FishHub is a malware downloader and spear-phishing tool developed and operated by Integrity Technology Group, a Beijing-based company with Chinese government contracts associated with the China-linked threat actor Flax Typhoon. It facilitates targeted network compromises through spear-phishing emails and downloads additional malicious programs after attackers establish an initial foothold.
Follow-on malware delivered through FishHub provides unauthorized remote access or locates specific files for theft. Associated payloads can enumerate files, search for documents, compress selected data, and transfer it to Integrity Technology Group-controlled servers. Confirmed FishHub victims include approximately 20 Taiwanese universities, and its malware-delivery infrastructure remained in use as of March 2026. In October 2026, U.S. authorities seized domains supporting FishHub malware delivery as part of a broader disruption of Integrity Technology Group's hacking infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“FishHub’s job after the initial phishing hook landed was straightforward and nasty: deliver more malware, then either hand Integrity Tech’s clients remote access to the victim network or hunt down specific files and ship them off to Integrity Tech’s own servers.”
Втора алатка на Integrity Technology Group се нарекува FishHub. Според обвиненијата, таа овозможувала напади врз компјутерски мрежи преку насочени фишинг-напади (spear-phishing) и инсталирање дополнителен злонамерен код.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Integrity Technology Group operated FishHub to deliver malware through spear-phishing, provide clients with remote access to victim networks, and locate and exfiltrate selected files. Approximately 20 Taiwanese universities were confirmed victims. Five domains supported malware delivery, including addresses impersonating Outlook, YouTube, and LinkedIn. U.S. authorities disrupted the tool through court-authorized seizures.
Spear-phishing and malware-delivery tool linked to Integrity Technology Group and Flax Typhoon. Following initial compromise, it downloaded additional, unnamed malware that provided unauthorized remote access or located and exfiltrated specified files to Integrity Tech-controlled servers. Approximately 20 Taiwanese universities were confirmed victims. Five seized domains were used to deliver the malware.
An Integrity Technology Group tool enabling spear-phishing and installation of additional malicious code. Associated malware provided unauthorized remote access or searched for specific files and exfiltrated them to Integrity-controlled servers. Twenty Taiwanese universities were identified as confirmed victims of FishHub-related activity.
Integrity Technology Group's hacking tool used to facilitate intrusions through spear phishing, provide remote network access, locate files, and exfiltrate data. Reported attacks affected at least 20 Taiwanese universities. US authorities seized domains used to access the tool.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.