The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In October 2026, the FBI seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate MicroScan and FishHub hacking tools targeting critical infrastructure worldwide. The operation disrupted China-based Integrity Technology Group's vulnerability scanning platform and spear-phishing tool, which had successfully breached power companies, airports, universities, and energy providers across the United States, Taiwan, Japan, and Poland. Investigators discovered stolen data from over 20 organizations on servers linked to the operation, including six Taiwanese universities.

This incident highlights the escalating sophistication of state-sponsored supply chain attacks targeting critical infrastructure, demonstrating how nation-state actors increasingly rely on third-party contractors to expand their cyber operations while maintaining plausible deniability.

Why This Matters Now

Critical infrastructure faces unprecedented threats from state-sponsored actors using contractor networks to obscure attribution while targeting vulnerabilities in power grids, transportation systems, and telecommunications networks that underpin national security.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Flax Typhoon operated MicroScan for vulnerability scanning and FishHub for spear-phishing attacks, along with a Mirai botnet to conduct widespread network reconnaissance and data exfiltration.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained Flax Typhoon's cross-network lateral movement and reduced their ability to maintain persistent access across the 20+ compromised organizations through workload segmentation and east-west traffic enforcement.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: CNSF visibility and monitoring would likely have detected the extensive vulnerability scanning activity across multiple cloud workloads, potentially limiting the attackers' ability to comprehensively map the attack surface across distributed infrastructure environments.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation policies would likely have constrained privilege escalation by limiting compromised service accounts to their designated workload boundaries, reducing the scope of elevated access across segmented cloud environments and preventing broad administrative privilege acquisition.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic inspection and enforcement would likely have significantly constrained lateral movement across network segments, limiting the attackers' ability to traverse between workloads and reducing their reach across the geographically distributed infrastructure of multiple victim organizations.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility and control mechanisms would likely have detected the persistent SoftEther VPN connections and suspicious domain communications across cloud environments, potentially constraining the attackers' ability to maintain coordinated command and control across multiple victim organizations simultaneously.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security policies would likely have constrained large-scale data exfiltration by detecting and limiting unauthorized outbound transfers, potentially reducing the volume of sensitive data successfully transmitted to attacker-controlled servers and limiting cross-organizational data aggregation capabilities.

Impact (Mitigations)

The overall campaign impact would likely have been substantially reduced, with compromises potentially limited to isolated workload segments rather than enabling the broad cross-organizational access that ultimately affected universities, power companies, airports, and energy providers across four countries.

Impact at a Glance

Affected Business Functions

  • Critical Infrastructure Operations
  • Power Grid Management
  • Network Security
  • Academic Research Systems
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Sensitive data and files from over 20 organizations including six universities in Taiwan, critical infrastructure operational data from power companies, airport systems, and natural gas providers. Email communications and Active Directory credentials were also compromised and exfiltrated.

Recommended Actions

  • • Implement Zero Trust Segmentation with identity-based policies and microsegmentation to prevent lateral movement across critical infrastructure networks
  • • Deploy Egress Security & Policy Enforcement with FQDN filtering and data loss prevention to detect and block unauthorized data exfiltration to attacker-controlled domains
  • • Establish Multicloud Visibility & Control with centralized policy management and traffic observability to detect anomalous scanning activities and suspicious automation patterns
  • • Enable Threat Detection & Anomaly Response capabilities to identify covert tools, remote access software, and baseline deviations indicative of persistent threat actor presence
  • • Implement Encrypted Traffic protection with MACsec/IPsec and high performance encryption to secure data in transit and prevent packet sniffing during exfiltration operations

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image