Global Law Enforcement Warns of Massive Email Espionage Campaign Linked to Chinese Firm Integrity Technology Group

Intelligence and law enforcement agencies from seven countries have issued a sweeping joint advisory detailing an extensive, multi-year cyber espionage campaign targeting critical infrastructure, government networks, and sensitive institutions worldwide. The operations, which date back to at least January 2021, have been explicitly tied to Integrity Technology Group, a China-based cybersecurity firm facing severe international sanctions over its alleged role in state-sponsored hacking activities.

According to the October joint advisory released by the FBI and international partners, hackers linked to or enabled by the company systematically compromised email systems across Southeast Asia, Africa, and North America. The targeted entities span a wide range of sensitive sectors, including government organizations, law enforcement agencies, healthcare systems, religious institutions, critical manufacturing, and educational bodies.

The advisory highlights the dual nature of Integrity Technology Group, which operates as a commercial entity while maintaining deep operational ties to Chinese state security interests. U.S. and UK authorities previously moved to penalize the firm, citing its involvement in aggressive and irresponsible cyber intrusions. Former FBI Director Christopher Wray previously noted that company leadership publicly acknowledged collecting intelligence and performing reconnaissance on behalf of Chinese government agencies for years.

The exposure of this extensive campaign follows a major counter-cyber operation in September 2024, when the FBI disrupted a massive botnet known as Raptor Train. Controlled by Integrity Technology Group, that infrastructure hijacked more than 200,000 consumer-grade devices, including routers and security cameras, routing malicious traffic and expanding the firm’s operational footprint. While that disruption targeted the botnet itself, the latest international advisory shifts focus to the sophisticated intrusion methods, lateral movement techniques, and data exfiltration processes employed by the threat actors.

Sophisticated Intrusion Techniques and Vulnerability Exploitation

The multi-page advisory provides a granular breakdown of how the hackers breach perimeter defenses, beginning with widespread automated reconnaissance. Using open-source scanning tools typically found on public repositories like GitHub—such as Nmap, masscan, and WPScan—the actors probe networks for exposed ports, focusing heavily on standard communication channels including ports 21, 22, 53, 80, 443, and 1080.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

In addition to standard utilities, the hackers have relied since at least 2017 on a proprietary or customized Python-based web application known as MicroScan. This tool incorporates more than 1,300 distinct penetration testing scripts tailored to discover specific web application flaws. The targeted platforms and software include widely deployed enterprise solutions such as OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts.

The advisory highlights a series of specific vulnerabilities exploited during these intrusions, many of which are associated with well-documented software flaws spanning over a decade. These include historical and critical vulnerabilities such as the GNU Bash command injection flaw known as Shellshock, ProFTPD vulnerabilities, ISC BIND denial-of-service bugs, Apache Struts remote code execution vulnerabilities, Pulse Connect Secure path traversal flaws, GitLab remote code execution issues, ONLYOFFICE Document Server vulnerabilities, and Strapi content management system flaws. Several of these security holes have recently been added to official catalog tracking known exploited vulnerabilities, underscoring the enduring danger of unpatched enterprise software.

Beyond direct vulnerability exploitation, the threat actors deployed deceptive social engineering tactics, including cross-site scripting payloads designed to inject fake login prompts into legitimate web pages. When unsuspecting users entered their credentials, the compromised interface offered a password-protected archive containing malicious executables. These binaries initiated background processes mimicking legitimate Windows system files to establish encrypted command-and-control communications with domains attributed to Integrity Technology Group.

The hackers also utilized password-spraying techniques to compromise Microsoft 365 and Exchange environments. By leveraging an open-source Python tool called EBurst, the operators tested common passwords across a vast array of authentication interfaces, including Exchange Control Panel, Exchange Web Services, Outlook Web Access, and PowerShell APIs, forcing defenders to monitor multiple entry points simultaneously.

Sustained Access and Extensive Data Exfiltration

Once inside a network, the threat actors employed stealthy persistence mechanisms to maintain access without triggering immediate security alerts. They frequently installed SoftEther, a legitimate virtual private network program, and disguised the installer under innocuous Windows system filenames such as conhost.exe or dllhost.exe. These tools were configured to automatically re-establish connections upon system restarts.

To harvest administrative credentials and domain information, the operators executed tools leveraging DCSync capabilities, allowing them to extract sensitive data directly from domain controllers through Active Directory replication services. This yielded deep insights into network topography, account group memberships, and organizational trust relationships.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

The primary objective of the campaign, however, appeared to be massive, targeted email theft. The hackers deployed custom tools and automated scripts, such as a PHP-based bot configured to harvest mailboxes, calendars, and contacts via Exchange Web Services. This data was subsequently compressed, encrypted, and funneled to remote command-and-control infrastructure. A secondary utility, office-cli, maintained persistent connections to Microsoft 365 accounts, methodically extracting mail archives across different historical periods while evading behavioral detection by blending in with legitimate access protocols.

In certain instances, exfiltrated data was routed exclusively to specific geographic IP addresses located in Xiamen, China. Furthermore, the advisory revealed that the actors maintained a dedicated web application enabling third-party entities to access stolen email contents directly through parameterized URLs, though the identities of those third-party beneficiaries remain undisclosed in public government findings.

International Response and Defensive Recommendations

The release of the coordinated international advisory underscores a deepening resolve among Western intelligence agencies to expose the intersection of commercial enterprises and state-sponsored cyber espionage. By publicly mapping out the infrastructure, tools, and indicators of compromise associated with Integrity Technology Group, governments aim to force organizations globally to audit their digital perimeters.

Targeted organizations and enterprises worldwide have been urged to conduct thorough threat-hunting exercises using the extensive indicators of compromise provided in the advisory, which include associated IP addresses, domains, and file hashes dating back several years. Cybersecurity authorities emphasize that swift isolation of compromised hosts, comprehensive log analysis, and rigorous vulnerability patching remain critical defenses against sophisticated threat actors capable of blending custom scripts with legitimate administrative tools to sustain long-term espionage campaigns.

Leave a Reply

Your email address will not be published. Required fields are marked *