Global Law Enforcement Exposes Sophisticated Cyber Espionage Campaign Linked to Chinese Firm

An international coalition of cybersecurity agencies, led by the Federal Bureau of Investigation alongside authorities from six other countries, has revealed a widespread and long-running cyber espionage campaign targeting critical institutions across Southeast Asia and beyond. The multi-nation advisory issued on October 8 details how hackers tied to a Chinese cybersecurity contractor systematically infiltrated government bodies, law enforcement agencies, healthcare infrastructure, and religious organizations to siphon sensitive communications and data.

The targeted firm at the center of the revelations, Integrity Technology Group, has already faced stringent economic sanctions imposed by both the United States and the United Kingdom. According to the joint government advisory, the operatives associated with the company deployed automated network scanning tools loaded with more than 1,300 specialized scripts. They systematically tested web applications for security flaws, attempted credential-guessing attacks against enterprise platforms like Microsoft 365 and Exchange, and deployed custom utilities designed to covertly harvest entire mailboxes.

Evidence compiled by investigators indicates that this network intrusion activity has been operational since at least mid-January 2021. While the advisory outlines the mechanics of these ongoing operations in detail, it does not specify exact timelines for individual data thefts or disclose the precise number of organizations compromised globally. The scope of the targeting extended far beyond Southeast Asian government networks, encompassing critical manufacturing facilities, educational institutions, IT infrastructure, and religious groups in North America, Africa, and the United States.

Investigators discovered that the threat actors established dedicated web applications to facilitate third-party access to the pilfered email contents, though the identities of those external beneficiaries remain undisclosed in public reports. This cyber espionage activity follows previous international enforcement actions, notably a September 2024 operation where the FBI disrupted a massive botnet controlled by Integrity Technology Group. That infrastructure, dubbed Raptor Train by security researchers, had commandeered upwards of 200,000 consumer routers, security cameras, and other connected Internet of Things devices.

While the 2024 disruption targeted the botnet itself, the October advisory focuses explicitly on the initial access vectors, lateral movement techniques, and data exfiltration methods observed during extensive forensic investigations into the company.

Who Is Behind It

Western security agencies characterize Integrity Technology Group as a commercially motivated enterprise deeply intertwined with Chinese state intelligence apparatuses. According to official assessments, company personnel actively develop, procure, and commercialize offensive cyber capabilities, host malicious infrastructure, and conduct direct network intrusions. The joint advisory frequently groups the corporate entity and the deployed threat actors under a single umbrella, though specific attribution for individual intrusions remains fluid.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

The U.S. Treasury Department officially sanctioned Integrity Technology Group in January 2025, citing its direct involvement in cyberattacks directed against domestic American entities. The United Kingdom followed suit by implementing restrictive measures in December 2025. These diplomatic and economic penalties built upon earlier warnings from senior Western intelligence officials. For instance, former FBI Director Christopher Wray stated publicly in 2024 that leadership within Integrity Technology Group had openly acknowledged collecting intelligence and performing reconnaissance on behalf of Chinese government security services over many years.

Technical analysts tracking these intrusions note that the operational methodologies mirror tactics historically associated with groups identified by private security firms as Flax Typhoon, Ethereal Panda, and RedJuliett. However, government attribution models do not always map neatly onto commercial threat intelligence nomenclature, and the underlying hackers may engage in concurrent operations completely independent of the sanctioned contractor. Microsoft famously tracked Flax Typhoon as early as 2023, noting its focus on organizations in regions like Taiwan.

Corporate leadership at Integrity Technology Group has strongly rejected the accusations levied by Western governments. Following the January 2025 U.S. sanctions, the company formally notified the Shanghai Stock Exchange that the punitive actions lacked any factual foundation. Simultaneously, spokespersons for the Chinese Ministry of Foreign Affairs condemned the Western measures, asserting Beijing’s firm opposition to foreign sanctions and complaints regarding external cyber operations.

How the Hackers Get In

The intrusion lifecycle typically begins with automated reconnaissance. The advisory notes that the threat actors leverage standard open-source utility programs such as Nmap, masscan, and WPScan to probe perimeter defenses, focusing heavily on standard communication ports including 21, 22, 53, 80, 443, and 1080. The heavy reliance on readily available public utilities indicates a preference for casting a wide net to identify vulnerable targets.

