Security News

Australia joins seven-nation warning as US seizes domains tied to Chinese hacking firm

iTnews · 12 Oct 2026
Key Takeaway Even if Australia is not named as a target, review the ASD and ACSC advisory, patch exposed systems promptly and train staff to spot spear phishing emails.

The Australian Signals Directorate (ASD) has joined a multinational warning about China's Integrity Technology Group. The US Justice Department and FBI seized seven domains supporting two of the firm's tools: MicroScan, a vulnerability scanner, and FishHub, a spear phishing tool. The Justice Department alleged the company holds contracts with the Chinese government. The advisory was issued by the FBI, CISA, the NSA and the ASD's Australian Cyber Security Centre, with agencies from the UK, Canada, Japan, New Zealand and Spain.

The advisory said the actors the company enables use techniques consistent with groups tracked as Flax Typhoon, Ethereal Panda and Red Juliett. It also described a custom web application that gave third-party access to stolen email content. The FBI recovered an archived email database taken from government bodies, law enforcement agencies, healthcare systems and religious institutions in Southeast Asia. In some cases, access to the stolen data was restricted to IP addresses in Xiamen, China.

Australia was not named among the victim locations. The advisory listed US critical infrastructure sectors, including government, critical manufacturing, healthcare and IT, plus organisations in Southeast Asia, Africa and North America. An ASD spokesperson told iTnews that the vulnerabilities and tactics outlined "are applicable to Australian entities" and encouraged organisations to mitigate the threat.

China ASD spear phishing state-sponsored advisory domain seizure

Summarised by CISO AI from iTnews, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.