Skip to content
Esta página está disponible en español. Ver en español
tldlog.com

domain name news

Search
Menu
  • rss
  • glossary
  • stories
  • reading list
  • advertising
  • about
  • privacy
  • legal notice
en Language: English
  • Deutsch de deutsche Startseite (diese Seite gibt es nicht auf Deutsch)
  • English en this page in English
  • Español es esta página en español
  • Français fr page d'accueil en français (cette page n'a pas de version en français)
  • Italiano it pagina iniziale in italiano (questa pagina non ha una versione in italiano)
  • Português pt página inicial em português (esta página não tem versão em português)
  • Русский ru главная страница на русском (у этой страницы нет русской версии)
  • 中文 zh 中文版首页(本页没有中文版)
  • .featured
  • .policy
  • .gtld
  • .cctld
  • .market
  • .legal
  • .security
  • .business
  • .pricing
  • .all

10 oct 2026 13:28 .security link

originally published on 8 oct 2026

DOJ and FBI seize domains tied to alleged Chinese cyber espionage tools

report an error (by email)

see your reading list

in plain words

US law enforcement took control of seven internet domain name A readable internet name made of labels separated by dots. Full definition of domain name connected to hacking tools allegedly used by a China-based company. One tool scanned networks for weaknesses, and the other sent fake messages to trick people into giving up access. Officials say these tools were used against important systems like power and transport networks in several countries. Taking down the domains disrupts the tools but may not stop the hackers completely.

The US Department of Justice and FBI announced on October 8 that they had seized seven domain names connected to two alleged Chinese cyber espionage tools, Microscan and FishHub. Authorities allege the tools were used by actors linked to China-based Integrity Technology Group to target critical infrastructure and other networks in the United States, Asia and Europe.

According to US officials, Microscan was used to scan networks for exploitable vulnerabilities, while FishHub supported spear-phishing campaigns aimed at deceiving targeted recipients. Together, the two tools allegedly allowed operators to move from identifying weak points in a network to gaining unauthorized access. A court affidavit unsealed in connection with the case lists seven domains tied to the operation, though the Justice Department’s public statement names only six.

The seizures were designed to disrupt the online infrastructure supporting the two tools, rather than to immediately identify or arrest the individuals allegedly behind them. Officials say the targeted networks included systems tied to critical infrastructure such as power and transportation, extending beyond the United States to networks in Asia and Europe. The scope of any successful intrusions and the identities of affected organizations have not been independently confirmed.

domain seizure The takeover of a domain by authorities, normally under a court order. Full definition of domain seizure work by cutting off DNS Domain Name System The internet's directory that links domain names to computer addresses. Full definition of DNS resolution for the targeted names, severing access to services that depend on them. However, such action does not necessarily disable the servers behind the operation. Without further disruption of supporting infrastructure, operators could potentially restore service using new domains, altered DNS settings or alternative hosting.

Alongside the seizures, the FBI issued an advisory on October 8 offering network defenders guidance to identify and respond to activity associated with the alleged campaign. The Justice Department did not specify the exact timing of the seizures; the Associated Press reported the action at 18:12 UTC on October 8.

The court filing establishes the legal basis for seizing the domains, but the attribution to Integrity Technology Group and claims about which networks were targeted or compromised remain allegations made by the government. Whether the seizures have permanently disrupted Microscan and FishHub, or only temporarily interrupted them, remains unconfirmed.

Read on circleid.com, opens another website in a new tab

The original opens on the source's website.

tags

  • cybersecurity (tag)
  • china
  • dns-security (tag)
  • domain-abuse (tag)

sponsored space

This space is available for sponsorship.

Advertising on tldlog

related

  • Rare Cyrillic and Latin letters let attackers spoof URLs in Chromium browsers

    link theregister.com

  • GoBalance bug lets attackers hijack Tor .onion addresses, researchers say

    link thehackernews.com

  • Quad9 resists French pirate-site blocking order, faces huge daily fines from beIN

    link torrentfreak.com

recently saved

    See the full reading list
    • rss
    • glossary
    • stories
    • reading list
    • advertising
    • about
    • privacy
    • legal notice
    • tldlog on X, opens another website in a new tab

    No cookies. No trackers.