An international coalition of law enforcement and cybersecurity agencies has issued a sweeping joint advisory detailing a multi-year cyber espionage campaign targeting critical infrastructure, government organizations, law enforcement agencies, healthcare systems, and religious institutions across Southeast Asia and around the globe. The advisory, released on October 8, directly links the intrusions to Integrity Technology Group, a China-based cybersecurity enterprise that has already faced severe sanctions from both the United States and the United Kingdom for its role in malicious cyber activity.

According to the joint findings released by agencies from seven countries, including the FBI, the threat actors have maintained persistent access to victim networks since at least mid-January 2021. The campaign relies on a meticulous methodology involving automated vulnerability scanning, credential harvesting, password spraying against Microsoft 365 and Exchange accounts, and the deployment of specialized tools designed to exfiltrate vast troves of sensitive email correspondence. Beyond Southeast Asia, the cyber attacks have affected organizations in Africa, North America, and various sectors within the United States, including government services, critical manufacturing, healthcare, IT, education, and law enforcement.

The revelations build upon prior enforcement actions taken against Integrity Technology Group. In September 2024, the FBI successfully disrupted a massive botnet known as Raptor Train, which the U.S. Justice Department revealed was controlled by the firm. That infrastructure compromised more than 200,000 consumer-grade devices, including routers and cameras. While the 2024 operation dismantled the botnet, the latest advisory shifts its focus to the broader intrusion vectors, credential theft mechanisms, and data exfiltration techniques uncovered during ongoing investigations into the company’s operations.

Who Is Behind It

Investigative agencies characterize Integrity Technology Group as a for-profit commercial entity operating with deep links to the Chinese government. Employees of the firm reportedly develop or procure advanced cyber tools for both internal deployment and commercial sale, host malicious infrastructure, and conduct direct network intrusions. Although the joint advisory groups the enterprise and its hackers under the broad umbrella term of threat actors, it stops short of attributing every specific break-in to individual employees or third-party clients.

The U.S. Treasury Department targeted the company with sanctions in January 2025 due to its involvement in multiple computer intrusions affecting American victims. The United Kingdom followed suit in December 2025, placing its own sanctions on the firm for reckless and irresponsible cyber operations. These diplomatic and economic measures underscore a growing Western consensus regarding commercialized cyber espionage, where private contractors operating within authoritarian states carry out state-sponsored intelligence gathering under the guise of legitimate business operations.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

The operational profile of the hackers aligns closely with activity tracked by private cybersecurity intelligence companies under various monikers, including Flax Typhoon, Ethereal Panda, and RedJuliett. For instance, Microsoft previously identified Flax Typhoon in 2023 as a China-based group focused on targeting organizations in Taiwan. However, security analysts note that threat intelligence naming conventions do not always map identically to government tracking frameworks, and the individuals associated with these campaigns may engage in operations independent of Integrity Technology Group.

When confronted with these allegations in January 2025, Integrity Technology Group vehemently denied any wrongdoing. The company informed the Shanghai Stock Exchange that the U.S. sanctions lacked any factual basis, a stance echoed by a Chinese Foreign Ministry spokesperson who stated that Beijing firmly opposed the unilateral American actions.

How the Hackers Get In

The campaign’s initial access phase typically begins with automated reconnaissance. The hackers utilize open-source scanners such as Nmap, masscan, and WPScan to probe networks and web applications for vulnerabilities, paying particular attention to common network ports. Because these tools are widely available on platforms like GitHub, investigators conclude that the threat actors actively search for lower-hanging fruit and vulnerable perimeters to exploit.

Among the tools identified in the advisory is MicroScan, a Python-based web application containing more than 1,300 penetration testing scripts used to detect specific flaws in enterprise services. The advisory highlights successful exploits across a wide range of software products, including GNU Bash, ProFTPD, ISC BIND, Apache Struts, Pulse Connect Secure, GitLab, ONLYOFFICE Document Server, and Strapi. Several of these flaws have been formally added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog.

In addition to software exploitation, the threat actors employ sophisticated social engineering and credential manipulation tactics. Investigators recovered a cross-site scripting payload designed to compromise vulnerable web pages by injecting fake login prompts for usernames and passwords. Once a victim submits their credentials, the compromised page serves a password-protected archive containing malicious executables configured to establish covert communication channels with command-and-control domains attributed to Integrity Technology Group.

The hackers also rely heavily on password spraying techniques, testing a small number of common passwords against large volumes of user accounts. For this purpose, they deploy EBurst, an open-source Python tool tailored specifically for targeting Microsoft 365 and Exchange environments through various communication interfaces, including ECP, EWS, OAB, OWA, and ActiveSync.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

How They Stay and What They Take

Once inside a network, the threat actors prioritize maintaining long-term persistence and evading detection. To achieve this, they frequently install SoftEther, a legitimate virtual private network program that blends smoothly with normal administrative traffic and is less likely to trigger security alerts. They often disguise the installation binaries by renaming them to mimic standard Windows system files and configure the software to initiate automatically upon system startup.

Credential harvesting is executed using advanced techniques such as DCSync, implemented through specialized tools like DC.exe. This method allows the intruders to mimic a domain controller and pull comprehensive directory data from Active Directory replication services, including account credentials, group memberships, and trust relationships.

For email theft, the hackers developed automated utilities from PHP scripts capable of interfacing directly with Exchange Web Services. These scripts collect mail, calendars, and contacts, compress and occasionally encrypt the data, and upload it to remote servers operated by the threat group. Another dedicated utility, office-cli, systematically interacts with Microsoft 365 accounts using valid configuration parameters to extract historical email archives while evading standard monitoring solutions. In certain instances, exfiltrated data access was deliberately restricted to specific Internet Protocol addresses located in Xiamen, China, while a specialized web interface allowed third-party beneficiaries to browse stolen mailboxes simply by modifying URL parameters.

Defensive Recommendations

In light of the extensive findings, international cybersecurity authorities have urged network defenders to proactively hunt for indicators of compromise within their environments. The advisory emphasizes the importance of reviewing extensive lists of malicious domains, file hashes, and IP addresses associated with the campaign, while exercising caution to verify older infrastructure indicators. Organizations are advised to isolate affected hosts, conduct thorough forensic analysis to determine the scope of unauthorized access, remediate compromised credentials, and harden network perimeters against automated scanning and credential spraying tools.

Leave a Reply

Your email address will not be published. Required fields are marked *