices worldwide. QTRouter routed attack traffic through them plus commercial proxies. The goal remained the same: hide the hand of the People’s Republic of China. Black Lotus Labs researchers called it a “quartermaster model” that supplied reconnaissance and routing services to multiple threat groups.
Yet the Integrity Technology Group operation stands out for its scale and persistence. It began as early as 2020. Activity continued into 2024. Even after the 2024 botnet takedown, new infrastructure appeared. The seven domains seized last week — including c0cc.cc for the scanning platform and several tied to phishing and VPN persistence — had remained active into September 2026.
Officials described the effort as indiscriminate. “We aim to remove the capability from the threat actors. We target their infrastructure, their money, and their tools,” FBI Cyber Division Deputy Assistant Director Jason Bilnoski told the Associated Press. He called the operation reckless.
The joint advisory offers defenders a roadmap. Patch known vulnerabilities quickly. The list includes several from 2016 through 2023 that the actors exploited successfully. Monitor edge devices closely. They often sit outside normal security oversight yet provide the foothold for deeper access. Audit VPN configurations. The attackers favored legitimate SoftEther clients renamed to look like system processes.
Apply firmware updates to routers and IoT hardware. Isolate critical systems from internet-facing equipment. Watch for unusual scanning from residential IP ranges. And review web applications for signs of data exfiltration or unauthorized mailbox access.
None of these steps guarantee safety. The contractor ecosystem gives Chinese operators redundancy. Take down one set of domains and another appears. Compromise one botnet and fresh devices join the fold. The model scales. It generates revenue. And it feeds a steady stream of intelligence back to Beijing.
Recent coverage highlights the challenge. Cybersecurity Dive reported on the broader pattern of using private firms to expand espionage reach. Nextgov/FCW noted how the seizures coincided with warnings to critical infrastructure operators worldwide. And Bleeping Computer detailed the specific domains and their roles in both scanning and maintaining access.
Even so, the October action marks progress. It renders the current versions of Microscan and FishHub inoperable. It exposes the contractor’s central role. And it signals to other would-be enablers that their infrastructure sits in American crosshairs.
The larger contest continues. Chinese cyber operators have spent years perfecting ways to hide in plain sight. They recruit contractors who build tools, rent servers, infect devices and sell access. The result looks less like a traditional intelligence service and more like a sophisticated marketplace where espionage and profit overlap.
American agencies keep striking at the infrastructure. They seize domains. They publish indicators. They coordinate with allies. Each disruption raises the cost of doing business. Yet the underlying incentives remain. As long as compromised residential devices provide plausible deniability, the proxy networks will regenerate.
Organizations cannot wait for the next seizure. They must assume their edge devices already face constant probing. Their email systems sit on targeted lists. And their critical infrastructure draws interest not just from state actors but from the contractors who serve them. The defenses that work start with visibility, rapid patching and a healthy suspicion of any traffic that looks too local to be foreign.