Executive Summary
In October 2026, the FBI seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate MicroScan and FishHub hacking tools targeting critical infrastructure worldwide. The operation disrupted China-based Integrity Technology Group's vulnerability scanning platform and spear-phishing tool, which had successfully breached power companies, airports, universities, and energy providers across the United States, Taiwan, Japan, and Poland. Investigators discovered stolen data from over 20 organizations on servers linked to the operation, including six Taiwanese universities.
This incident highlights the escalating sophistication of state-sponsored supply chain attacks targeting critical infrastructure, demonstrating how nation-state actors increasingly rely on third-party contractors to expand their cyber operations while maintaining plausible deniability.
Why This Matters Now
Critical infrastructure faces unprecedented threats from state-sponsored actors using contractor networks to obscure attribution while targeting vulnerabilities in power grids, transportation systems, and telecommunications networks that underpin national security.
Attack Path Analysis
Flax Typhoon/Integrity Tech conducted state-sponsored espionage using MicroScan vulnerability scanning platform to identify weaknesses in critical infrastructure, followed by FishHub spear-phishing to deliver malware, establish persistent access via SoftEther VPN, conduct lateral movement across compromised networks, maintain command and control through multiple domains, and exfiltrate sensitive data from over 20 organizations including universities and critical infrastructure providers.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers used MicroScan vulnerability scanning platform with 1,300+ penetration testing scripts to identify security flaws in critical infrastructure, targeting CVEs including Apache Struts RCE, Pulse Secure VPN file read, and GitLab RCE vulnerabilities across power companies, airports, and universities
Related CVEs
CVE-2015-3306
CVSS 10ProFTPD unauthorized file read vulnerability allowing attackers to read arbitrary files on the system.
Affected Products:
ProFTPD ProFTPD – < 1.3.5
Exploit Status:
exploited in the wildCVE-2016-3081
CVSS 8.1Apache Struts remote code execution vulnerability allowing attackers to execute arbitrary code via multipart requests.
Affected Products:
Apache Struts – 2.3.20 - 2.3.28.1, 2.5.0 - 2.5.2
Exploit Status:
exploited in the wildCVE-2019-11510
CVSS 10Pulse Secure VPN arbitrary file read vulnerability allowing unauthenticated attackers to read arbitrary files.
Affected Products:
Pulse Secure Connect Secure – < 8.2R12.1, < 8.3R7.1, < 9.0R3.4
Exploit Status:
exploited in the wildCVE-2021-22205
CVSS 10GitLab remote code execution vulnerability allowing attackers to execute arbitrary code via image upload.
Affected Products:
GitLab GitLab – 13.10.0 - 13.10.2, 13.9.0 - 13.9.6, < 13.8.8
Exploit Status:
exploited in the wildCVE-2014-6278
CVSS 8.8GNU Bash Shellshock vulnerability allowing remote code execution through environment variable manipulation.
Affected Products:
GNU Bash – < 4.3
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Gather Victim Network Information: Domain Properties
Active Scanning: Scanning IP Blocks
Phishing: Spearphishing Attachment
Exploit Public-Facing Application
Brute Force: Password Spraying
Protocol Tunneling
Exfiltration Over C2 Channel
Data from Local System
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – External Vulnerability Scanning
Control ID: 11.3.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Critical power grid infrastructure directly targeted by Chinese state-sponsored Flax Typhoon operations, requiring enhanced encrypted traffic monitoring and zero trust segmentation controls.
Airlines/Aviation
Airport infrastructure in Japan and Poland specifically scanned by MicroScan platform, exposing aviation systems to lateral movement attacks and data exfiltration risks.
Higher Education/Acadamia
Multiple universities breached following vulnerability scans, with six Taiwanese institutions having data stolen via FishHub spear-phishing campaigns and unauthorized remote access tools.
Government Administration
U.S. government agencies targeted by Integrity Technology Group tools, requiring immediate egress security enforcement and multicloud visibility to prevent state-sponsored data exfiltration.
Sources
- FBI disrupts Chinese hacking tools used to breach critical infrastructurehttps://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/Verified
- Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated by Chinese Government-Linked Hackershttps://www.justice.gov/opa/pr/justice-department-and-fbi-seize-vulnerability-scanning-and-spear-phishing-tools-operatedVerified
- FBI Seizure Affidavit - Flax Typhoon Infrastructurehttps://www.justice.gov/usao-wdpa/media/1464921/dl?inline=Verified
- CISA Joint Cybersecurity Advisory - Chinese Government-Linked Hackershttps://www.cisa.gov/news-events/cybersecurity-advisories/aa26-282aVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained Flax Typhoon's cross-network lateral movement and reduced their ability to maintain persistent access across the 20+ compromised organizations through workload segmentation and east-west traffic enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: CNSF visibility and monitoring would likely have detected the extensive vulnerability scanning activity across multiple cloud workloads, potentially limiting the attackers' ability to comprehensively map the attack surface across distributed infrastructure environments.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation policies would likely have constrained privilege escalation by limiting compromised service accounts to their designated workload boundaries, reducing the scope of elevated access across segmented cloud environments and preventing broad administrative privilege acquisition.
Control: East-West Traffic Security
Mitigation: East-west traffic inspection and enforcement would likely have significantly constrained lateral movement across network segments, limiting the attackers' ability to traverse between workloads and reducing their reach across the geographically distributed infrastructure of multiple victim organizations.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control mechanisms would likely have detected the persistent SoftEther VPN connections and suspicious domain communications across cloud environments, potentially constraining the attackers' ability to maintain coordinated command and control across multiple victim organizations simultaneously.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have constrained large-scale data exfiltration by detecting and limiting unauthorized outbound transfers, potentially reducing the volume of sensitive data successfully transmitted to attacker-controlled servers and limiting cross-organizational data aggregation capabilities.
The overall campaign impact would likely have been substantially reduced, with compromises potentially limited to isolated workload segments rather than enabling the broad cross-organizational access that ultimately affected universities, power companies, airports, and energy providers across four countries.
Impact at a Glance
Affected Business Functions
- Critical Infrastructure Operations
- Power Grid Management
- Network Security
- Academic Research Systems
Estimated downtime: 7 days
Estimated loss: $5,000,000
Sensitive data and files from over 20 organizations including six universities in Taiwan, critical infrastructure operational data from power companies, airport systems, and natural gas providers. Email communications and Active Directory credentials were also compromised and exfiltrated.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies and microsegmentation to prevent lateral movement across critical infrastructure networks
- • Deploy Egress Security & Policy Enforcement with FQDN filtering and data loss prevention to detect and block unauthorized data exfiltration to attacker-controlled domains
- • Establish Multicloud Visibility & Control with centralized policy management and traffic observability to detect anomalous scanning activities and suspicious automation patterns
- • Enable Threat Detection & Anomaly Response capabilities to identify covert tools, remote access software, and baseline deviations indicative of persistent threat actor presence
- • Implement Encrypted Traffic protection with MACsec/IPsec and high performance encryption to secure data in transit and prevent packet sniffing during exfiltration operations



