DNS Benchmark ProReal-time DoH latency analysis

Security

Data Breach Update: FBI Seizes China Email-Theft Tools

Published October 9, 2026 · DNS Benchmark Pro Editorial · Reading time: 7 minutes

TL;DR — On 8 October 2026 the US Department of Justice and the FBI announced the court-authorized seizure of seven domains behind MicroScan and FishHub, two intrusion tools attributed to the US-sanctioned Chinese contractor Integrity Technology Group. The same day, ten agencies across seven countries published joint advisory AA26-281A, describing a pipeline that ran automated scanning against eight long-patched CVEs, sprayed Microsoft Exchange and Office 365 with the open-source EBurst tool, stole credentials by DCSync, hid persistence inside legitimate SoftEther VPN clients, and exfiltrated mailboxes into a web application that handed third parties access to stolen email by URL argument. This data breach update covers what was seized, what to hunt for, and why none of the exploited flaws was a zero day.

The most instructive data breach update of the week is not a new vulnerability. It is a detailed, ten-agency account of an email-theft business that ran for years on software most organisations patched a decade ago. Announced on Thursday 8 October by the US Attorney’s Office for the Western District of Pennsylvania, the seizures took down the infrastructure behind MicroScan and FishHub — and the accompanying ten-agency advisory is unusually specific about how the stolen mail was monetised.

What the Justice Department actually seized

Seven domains, taken under court order and now serving seizure notices. One provided Integrity Tech’s access to MicroScan. Five delivered FishHub’s follow-on malware. The seventh fronted unauthorised remote administration software that stitched several victim networks back to an Integrity Tech server.

Announcing the action, US Attorney Troy Rivetti’s office quoted FBI Cyber Division Assistant Director Brett Leatherman, who framed the company’s role plainly: Integrity Technology Group supplied China-linked actors with the capability for widespread vulnerability scanning and, in some cases, the intrusions themselves. The firm was sanctioned by the US in January 2025 and by the UK in December 2025, and the Justice Department dismantled a Mirai-class botnet of more than 200,000 consumer devices tied to it in September 2024.

ElementDetail
Announced8 October 2026 — DOJ / FBI, W.D. Pennsylvania; advisory AA26-281A
Authoring agenciesFBI, CISA, NSA, UK NCSC, Australian ACSC, Canadian Centre for Cyber Security, Japan NPA and NCO, New Zealand NCSC, Spain CNI
Tools seizedMicroScan (scanner, in use since 2017, 1,300+ scripts); FishHub (spear-phishing and follow-on malware)
Domains seized7 — 1 scanner access, 5 malware delivery, 1 remote administration
Confirmed victims~20 Taiwanese universities (FishHub); 2 universities plus scanning of a South Carolina power company, airports in Japan and Poland, Taiwanese gas and electricity operators
Sectors targetedGovernment services, critical manufacturing, healthcare, information technology, education, law enforcement, religious organisations
RegionsNorth America, Southeast Asia, Africa
Exploited CVEs8, all with patches available; five newly added to CISA’s KEV catalog
AttributionMethods consistent with Flax Typhoon / Ethereal Panda / RedJuliett; agencies refer only to “the threat actors”
The J. Edgar Hoover Building in Washington DC, FBI headquarters, which coordinated the domain seizures described in this data breach update on China-linked email theft
FBI headquarters, the J. Edgar Hoover Building in Washington, DC. The Bureau coordinated the seven-domain seizure and co-authored advisory AA26-281A with nine partner agencies. Photograph by ajay_suresh, via Wikimedia Commons, licensed CC BY 2.0.

MicroScan: vulnerability scanning as a managed service

MicroScan is a Python web application that has been in service since 2017. It carries more than 1,300 penetration-testing scripts aimed at OpenSSL, Oracle WebLogic, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins and Apache Struts. The operators ran it continuously against internet-facing estates and handed the findings to clients who could act on them later. In the affidavit’s account, Taiwanese university networks scanned in August 2022 and March 2023 were breached afterwards — the scan and the intrusion separated by months.

That separation matters. Most IT security programmes treat a scan hitting the perimeter as background radiation; here it was reconnaissance held in inventory, and the server infrastructure that answered those probes was compromised on someone else’s schedule. A finding does not expire when the scan ends. It expires when you patch.

Eight CVEs, zero zero-days — and one of them is a DNS server

Nothing in this campaign required a zero-day vulnerability. The advisory lists eight flaws the actors successfully exploited, the oldest from 2014 and the newest from 2023. Five are flagged in the advisory itself as new additions to CISA’s Known Exploited Vulnerabilities catalog.

CVEComponentImpact
CVE-2014-6278GNU Bash (Shellshock)Remote code execution
CVE-2015-3306ProFTPDUnauthenticated file read / write
CVE-2015-5477ISC BIND 9TKEY query denial of service — a single packet crashes named
CVE-2016-3081Apache StrutsRemote code execution
CVE-2019-11510Pulse Connect SecureArbitrary file read on the VPN gateway
CVE-2021-3199ONLYOFFICE Document ServerArbitrary file write
CVE-2021-22205GitLab CE / EEUnauthenticated remote code execution
CVE-2023-22894StrapiInformation disclosure

CVE-2015-5477 is the entry this site cares about most. It is an assertion failure in ISC BIND 9 triggered by a malformed TKEY query: one crafted packet, one crashed resolver, no authentication. An actor who can drop a recursive resolver at will does not need a DDoS attack to take name resolution away from a network — and when resolution goes, everything downstream of it goes with it, including the mail flow this campaign existed to harvest. That a 2015 BIND bug was still worth carrying in a 2026 toolkit says something uncomfortable about how rarely authoritative and recursive DNS server estates get audited.

