Global Intelligence Agencies Expose China-Linked Cyber Campaign Targeting Government and Critical Infrastructure Across Southeast Asia

Law enforcement and intelligence agencies from seven countries, led by the Federal Bureau of Investigation, have issued a comprehensive joint advisory detailing a far-reaching cyberespionage campaign. The operations, which have been active since at least January 2021, targeted government organizations, law enforcement agencies, healthcare systems, and religious institutions primarily across Southeast Asia, alongside victims in North America and Africa.

The malicious activity has been directly tied to Integrity Technology Group, a China-based, for-profit cybersecurity company that has maintained close operational links to state security apparatuses. According to the international advisory, the enterprise utilizes a hybrid model of commercial operations and state-sponsored cyber intrusions, employing personnel who build or procure cyber exploitation tools, host command-and-control infrastructure, and execute covert network break-ins. Both the United States and the United Kingdom have implemented official sanctions against the firm in response to its sustained and aggressive cyber operations targeting foreign entities.

The newly released disclosures build upon previous enforcement actions, most notably a major disruption in September 2024 when the FBI dismantled a massive botnet controlled by Integrity Technology Group. That infrastructure, tracked by security researchers as Raptor Train, compromised upwards of 200,000 consumer-grade routers, security cameras, and other Internet of Things devices. While the 2024 operation successfully neutralized the botnet, the latest joint advisory shifts its focus to the specific intrusion vectors, credential-harvesting mechanisms, and exfiltration techniques deployed by the threat actors over several years of observed activity.

Who Is Behind It

The coordinated international warning describes Integrity Technology Group as a commercial entity that operates as a contractor and proxy for Chinese government intelligence operations. While official government advisories group the company and its deployed hackers under the unified label of "threat actors," investigative findings indicate that the firm’s leadership has openly acknowledged collecting foreign intelligence and conducting technical reconnaissance on behalf of state security agencies.

The operational signatures and toolsets utilized during these campaigns display strong behavioral overlaps with several well-documented state-sponsored hacking groups tracked by private cybersecurity firms under monikers such as Flax Typhoon, Ethereal Panda, and RedJuliett. For instance, Microsoft previously identified Flax Typhoon in 2023 for its focused targeting of organizations and critical infrastructure in Taiwan. Intelligence analysts note, however, that these commercial and tactical alignments fluidly overlap, and the individuals carrying out specific intrusions may engage in concurrent operations completely independent of their corporate affiliation.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

In response to previous punitive measures enacted by Western governments, Integrity Technology Group and Chinese diplomatic officials have vehemently denied any involvement in malicious cyber activities. Following U.S. Treasury sanctions imposed in early 2025, representatives for the company formally protested the move through financial regulatory filings, asserting that the allegations lacked factual grounding. Similarly, spokespersons for the Chinese Ministry of Foreign Affairs issued statements condemning the Western sanctions as baseless and politically motivated.

How the Hackers Get In

The advisory details a methodical and opportunistic approach to network compromise, beginning with wide-scale reconnaissance and vulnerability scanning. The operators routinely leverage open-source administrative and security testing tools commonly found on repositories like GitHub, including Nmap, masscan, and WPScan, focusing their automated scans on standard communication ports such as 21, 22, 53, 80, 443, and 1080.

Among the primary technical assets identified in the advisory is a custom Python-based web application known as MicroScan, which has been operational since 2017. Containing more than 1,300 specialized penetration testing scripts, MicroScan allows the hackers to automatically probe web applications and enterprise services for known security weaknesses. The targeted technologies include widely deployed platforms such as OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts.

The hackers rely heavily on command-line utilities built from exploit code written in languages like Python and Go. The joint advisory highlights several specific common vulnerabilities and exposures successfully targeted by these scripts, including historical and recent flaws across enterprise software ecosystems. These encompass GNU Bash command injection vulnerabilities, ProFTPD server flaws, ISC BIND denial-of-service bugs, Apache Struts remote code execution issues, Pulse Connect Secure VPN flaws, GitLab object storage vulnerabilities, ONLYOFFICE Document Server bugs, and Strapi content management system exploits. Several of these vulnerabilities were formally integrated into official known exploited vulnerability catalogs following investigations into the group’s methodologies.

In addition to software exploits, the operators have utilized cross-site scripting payloads to deploy deceptive login interfaces on compromised web pages. When unsuspecting visitors entered their corporate credentials, the manipulated sites prompted them to download password-protected archive files containing malicious executables. These binaries initiated background processes mimicking legitimate Windows system files to facilitate encrypted communications with command-and-control servers attributed to Integrity Technology Group, ultimately positioning the threat actors for deeper network infiltration.

Password spraying represents another core vector employed by the group, utilizing open-source utilities like EBurst to test common passwords against thousands of Microsoft 365 and Exchange user accounts. The tool systematically interacts with multiple native Exchange interfaces—including administrative endpoints, web access portals, remote procedure call gateways, and mobile synchronization services—compelling enterprise defenders to monitor and secure every potential entry point.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

How They Stay and What They Take

Once initial access is successfully established, the hackers implement rigorous persistence mechanisms to maintain long-term footholds within targeted networks. To blend in with normal administrative traffic and evade detection by endpoint security solutions, they frequently install SoftEther, a legitimate virtual private network program. The installers are often disguised with names resembling critical Windows system processes, such as conhost.exe or dllhost.exe, and configured to automatically re-establish connections upon system restarts.

For internal reconnaissance and privilege escalation, the actors deploy specialized credential-harvesting tools like DC.exe. This utility executes DCSync techniques, interacting directly with domain controllers through Active Directory replication services to duplicate sensitive account credentials, group memberships, and trust relationships across the enterprise environment.

The primary objective across many of these campaigns appears to be the systematic theft of sensitive correspondence, intelligence, and internal documents. The hackers developed custom automated scripts, such as a PHP-based utility designated Curlc4.txt, to extract communications via Exchange Web Services. This interface provides comprehensive access not only to user mailboxes but also to organizational calendars and global address lists. The harvested data is compressed, occasionally encrypted, and exfiltrated to remote infrastructure managed by the threat actors.

Additional persistence is maintained through specialized command-line utilities configured with specific tenant identifiers and access keys, enabling continuous and stealthy extraction of email records across various historical timelines. In certain instances observed by investigators, access to the repository of stolen communications was strictly restricted to specific geographic IP addresses located within Xiamen, China, while third-party associates were granted direct access through tailored web application interfaces.

International intelligence and law enforcement authorities continue to urge network defenders and organizations worldwide to review extensive technical indicators of compromise, isolate affected hosts, and implement robust monitoring strategies to mitigate the persistent risks posed by state-linked commercial espionage operations.

Leave a Reply

Your email address will not be published. Required fields are marked *