Integrity Technology Group: FBI Warns Chinese State-Linked Hackers Use Automated Tools to Steal Sensitive Data

Integrity Technology Group: FBI Warns Chinese State-Linked Hackers Use Automated Tools to Steal Sensitive Data

FBI Warns of Chinese State-Linked Hackers Exploiting Vulnerabilities at Scale

On October 8, 2026, the FBI, in collaboration with CISA, the NSA, and international partners, issued a joint advisory warning of a sophisticated cyberespionage campaign linked to Chinese government-affiliated hackers. The threat actors supported by China-based Integrity Technology Group are targeting organizations across government, manufacturing, healthcare, IT, law enforcement, education, and religious institutions in Southeast Asia, Africa, and North America.

The attackers employ a combination of automated vulnerability scanning, large-scale botnets, and manual exploitation to steal sensitive data. Their tactics align with activity tracked under names like Flax Typhoon, Ethereal Panda, and Red Juliett, though the advisory notes that commercial threat labels may not directly correspond to state attribution.

Attack Methods & Tools

The hackers leverage open-source scanning tools (Nmap, masscan, Fscan, dirsearch, WPScan) to identify exposed services, particularly targeting FTP, SSH, DNS, HTTP, HTTPS, and SOCKS ports. A key tool in their arsenal is MicroScan, a Python-based web application active since at least 2017, containing over 1,300 penetration-testing scripts for vulnerabilities in Oracle WebLogic, WordPress, Jenkins, Apache Struts, OpenSSL, and Juniper ScreenOS.

Initial access is gained through Python/Go exploitation utilities, JavaScript XSS payloads, and credential-harvesting pages. One recovered payload, live700_v1.exe, disguised itself as DiagTrack.exe (a legitimate Windows process) and established encrypted communications with dns.studiocloud[.]xyz, likely for email data exfiltration.

For password spraying, the attackers use EBurst, an open-source Python tool, against Microsoft Exchange interfaces (Outlook Web Access, Exchange Web Services, Autodiscover, PowerShell, and ActiveSync). Post-compromise, they deploy SoftEther VPN clients, often disguised as conhost.exe or dllhost.exe, to maintain persistent access while obscuring command-and-control traffic.

Data Theft & Exfiltration

The hackers employ multiple tools for data collection:

  • Curlc4.txt (PHP script): Interfaces with Exchange Web Services to steal emails, calendars, and contacts, compressing and encrypting them (RC4/AES-128-CBC) before exfiltration to natcloudservice[.]com.
  • DC.exe: Performs DCSync replication to extract Active Directory credentials and directory data.
  • office-cli: Automates Outlook 365 mailbox access using stolen credentials.

Recommended Defensive Measures

Authorities advise organizations to:

  • Disable unused services and patch exposed systems.
  • Sanitize web application inputs and enforce multifactor authentication.
  • Restrict administrative privileges and monitor for unexpected VPN installations, abnormal Active Directory replication, and unusual outbound traffic.
  • In case of compromise, isolate affected hosts, preserve forensic evidence, and scope compromised accounts.

The advisory underscores the global reach and persistence of these state-linked cyber operations, highlighting the need for heightened vigilance across critical sectors.

Source: https://cyberpress.org/fbi-warns-chinese-state-linked-hackers/

Integrity Technology Group TPRM report: https://www.rankiteo.com/company/integrity360-se

