Taiwan, which had about 20 universities, was not aware that its own e-mail system would appear on a United States list of victims of transnational cybercrime cases. On 8 October, the United States Department of Justice case file unsealed in the western part of Pennsylvania pointed to a web-invasive tool called FishHub: the operator was able to access remote control access, search documents and send information to a controlled server after entering the system with targeted fishing mail and malicious programs. United States investigators confirmed that there are about 20 universities in Taiwan that have been affected by their activities.
Another tool, MicroScan, was responsible for large-scale leak scanning, and its detection targets extended to a power company in South Carolina, the airports in Japan and Poland, the Taiwan Gas and Power Critical Establishment, and a transnational non-governmental organization. The Ministry of Justice announced that the seizure of seven Internet domain names relating to two sets of tools and remote access had been authorized by the courts, thereby blocking the ability of the attackers to continue to borrow the relevant facilities. (a) The seizure is a judicial action that has been carried out; Links between tools and specific attacks, persons and clients are drawn from case documents filed by the United States prosecution.
原始来源 · justice.gov美国司法部10月8日公告:查封七个域名、Microscan及FishHub工具justice.gov ↗Ministry of Justice announced the seizure of seven domain names, with only six names listed in the bulletin

In a bulletin dated 8 October, the United States Department of Justice clearly named c0cc.[. ]cc for the visit to Microscan and 98aicai [...]com, 98aicode [...]com, unlook3650 [...]com,youtubecard [...]com, linkedins [...]net for distribution in the FishHub malicious process. The six names correspond to two uses: the former favour network reconnaissance scanning; The latter five involved the delivery of malicious proceedings following fishing attacks. The Ministry of Justice stated that a total of seven domain names had been seized, but that its press release did not contain a complete list of seven; The seventh domain name is to be verified by a court warrant and affidavit and cannot be filled in in order to fill out all seven.
Targets and victims are also stratified. Ministry of Justice has included South Carolina Electricity Company, Japan and Polish airports, Taiwan Energy Enterprise and two universities as detection and scanning targets for Microscan; The identified organizations for the FishHub event include about 20 universities in Taiwan. Scanning, successful invasions and the amount of stolen data are not the same, nor does judicial material mean that all of the above-mentioned scanning targets are illegally controlled.
原始来源 · ic3.govFBI等部门10月8日联合技术通报:永信至诚关联网络活动指标ic3.gov ↗How listed cyber security companies enter the transnational attack chain
The Ministry of Justice contacted the Chinese company Integration Technology Group (Nunshin) and quoted its contract with the Chinese Government. (a) Young-shin is also running a commercial network security service with the Chinese Government project, and the development of tools, malicious use and commissioning of tasks may involve different subjects; The contractual relationship of the Government itself does not yet indicate who specifically ordered a particular attack. From corporate subjects, tool codes, server control, to attack samples, victims and sources of government mandates, multiple layers of subjects are involved. The United States judicial documents explain some of the technical links and the existence of a direct command relationship between government contracts and specific attacks remains key to the attribution of responsibility in this case.
This seizure has taken place and is a judicial fact that can be established; Whether an individual or legal person violates specific criminal law provisions and which attacks are under the direct direction of the State remain a matter of responsibility to be defined on a case-by-case basis and in court proceedings.
The most noteworthy feature of this case is the fact that the services providers have a real and verifiable corporate identity: the Shanghai Founding Company is a firm that has never been more successful.
Chinese name from the Internet hacker code to listed company
The United States Department of Justice has directed organizations operating or using these tools to the Integration Technology Group and linked to what the cyber security community calls the “Flax Typhoon” attacks. The English company ' s name is not a vague code. The Shanghai Stock Exchange website lists the stock code 688244 company, called Young-shin-Tech Group Inc., which is known in English as the Integrity Technology Group Inc.
The network of corporate officials identified itself as a cyber security test assessment, a cyber-shooting range and an anti-defense training service provider, and highlighted its business as a client of its political enterprise. Legal cybersecurity testing tools and unauthorized intrusion tools may technically use similar capabilities, but legal testing requires the authorization of the client. The specific allegations made by the United States on this occasion are that the same company controlled the tools used to scan third-party systems, hack and transmit information to the outside world by fishing. This has made the relationship between commercial companies and State intelligence activities no longer present only in the general label of “offer hacker organizations”.
