MicroScan is a Python-based web application developed by Integrity Technology Group for reconnaissance and vulnerability scanning of internet-facing websites, services, and networks. Used since at least 2017, it contains more than 1,300 penetration-testing scripts that identify weaknesses in technologies including OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts. Its dashboard supports centralized review of vulnerability totals, scan status, and plugin rankings.
Integrity Technology Group, a Beijing-based company with Chinese government contracts, used MicroScan to identify vulnerabilities for subsequent exploitation by its clients. Its operations are associated with China-linked activity tracked as Flax Typhoon. A company-operated botnet of devices infected with a Mirai variant supported MicroScan reconnaissance, alongside other infrastructure; MicroScan is distinct from the malware infecting those devices.
Identified scanning targets included a power company in South Carolina, a multinational nongovernmental organization, airports in Japan and Poland, Taiwanese natural gas and electricity companies, and two Taiwanese universities. Attackers subsequently compromised the two universities, but scanning alone does not establish a successful intrusion, and MicroScan's confirmed functionality is reconnaissance rather than remote access or data theft. On October 8, 2026, U.S. authorities announced court-authorized seizures of infrastructure supporting access to MicroScan as part of a broader disruption of Integrity Technology Group's hacking tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Appendix B lists CVE-2016-3081 as successfully exploited, affecting Apache Struts 2.3.19–2.3.20.2, 2.3.21–2.3.24.1, and 2.3.25–2.3.28. It enables remote code execution and is marked as newly added to CISA's KEV Catalog. | “As early as 2017, these threat actors have also used a malicious application known as ‘MicroScan.’”
Appendix B lists CVE-2014-6278 as successfully exploited, affecting GNU Bash through 4.3 bash43-026 and enabling remote code execution. The MicroScan section links this appendix to vulnerabilities recovered from its penetration-testing scripts. | “As early as 2017, these threat actors have also used a malicious application known as ‘MicroScan.’”
Appendix B lists CVE-2021-3199 as successfully exploited, affecting ONLYOFFICE DocumentServer 5.1.5 through 5.6.2 and allowing unauthorized writes. It is marked as newly added to CISA's KEV Catalog. | “As early as 2017, these threat actors have also used a malicious application known as ‘MicroScan.’”
Appendix B lists CVE-2015-5477 as successfully exploited, affecting ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3, with denial-of-service impact. It is marked as newly added to CISA's KEV Catalog. | “As early as 2017, these threat actors have also used a malicious application known as ‘MicroScan.’”
Appendix B lists CVE-2021-22205 as successfully exploited, affecting GitLab and enabling remote code execution. Its affected-version field states 'All versions starting from 11.9' without providing a fixed-version boundary. | “As early as 2017, these threat actors have also used a malicious application known as ‘MicroScan.’”
Appendix B lists CVE-2015-3306 as successfully exploited, affecting ProFTPD 1.3.5 and allowing unauthorized reads. An asterisk identifies it as newly added to CISA's Known Exploited Vulnerabilities Catalog. | “As early as 2017, these threat actors have also used a malicious application known as ‘MicroScan.’”
Appendix B lists CVE-2023-22894 as successfully exploited, affecting Strapi up to 4.5.5 and causing information disclosure through cleartext storage of sensitive information. It is marked as newly added to CISA's KEV Catalog. | “As early as 2017, these threat actors have also used a malicious application known as ‘MicroScan.’”
Appendix B lists CVE-2019-11510 as successfully exploited, affecting Pulse Connect Secure 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, and allowing unauthorized reads. | “As early as 2017, these threat actors have also used a malicious application known as ‘MicroScan.’”
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Microscan, accessed through the now-seized domain c0cc.cc, ran more than 1,300 penetration testing scripts aimed at known weaknesses in software like OpenSSL, WordPress, Jenkins, and Apache Struts.”
Ботнетот користел алатка наречена MicroScan за извидување и скенирање компјутерски системи во потрага по безбедносни пропусти.
1 distinct technique documented for this family, organized by ATT&CK tactic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Integrity Technology Group operated Microscan to scan and sometimes compromise U.S. and foreign networks, including critical infrastructure. Powered by an infected-IoT botnet, it used more than 1,300 penetration-testing scripts targeting known software weaknesses. The article reports activity dating to at least 2017 and availability through September 9, 2026. U.S. authorities seized its access domain to disrupt operations.
Reconnaissance tool developed by Integrity Technology Group and linked to Flax Typhoon. It used support from a Mirai-based IoT botnet to scan victim networks for weaknesses that clients could subsequently exploit. Reported scanning targeted organizations in the United States, Japan, Poland, and Taiwan. Two Taiwanese universities were compromised shortly after being scanned. The FBI seized c0cc[.]cc, the domain Integrity Tech used to access the tool.
A Python-based web reconnaissance and vulnerability-scanning platform used to identify potential targets. It contained more than 1,300 penetration-testing scripts and incorporated additional open-source scanners. Originally hosted at 198.13.53[.]226 and accessible through c0cc[.]cc, it reportedly had been used since 2017. Reported targets included energy companies, airports, universities, and an international NGO.
Integrity Technology Group's vulnerability-scanning platform, primarily associated with Flax Typhoon. It supported reconnaissance against US and foreign critical infrastructure, using an IoT botnet built with a Mirai variant. US authorities seized domains used to access the platform.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.