Alongside standard reconnaissance scripts, the hackers have operated a proprietary Python-based web application known as MicroScan since 2017. This utility houses more than 1,300 specialized penetration testing scripts aimed at exploiting known vulnerabilities in widely deployed enterprise software, including OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts. Officials from the UK’s National Cyber Security Centre highlighted that the actors uniquely incorporate artificial intelligence tools to automate aspects of their network scanning, though the core technical advisory primarily details manual and scripted execution.

Initial compromise frequently relies on command-line utilities built upon exploit code written in Python and Go. The joint advisory highlights several specific vulnerabilities successfully leveraged by the actors over the years. These include older critical flaws such as the GNU Bash command injection vulnerability, file inclusion flaws in ProFTPD, denial-of-service bugs in ISC BIND, and remote code execution vulnerabilities in Apache Struts, Pulse Connect Secure VPNs, GitLab instances, ONLYOFFICE Document Server, and Strapi CMS platforms. Several of these vulnerabilities were formally integrated into the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog alongside the advisory release.

In addition to software exploitation, the actors utilized sophisticated social engineering techniques, such as cross-site scripting payloads designed to inject fake login prompts into compromised web pages. When unsuspecting visitors entered their credentials, the malicious interface offered a password-protected archive containing an executable masquerading as a legitimate Windows diagnostic process. This background utility initiated encrypted communications with command-and-control domains attributed by the FBI directly to Integrity Technology Group.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Credential harvesting also relied on high-volume password spraying techniques. Using an open-source Python utility called EBurst, the operators systematically tested common passwords against large pools of Microsoft 365 and Exchange accounts. The utility targeted multiple enterprise authentication interfaces, including Exchange Control Panel, Exchange Web Services, Offline Address Book, Outlook on the Web, Remote Procedure Calls, application programming interfaces, MAPI protocols, PowerShell endpoints, Autodiscover, and ActiveSync services.

How They Stay and What They Take

Once inside a targeted network, the threat actors focused on persistence and stealth. They routinely installed SoftEther, a legitimate virtual private network program, to maintain covert access while evading detection by conventional security solutions. To blend in with normal administrative traffic, the operators frequently renamed the installation binaries to mimic standard Windows system files like conhost.exe or dllhost.exe, configuring the software to establish automatic reconnections upon system startup.

To escalate privileges and harvest internal credentials, the operators deployed a specialized tool designated DC.exe. This utility executed DCSync attacks, mimicking domain controllers through the Active Directory replication service to extract password hashes, group memberships, and trust relationship data across the enterprise domain.

Email exfiltration was executed using customized automation scripts. One prominent mechanism involved a PHP-based bot called Curlc4.txt, which interacted directly with Exchange Web Services to extract electronic mail, calendar entries, and contact lists. The utility compressed and occasionally encrypted the stolen data before uploading it to remote command-and-control infrastructure centered around domains like natcloudservice[.]com.

A secondary utility, office-cli, enabled persistent, targeted extraction from Microsoft 365 environments across specific historical timeframes. By utilizing legitimate access tokens defined in configuration files containing client and tenant identifiers, the tool successfully bypassed traditional behavioral alerts. Furthermore, investigators observed instances where the actors manually queried databases or directly downloaded bulk email repositories. In certain deployments, the operators restricted access to stolen datasets strictly to Internet Protocol addresses originating from Xiamen, China, while providing third-party users interface access via parameterized URLs.

Mitigation and Indicator Tracking

Defenders are strongly urged to audit their environments for indicators of compromise and anomalous authentication attempts across all exposed mail and remote access interfaces. The joint advisory provides extensive technical appendices featuring domains, IP addresses, and file hashes linked to the threat actors, spanning records dating back nearly a decade. Analysts note that while some infrastructure indicators overlap with previous alerts, individual activity timestamps require careful contextual analysis before implementing network blocks. Security agencies emphasize that thorough threat hunting, network isolation, and subsequent hardening remain essential steps for organizations working to eradicate unauthorized access from compromised enterprise environments.

Leave a Reply

Your email address will not be published. Required fields are marked *