---
id: "deb2e9df-f97d-46e2-b08d-67958e2fb121"
kind: "link"
title: "DOJ and FBI seize domains tied to alleged Chinese cyber espionage tools"
language: "en"
section: "security"
date: "2026-10-10T13:28:32Z"
updated: "2026-10-10T13:28:32Z"
canonical: "https://tldlog.com/l/doj-fbi-seize-domains-tied-alleged-chinese-cyber-espionage/"
origin: "master"
translations:
  es: "https://tldlog.com/es/l/doj-fbi-incautan-dominios-vinculados-presuntas-herramientas/"
source:
  name: "circleid.com"
  url: "https://circleid.com/posts/us-seizes-seven-domains-linked-to-alleged-chinese-cyber-espionage-operation"
  language: "en"
  date: "2026-10-08T15:56:00Z"
---

# DOJ and FBI seize domains tied to alleged Chinese cyber espionage tools

## in plain words

US law enforcement took control of seven internet domain names connected to hacking tools allegedly used by a China-based company. One tool scanned networks for weaknesses, and the other sent fake messages to trick people into giving up access. Officials say these tools were used against important systems like power and transport networks in several countries. Taking down the domains disrupts the tools but may not stop the hackers completely.

The US Department of Justice and FBI announced on October 8 that they had seized seven domain names connected to two alleged Chinese cyber espionage tools, Microscan and FishHub. Authorities allege the tools were used by actors linked to China-based Integrity Technology Group to target critical infrastructure and other networks in the United States, Asia and Europe.

According to US officials, Microscan was used to scan networks for exploitable vulnerabilities, while FishHub supported spear-phishing campaigns aimed at deceiving targeted recipients. Together, the two tools allegedly allowed operators to move from identifying weak points in a network to gaining unauthorized access. A court affidavit unsealed in connection with the case lists seven domains tied to the operation, though the Justice Department’s public statement names only six.

The seizures were designed to disrupt the online infrastructure supporting the two tools, rather than to immediately identify or arrest the individuals allegedly behind them. Officials say the targeted networks included systems tied to critical infrastructure such as power and transportation, extending beyond the United States to networks in Asia and Europe. The scope of any successful intrusions and the identities of affected organizations have not been independently confirmed.

Domain seizures work by cutting off DNS resolution for the targeted names, severing access to services that depend on them. However, such action does not necessarily disable the servers behind the operation. Without further disruption of supporting infrastructure, operators could potentially restore service using new domains, altered DNS settings or alternative hosting.

Alongside the seizures, the FBI issued an advisory on October 8 offering network defenders guidance to identify and respond to activity associated with the alleged campaign. The Justice Department did not specify the exact timing of the seizures; the Associated Press reported the action at 18:12 UTC on October 8.

The court filing establishes the legal basis for seizing the domains, but the attribution to Integrity Technology Group and claims about which networks were targeted or compromised remain allegations made by the government. Whether the seizures have permanently disrupted Microscan and FishHub, or only temporarily interrupted them, remains unconfirmed.

Source: [circleid.com](https://circleid.com/posts/us-seizes-seven-domains-linked-to-alleged-chinese-cyber-espionage-operation)
