Advisory
Published 2026-10-08
Verified 2026-10-09

CISA/FBI/NSA + ACSC and partners (AA26-281A): China-linked Integrity Technology Group enables actors (TTPs consistent with Flax Typhoon) stealing email worldwide; DOJ/FBI seize MicroScan and FishHub domains

On 8 October 2026, CISA, FBI, NSA and international partners including Australia's ACSC published joint Cybersecurity Advisory AA26-281A on China-linked threat actors enabled by Integrity Technology Group (Integrity Tech), a China-based company with government links that builds or acquires cyber tools, hosts infrastructure and compromises networks. Observed TTPs are consistent with activity tracked as Flax Typhoon, Ethereal Panda and Red Juliett (vendor names may not map 1:1). Actors combine automated scanning (including MicroScan with 1,300+ scripts), large IoT botnets, password spraying against Microsoft 365/Exchange, VPN persistence and hands-on exploitation to steal email and credentials, and have run a portal giving third parties access to stolen mail. Same day, the US Justice Department and FBI announced court-authorised seizures of seven domains used for MicroScan and FishHub spear-phishing/malware delivery; scanning targets cited in court papers include a South Carolina power company, airports in Japan and Poland, Taiwanese energy firms and universities. Integrity Tech was previously sanctioned by the US (Jan 2025) and UK (Dec 2025); a 2024 FBI action disrupted its Raptor Train botnet. Mitigations in the advisory include disabling unused services/ports, sanitising web inputs, MFA everywhere, and timely patching of listed n-day flaws. Primary: CISA AA26-281A (ACSC co-author); DOJ seizure PR; wire: BleepingComputer / The Hacker News.

Product
n/a (joint advisory / law-enforcement disruption — Integrity Tech tooling MicroScan and FishHub; Flax Typhoon-consistent TTPs)
Versions
n/a — apply AA26-281A mitigations; patch n-day flaws listed in the advisory
Exploited in Australia?
unknown
Patch to
Read AA26-281A. Prioritise MFA on email and admin paths, lock down edge devices and unused services, hunt for Integrity Tech / MicroScan / FishHub infrastructure in logs, and patch the older publicly known CVEs called out in the advisory. Report suspected activity to ASD's ACSC.

Primary: CISA — AA26-281A: Chinese government-linked cyber threat actors combine automated and hands-on hacking tools (8 Oct 2026; ACSC co-author) · Vendor: US Department of Justice — Justice Department and FBI seize MicroScan and FishHub tools (8 Oct 2026) · BleepingComputer — FBI disrupts Chinese hacking tools used to breach critical infrastructure (8 Oct 2026)

australia network identity