"id": "int1791534337",
"linkid": "integrity360-se",
"type": "Cyber Attack",
"date": "10/2026",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of geographical region"
{'affected_entities': [{'industry': ['Government',
                                     'Manufacturing',
                                     'Healthcare',
                                     'IT',
                                     'Law enforcement',
                                     'Education',
                                     'Religious'],
                        'location': ['Southeast Asia',
                                     'Africa',
                                     'North America'],
                        'type': ['Government',
                                 'Manufacturing',
                                 'Healthcare',
                                 'IT',
                                 'Law enforcement',
                                 'Education',
                                 'Religious institutions']}],
 'attack_vector': ['Automated vulnerability scanning',
                   'Large-scale botnets',
                   'Manual exploitation',
                   'Password spraying',
                   'Credential harvesting',
                   'VPN-based persistence'],
 'data_breach': {'data_encryption': ['RC4', 'AES-128-CBC'],
                 'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Emails',
                                              'Calendars',
                                              'Contacts',
                                              'Active Directory credentials',
                                              'Directory data',
                                              'Personally identifiable '
                                              'information']},
 'date_detected': '2026-10-08',
 'date_publicly_disclosed': '2026-10-08',
 'description': 'On October 8, 2026, the FBI, in collaboration with CISA, the '
                'NSA, and international partners, issued a joint advisory '
                'warning of a sophisticated cyberespionage campaign linked to '
                'Chinese government-affiliated hackers. The threat actors '
                'supported by China-based Integrity Technology Group are '
                'targeting organizations across government, manufacturing, '
                'healthcare, IT, law enforcement, education, and religious '
                'institutions in Southeast Asia, Africa, and North America. '
                'The attackers employ automated vulnerability scanning, '
                'large-scale botnets, and manual exploitation to steal '
                'sensitive data.',
 'impact': {'data_compromised': 'Emails, calendars, contacts, Active Directory '
                                'credentials, directory data, personally '
                                'identifiable information',
            'identity_theft_risk': 'High',
            'systems_affected': ['FTP',
                                 'SSH',
                                 'DNS',
                                 'HTTP',
                                 'HTTPS',
                                 'SOCKS',
                                 'Microsoft Exchange',
                                 'Active Directory']},
 'initial_access_broker': {'backdoors_established': ['SoftEther VPN clients '
                                                     '(disguised as '
                                                     'conhost.exe or '
                                                     'dllhost.exe)'],
                           'entry_point': ['Python/Go exploitation utilities',
                                           'JavaScript XSS payloads',
                                           'Credential-harvesting pages']},
 'motivation': 'Cyberespionage, Data theft',
 'recommendations': ['Disable unused services and patch exposed systems',
                     'Sanitize web application inputs and enforce multifactor '
                     'authentication',
                     'Restrict administrative privileges and monitor for '
                     'unexpected VPN installations, abnormal Active Directory '
                     'replication, and unusual outbound traffic',
                     'In case of compromise, isolate affected hosts, preserve '
                     'forensic evidence, and scope compromised accounts'],
 'references': [{'date_accessed': '2026-10-08',
                 'source': 'FBI, CISA, NSA, International partners'}],
 'response': {'containment_measures': ['Isolate affected hosts',
                                       'Preserve forensic evidence',
                                       'Scope compromised accounts'],
              'enhanced_monitoring': ['Monitor for unexpected VPN '
                                      'installations',
                                      'Abnormal Active Directory replication',
                                      'Unusual outbound traffic'],
              'law_enforcement_notified': 'FBI, CISA, NSA, International '
                                          'partners',
              'remediation_measures': ['Disable unused services',
                                       'Patch exposed systems',
                                       'Sanitize web application inputs',
                                       'Enforce multifactor authentication',
                                       'Restrict administrative privileges']},
 'threat_actor': ['Flax Typhoon',
                  'Ethereal Panda',
                  'Red Juliett',
                  'Integrity Technology Group'],
 'title': 'FBI Warns of Chinese State-Linked Hackers Exploiting '
          'Vulnerabilities at Scale',
 'type': 'Cyberespionage',
 'vulnerability_exploited': ['Oracle WebLogic',
                             'WordPress',
                             'Jenkins',
                             'Apache Struts',
                             'OpenSSL',
                             'Juniper ScreenOS',
                             'Microsoft Exchange (OWA, EWS, Autodiscover, '
                             'PowerShell, ActiveSync)']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.