← All articles

· Graybridge Software

MicroScan and FishHub: US Disrupts Two China-Linked Hacking Tools

On October 8, 2026, the United States announced it had disrupted two tools used by Chinese state-sponsored groups, including Flax Typhoon, against critical infrastructure. Here is what has emerged and what OT and IT leaders can do right away.

OT securityFlax TyphoonIoT botnetcritical infrastructure

On Thursday, October 8, 2026, the United States announced it had taken down two tools used by attack groups sponsored by the Chinese state. SecurityWeek reported the news on October 9. The tools are called MicroScan and FishHub, and according to the reports they were used against critical infrastructure in the US and abroad.

A note on method: the description of the SecurityWeek article refers to a seizure ("seized"), while the text we were able to review uses the term "disruption." The legal and technical details of the operation are therefore not confirmed at this time, and here we speak of a disruption of operations.

The two tools and who built them

Both tools were developed by Integrity Technology Group (Integrity Tech). Their roles are complementary:

  • MicroScan is used for vulnerability scanning, that is, reconnaissance of the victim's systems.
  • FishHub enables network intrusions through spear phishing, meaning targeted email messages.

The groups that used them include Flax Typhoon, along with other Chinese APT groups.

The IoT botnet behind the reconnaissance

According to the United States, Integrity Tech allegedly used a variant of the Mirai malware to build a botnet of IoT devices. This botnet reportedly supported the reconnaissance carried out with MicroScan on victims' networks. In practice, compromised and seemingly mundane devices become the starting point from which more important networks are observed and probed.

Known targets

The targets named include a US electric utility, non-governmental organizations, and airports in Japan and Poland. The list continues with a Taiwan-related target, but the text available to us cuts off there: the full list of victims and any technical indicators should be verified in the original source.

Why it matters to those running industrial networks

The key point for plant, utility and infrastructure managers is that compromised IoT devices are being used to scan industrial and utility networks. Shutting down an operation does not eliminate the risk: similar tools and techniques can be rebuilt, and the exposed attack surface stays the same until it is reduced.

Enforcement action reduces the attacker's capability, but it does not close the doors that were already open.

What to do in practice

The lessons from this case match well-known OT security best practices:

  • Inventory your exposure: check which OT and edge devices are reachable from the internet, and remove or protect those that should not be.
  • Patch quickly, prioritizing externally accessible systems.
  • Harden email against spear phishing with filtering, sender authentication and targeted training.
  • Monitor scanning activity directed at your networks, particularly at the perimeter and on the boundary segments between IT and OT.
  • Keep IoT devices under control, since they can be compromised and used as a base for reconnaissance.

What remains to be clarified

As of October 9, 2026, several points remain open: the precise method of the intervention, the full list of victims, and the indicators of compromise. Before updating detection rules or internal procedures, it is worth consulting the full text of the source and the official communications from the authorities.