Official seal of the Federal Bureau of Investigation, the agency that seized seven domains supporting the MicroScan and FishHub intrusion tools
The seized domains now serve FBI notices. The advisory warns defenders to vet the published indicators before blocking them wholesale — some date back to 2016 and may since have been reallocated. Official FBI seal, public domain, via Wikimedia Commons.

The mailbox pipeline, and the portal at the end of it

The post-exploitation chain is the clearest part of the advisory. Credentials came from EBurst, an open-source Python tool that sprays passwords against Microsoft Exchange and Office 365 across ten separate interfaces — ECP, EWS, OAB, OWA, RPC, API, MAPI, PowerShell, Autodiscover and ActiveSync. Most organisations monitor two of those. Active Directory credentials were lifted by DCSync, which impersonates a domain controller and asks politely for replication data. Mail was then collected remotely, archived, staged locally and exfiltrated automatically.

Persistence hid inside legitimate software. The actors installed SoftEther VPN clients — pulled down with PowerShell on Windows, curl or wget on Linux — set to reconnect at boot and renamed to conhost.exe or dllhost.exe so they read as Windows binaries. Endpoint tooling tends not to flag SoftEther, because SoftEther is not malware, and the command-and-control traffic rode inside that tunnel.

Then the commercial part: the operators maintained a web application that gave third parties access to the stolen mail, viewable per account by appending arguments to a URL. Stolen email from government, law enforcement, healthcare and religious organisations across Southeast Asia was, in effect, a browsable product. The agencies have not said who the third parties were.

What this data breach update means for defenders

  1. Hunt the five new KEV entries first. The advisory flags CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199 and CVE-2023-22894 as new KEV catalog entries. Federal agencies get a deadline; everyone else gets a prioritised list for free.
  2. Audit every Exchange authentication interface, not just OWA. Enumerate ECP, EWS, OAB, RPC, MAPI, PowerShell, Autodiscover and ActiveSync, disable what you do not use, and require multifactor authentication on what remains. A spray that fails on OWA and succeeds on ActiveSync is a successful spray.
  3. Look for SoftEther where it should not be. Search for conhost.exe and dllhost.exe outside C:\Windows\System32, for VPN clients set to auto-start on servers, and for persistent outbound tunnels from hosts that should never build one.
  4. Alert on unexpected Active Directory replication. DCSync from a host that is not a domain controller is one of the highest-signal detections available and costs nothing but a rule.
  5. Turn on protective DNS. The advisory recommends it explicitly, alongside domain-reputation screening. Resolver-level blocking of known-bad destinations stops a tunnel before it establishes, and it is the one control that sees traffic from devices your endpoint agent never reached.
  6. Check your own mail-related DNS records. An account-takeover campaign that lives in mailboxes is also a spoofing campaign waiting to happen. Our email DNS checker verifies SPF, DKIM, DMARC and MX configuration in one pass.
DNS Benchmark Pro results ranking public resolvers by DNS server performance, used to baseline resolution health when hunting command-and-control tunnels
A real DNS Benchmark Pro run. Baselining DNS server performance gives you a reference point — an abrupt change in resolver behaviour is often the first visible trace of resolver tampering or an outbound tunnel.

Protective DNS only helps if the resolvers your estate actually uses are the ones you think it uses, and if they are healthy enough that nobody quietly reconfigures around them. Our free DNS benchmark and network diagnostic tool gives a per-resolver view rather than a single vantage point. And our guide to DNS over HTTPS and DNS over TLS explains what those protocols protect — the query path — and what they do not: the endpoint that decided to send the query.

Network latency comparison chart across public DNS resolvers, part of routine IT security and cloud security monitoring for enterprise networks
Per-resolver network latency distribution from the same engine. Consistent, measured behaviour is what makes an anomaly legible; without a baseline, a hijacked or degraded resolver simply looks like a slow day.

Industry impact: the long tail is the attack surface

The headline is a law-enforcement win, and a real one. But the operational lesson sits lower down the page: a state-linked commercial intrusion outfit, resourced well enough to run a 1,300-script scanning platform continuously for nine years, got into government, healthcare and critical manufacturing networks using nothing but patched vulnerabilities. Shellshock is twelve years old. The BIND flaw is eleven. The Pulse Secure file read has been on every enterprise IT news roundup and every KEV list since 2019.

That is the asymmetry worth taking into next quarter’s planning. Cloud security budgets concentrate on the newest surface, because that is where the headlines are. Meanwhile an unloved document server, a forgotten GitLab instance and a resolver nobody has restarted since the last office move sit in the same routing table as the mail system. The actors in this data breach update did not need novel capability. They needed patience, a scanner and an inventory gap.

Close the gap you can measure. Enumerate what answers on the internet, patch what the KEV catalog now flags, instrument every authentication interface on your mail platform, and make resolver behaviour something you have numbers for. None of it is glamorous, and all of it would have cost this campaign most of its victims.

Sources

All DNS newsRun the free DNS benchmark

Independent editorial analysis published by DNS Benchmark Pro / Genext Information Systems. The FBI headquarters photograph is by ajay_suresh, via Wikimedia Commons, licensed CC BY 2.0; the FBI seal is a public-domain reproduction of an official US government seal, via Wikimedia Commons; the benchmark screenshots are original captures of the DNS Benchmark Pro engine. No images on this page are AI-generated. DNS Benchmark Pro is not affiliated with the Federal Bureau of Investigation, CISA or any agency named in this report.