The company ' s ownership of the Chinese Government ' s project contract was included in the United States Department of Justice Bulletin. The United States Treasury Department also sanctioned the United States of America for its network activities in January
- The 2026 round of closures was equivalent to law enforcement directly targeting the operational infrastructure of specific tools, in addition to the sanctions already in place. The fact that the company is being accused of being linked to State intelligence activities does not mean that all open business operations of the company are espionage activities. The United States is now pointing to specific tools, operating facilities and victimization networks, which determine the actual scope of enforcement action.
Two sets of tools divided: first to identify gaps and then to get mail and documents
原始来源 · open.sseinfo.com上交所披露:永信至诚中文及英文公司名、股票代码688244open.sseinfo.com ↗MicroScan is the first to look like an automated reconnaissance device. According to the Ministry of Justice, it has been able to perform a gap scanning by means of a network of devices infected by the Mirai family malicious process, and to do so through other channels. Internet routers, cameras and storage equipment, once illegally controlled, can be a springboard for the attackers to cover the real address and to send the scanned traffic in a scattered manner. Often the owner of such equipment is not the target itself, but is uninformed and is borrowed as a network activity infrastructure.
FishHub is in the phase of further invasion. According to judicial sources, fishing mail allowed the attackers to enter the system first, and FishHub then downloaded malicious programs that allowed customers to access or locate specific documents remotely and to transmit them to servers under his control. The United States Government lists five domain names related to malicious program transmissions: 98aicai [...]com, 98aicode [...]com, outlook3650 [...]com, youtubecard [...]com and linkedins [...]net; One of the domains used for the scanning tool is c0cc.[. ]cc. The string is the seized infrastructure evidence in the case file and is not a link that should be accessed by the average reader.
About 20 universities in Taiwan were affected by FishHub ' s activities; Energy enterprises and airports appear on the MicroScan scan list. Scan list of targets does not amount to a list of victims whose confidentiality has been stolen; The fact that some of the colleges confirmed victimization does not mean that all listed facilities are exposed to data leakage. The United States text distinguished between technical acts and allowed the chain of responsibility to be further tracked.
Two United States operations targeting the same tools and resources
In September 2024, the United States FBI had, under the authority of the Court, undermined a Mirai zombie network linked to the whole of the faith. The Ministry of Justice announced that year on a scale of over 200,000 infected equipment worldwide, including small routers, web cameras, hard disk video recorders and network storage equipment. The FBI was able to release part of the infection by controlling attacks on network facilities and sending orders to the infected equipment to release the malicious process; The Ministry of Justice stated that it did not read the information on the equipment holder.
On 8 October 2026, the United States court authorized the seizure of seven domain names for the operational corridor and malicious process distribution facilities for MicroScan, FishHub and the company of the United States of America. The Ministry of Justice also disclosed that the investigation was conducted by the FBI offices in San Diego and Baltimore, with substantive assistance from the Japanese Police Office; The United States and its cooperating agencies issue threat activity indicators for access to the network of affected universities, energy enterprises and airports. The case has entered the phase of court arrest, transnational police collaboration and victim network protection, with more than one diplomatic declaration.
原始来源 · justice.gov美国司法部2024年案卷:查封前次Mirai僵尸网络justice.gov ↗Two of the law enforcement efforts exposed an infrastructure problem that has been going on for many years: the first dismantling of the network of controlled equipment and the second targeting the gap scanning and mail intrusion tools. If clients have continued access to networks of others through a platform provided by a company, the boundary between this “network security business” and government-supported intelligence gathering must be defined by specific contracts, financial flows, operational logs and evidence of victimization.
The Beijing Foreign Ministry responded on 9 October, stating that it opposed cyberattacks and false accusations, stressing that China and the United States should work together to address cybersecurity risks. The diplomatic stance of China and the domain sealing of the United States courts have taken place at different levels: the former is a political position and the latter is an enforcement operation that has taken place. What would really test the effectiveness of this round in the future is not the determination of who is tougher, but the ability of the network of the affected schools and critical facilities to cut off the malicious and persistent link and the ability to trace the evidence back to the operational and the client.
The most noteworthy case is the connection between State procurement, private security tools and the affected school: who purchased the capability to scan and invade, who authorized the operator to use it, and who assumed the consequences of the invasion. The Chinese Government has placed a large amount of network capacity in commercial suppliers, which could blur the line between national action and market services; The more so, the less the government contract and the implementer should hide behind the abstract “blacker” label.
原始来源 · apnews.com美联社:FBI查封中国黑客工具及网络安全调查apnews.com ↗
Article discussion
Verified members can discuss this report publicly and manage their own content.
Checking member sign-in status…