Law enforcement and intelligence agencies across seven countries have issued a sweeping joint advisory detailing an extensive, multi-year cyber espionage campaign orchestrated by hackers tied to a prominent Chinese cybersecurity company. The coordinated disclosure, released on October 8, highlights how operatives linked to Beijing-based Integrity Technology Group systematically compromised sensitive government organizations, law enforcement bodies, healthcare systems, and religious institutions primarily across Southeast Asia, alongside collateral targets in North America, Africa, and other regions.

The joint warning builds upon a series of escalating international regulatory and legal actions against the firm, which has already faced severe economic sanctions from both the United States and the United Kingdom. According to the multi-agency advisory, the malicious actors utilized a vast array of automated scanning scripts, brute-force tactics, and specialized credential-harvesting tools to infiltrate and extract data from enterprise networks, maintaining persistent access to compromised environments since at least January 2021.

The newly published findings offer a granular look into the methodology of the threat actors, shedding light on how a for-profit enterprise allegedly collaborated with or enabled state-sponsored cyber operations. While the advisory uses the collective term "threat actors" to describe the overlap between Integrity Technology Group and the operatives utilizing its infrastructure, the documentation underscores the blurry lines between commercial cybersecurity entities and state-directed intelligence collection in modern cyberspace.

Who Is Behind the Campaign

Integrity Technology Group has long been under intense scrutiny by Western governments. The U.S. Treasury Department imposed direct sanctions on the Beijing-based company in January 2025, citing its foundational role in orchestrating computer intrusions against domestic and international targets. Several months later, in December 2025, the United Kingdom followed suit, introducing its own set of restrictive measures to combat what British officials termed reckless and irresponsible activity in cyberspace.

High-ranking security officials have previously pointed to public admissions by the company’s leadership as a smoking gun. During remarks at the Aspen Cyber Summit, then-FBI Director Christopher Wray noted that the chairman of Integrity Technology Group had openly acknowledged that his firm routinely gathered intelligence and performed reconnaissance operations on behalf of Chinese government security agencies.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Security researchers tracking the broader threat landscape have long associated the operational patterns of these hackers with several well-known designations, including Flax Typhoon, Ethereal Panda, and RedJuliett. While threat intelligence nomenclature varies across the cybersecurity industry—and these group aliases do not map one-to-one with official government tracking systems—the techniques deployed in the Southeast Asian campaigns bear the unmistakable hallmarks of these sophisticated state-aligned actors.

Despite mounting international pressure and severe economic penalties, the accused firm has vehemently denied any wrongdoing. In January 2025, Integrity Technology Group formally protested the U.S. actions, telling the Shanghai Stock Exchange that the allegations lacked any factual basis. Concurrently, spokespersons for the Chinese Foreign Ministry voiced firm opposition to the sanctions, accusing Western governments of geopolitical maneuvering and double standards.

How the Hackers Get In

The joint advisory details a methodical, multi-phase approach to network intrusion that begins with wide-scale vulnerability scanning. Rather than relying exclusively on zero-day exploits, the hackers frequently leverage common open-source penetration testing utilities and GitHub repositories, such as Nmap, masscan, and WPScan, to probe external-facing web applications and networks. Their primary reconnaissance heavily focuses on standard communication and administrative ports, including ports 21, 22, 53, 80, 443, and 1080.

Among the specific tools highlighted in the report is a proprietary Python-based web application known as MicroScan. Active since at least 2017, MicroScan houses an extensive library of more than 1,300 distinct scripts designed to test and exploit web servers, enterprise software, and content management systems. The hackers have systematically directed these scripts against prominent software platforms and frameworks, including OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts.

The advisory explicitly lists a series of software vulnerabilities historically targeted by the hackers’ exploit frameworks. These include longstanding security flaws affecting GNU Bash (CVE-2014-6278), ProFTPD (CVE-2015-3306), ISC BIND (CVE-2015-5477), Apache Struts (CVE-2016-3081), Pulse Connect Secure (CVE-2019-11510), GitLab (CVE-2021-22205), ONLYOFFICE Document Server (CVE-2021-3199), and Strapi (CVE-2023-22894). Several of these flaws were subsequently added by the U.S. Cybersecurity and Infrastructure Security Agency to its Known Exploited Vulnerabilities catalog, emphasizing their widespread utility in real-world attacks.

Beyond automated software exploitation, the threat actors have demonstrated a penchant for social engineering and deceptive credential harvesting. In multiple observed instances, the FBI recovered cross-site scripting payloads designed to inject fake login prompts into vulnerable web pages. When unsuspecting visitors entered their credentials, the modified page offered a password-protected ZIP archive containing malicious executables disguised as legitimate administrative software. This malware established outbound encrypted communication channels with command-and-control infrastructure attributed by investigators to Integrity Technology Group.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Password spraying represents another core pillar of the group’s initial access strategy. Utilizing an open-source Python tool called EBurst, the operators systematically test common passwords against a vast array of Microsoft 365 and Exchange accounts. The tool targets multiple administrative and client-facing interfaces—such as ECP, EWS, OAB, OWA, RPC, API, MAPI, PowerShell, Autodiscover, and Microsoft-Server-ActiveSync—underscoring the critical need for enterprise network defenders to secure every potential gateway into collaborative environments.

How They Stay and What They Take

Once initial access is secured, the operatives employ careful persistence mechanisms to avoid detection by standard security monitoring tools. Rather than deploying custom, easily flagged backdoors, they frequently install SoftEther, a legitimate open-source virtual private network client. To blend in with normal administrative traffic, the attackers routinely rename the installer executable to mimic core Windows processes like conhost.exe or dllhost.exe, configuring the software to establish a persistent connection upon system startup.

For privilege escalation and credential theft, the hackers deployed specialized tools capable of executing DCSync attacks. By mimicking a domain controller through Active Directory’s standard replication protocol, tools such as DC.exe enabled the operators to quietly siphon off account credentials, security group memberships, and organizational trust relationships.

The primary objective of the espionage campaign, however, appears to be massive intelligence extraction, particularly targeting email correspondence. The threat actors built custom extraction mechanisms, including a standalone PHP-based bot named Curlc4.txt, designed to harvest mailboxes, contact lists, and calendar entries via Exchange Web Services. After compressing and occasionally encrypting the stolen data, the script uploaded the archives to remote servers tied to external command-and-control domains.

Additionally, the operators utilized a command-line utility known as office-cli to continuously query Microsoft 365 environments across various historical timeframes. By leveraging legitimate API access tokens and configuration files containing valid client and tenant identifiers, the tool allowed the hackers to bypass behavioral anomaly detection mechanisms and exfiltrate sensitive correspondence undetected. In select cases, the stolen intelligence was funneled through dedicated web applications that restricted data viewing privileges exclusively to IP addresses originating from Xiamen, China.

The broader scope of these operations underscores the evolving challenges facing global cybersecurity authorities. While international sanctions and infrastructure disruptions—such as the 2024 FBI-led dismantling of the 200,000-device Raptor Train IoT botnet controlled by the same firm—have temporarily degraded the group’s operational capacity, the release of the latest joint advisory signals that the network of infrastructure and tactics utilized by commercialized Chinese threat actors remains a persistent and complex threat to international security.

By Nana

Leave a Reply

Your email address will not be published. Required fields are marked *