Global Law Enforcement Exposes State-Linked Cyber Campaign Targeting Government and Critical Infrastructure Across Multiple Continents

Law enforcement and intelligence agencies from seven countries have issued a sweeping joint cybersecurity advisory detailing a prolonged and sophisticated cyberespionage campaign orchestrated by hackers tied to a Chinese cybersecurity firm. According to the October 8 disclosure, the malicious actors systematically compromised email systems within government organizations, law enforcement agencies, healthcare networks, and religious institutions, primarily focusing their operations across Southeast Asia while simultaneously reaching targets in North America and Africa.

The private-sector entity at the center of the international scrutiny is Integrity Technology Group, a China-based, for-profit enterprise that has already faced heavy international repercussions. Both the United States and the United Kingdom have implemented official sanctions against the company, pointing to its extensive involvement in unauthorized computer intrusions and malicious digital activities directed at foreign critical infrastructure and institutional targets.

Joint findings compiled by the FBI and allied international agencies reveal that the threat actors utilized automated scanning architectures equipped with an extensive repository of penetration testing scripts to identify web vulnerabilities. By leveraging these scripts alongside credential-guessing techniques directed at Microsoft 365 and Exchange platforms, the operators gained unauthorized entry into sensitive networks. Once inside, they deployed specialized tools designed explicitly to harvest, siphon, and mirror complete mailboxes.

Evidence cited in the advisory indicates that these network intrusions have been active since at least mid-January 2021. While the international assessment describes the tactics and methodologies in the present tense, investigators have not published specific timelines regarding individual data thefts, nor have they publicly quantified the exact volume of organizations successfully breached during the multi-year campaign.

Beyond the primary impact observed in Southeast Asia, the same network of threat actors cast a wide international net, targeting critical manufacturing operations, information technology organizations, educational institutions, and government services in the United States and other Western nations. Investigators uncovered evidence that the operators maintain a dedicated web application infrastructure designed to facilitate third-party access to stolen email archives, though the specific identities of those third-party beneficiaries remain undisclosed in the official report.

The international advisory builds upon previous disruption efforts led by Western law enforcement. In September 2024, the FBI dismantled a massive botnet that the U.S. Department of Justice explicitly linked to Integrity Technology Group. Tracked by security researchers under the moniker "Raptor Train," the hijacked network controlled upwards of 200,000 compromised consumer devices, including routers and security cameras, leveraging them as resilient proxy infrastructure for malicious operations. While the 2024 intervention neutralized the botnet itself, the latest intelligence advisory sheds light on the broader operational tradecraft, initial access vectors, and specific data exfiltration methodologies employed by the syndicate.

Who Is Behind It

Western cybersecurity authorities characterize Integrity Technology Group as a commercial entity that operates with deep alignment to Chinese government intelligence priorities. The firm reportedly employs individuals tasked with developing, procuring, and deploying sophisticated cyber weapons, maintaining malicious infrastructure, and executing targeted network breaches.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Official attribution models note significant operational overlap between the tactics observed in this campaign and those tracked by private security researchers under threat group monikers such as Flax Typhoon, Ethereal Panda, and RedJuliett. For instance, Flax Typhoon has been monitored extensively by Microsoft since at least 2023, initially identifying its regional focus on entities located in Taiwan before expanding into a broader global threat landscape.

The corporate leadership of Integrity Technology Group has strongly rejected accusations leveled by Western governments. In January 2025, following the implementation of U.S. financial restrictions, the company communicated to the Shanghai Stock Exchange that the allegations lacked factual foundation. Official representatives from the Chinese Ministry of Foreign Ministries similarly voiced firm opposition to the sanctions, denouncing them as unfounded foreign interference.

Despite these official denials, statements from high-ranking international security officials underscore the deep ties between commercial contractors and state intelligence apparatuses in cyber operations. Former FBI Director Christopher Wray publicly noted in 2024 that the firm’s leadership had openly acknowledged collecting foreign intelligence and conducting reconnaissance on behalf of Chinese state security services for years.

How the Hackers Get In

The advisory details a methodical reconnaissance and exploitation process. The actors routinely employ open-source network discovery and vulnerability assessment utilities, including Nmap, masscan, and WPScan, focusing heavily on standard communication ports such as 21, 22, 53, 80, 443, and 1080. The reliance on publicly available reconnaissance tools commonly found on code-sharing platforms indicates a systematic approach to identifying vulnerable perimeter defenses.

A core component of the actors’ automated toolset is a custom Python-based web application known as MicroScan, which has been operational since 2017. Housing more than 1,300 specialized penetration testing scripts, MicroScan targets known software vulnerabilities across a broad spectrum of enterprise software, including enterprise servers, content management systems, and web frameworks.

The international advisory highlights multiple specific Common Vulnerabilities and Exposures (CVEs) successfully exploited by the threat actors. These include historical and modern flaws affecting widely used platforms such as GNU Bash, ProFTPD, ISC BIND, Apache Struts, Pulse Connect Secure, GitLab, ONLYOFFICE Document Server, and Strapi. Several of these vulnerabilities were recently incorporated into official vulnerability tracking catalogs as actively exploited in the wild.

In addition to software exploitation, the actors utilized deceptive web-based techniques, including cross-site scripting payloads injected into vulnerable web applications. These scripts dynamically alter legitimate pages to present convincing credential harvesting interfaces designed to capture administrative and user authentication data. Visitors who input their credentials are subsequently prompted to download malicious binaries disguised as harmless compressed files, establishing persistent command-and-control communications with external domains tied to the threat group.

To bypass multi-factor authentication defenses and compromise cloud environments, the actors relied heavily on password spraying techniques. Using custom and open-source command-line utilities such as EBurst, the operators systematically tested common passwords across a vast array of Microsoft 365 and Exchange authentication endpoints, including Exchange Control Panel, Exchange Web Services, Outlook Web Access, and mobile synchronization interfaces.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

How They Stay and What They Take

Once initial access is established, the threat actors prioritize persistence and stealth. Rather than deploying easily detectable malware, they frequently install legitimate remote management and virtual private network software, such as SoftEther, rebranding executable files to mimic essential Windows system processes like conhost.exe or dllhost.exe. These tools are configured to automatically re-establish connections upon system reboots.

For credential theft within compromised local networks, the operators utilized specialized utilities like DC.exe to execute DCSync attacks. This technique interacts directly with Active Directory replication services to extract master domain account credentials, group memberships, and trust relationships without requiring direct access to the primary domain controller’s physical storage.

Email exfiltration was executed through automated and manual mechanisms. The actors developed custom PHP-based scripts, including Curlc4.txt, which interface directly with Exchange Web Services to extract electronic mail, calendar entries, and contact lists. These archives were subsequently compressed, encrypted, and uploaded to dedicated command-and-control servers operating under infrastructure domains such as natcloudservice[.]com.

Additional persistence was maintained through specialized command-line utility configurations, such as office-cli, which systematically queried Microsoft 365 accounts over extended periods to harvest historical correspondence while evading traditional security monitoring. Investigators observed instances where access to the exfiltrated datasets was geographically restricted, routing exclusively through specific internet protocol addresses located in Xiamen, China. Dedicated web interfaces established by the group allowed authorized operators to retrieve specific mailboxes simply by adjusting URL parameters.

Defensive Recommendations and Ongoing Threat Monitoring

In response to the expansive findings, international cybersecurity agencies have published comprehensive mitigation guidance and extensive lists of indicators of compromise, including domain names, IP addresses, and cryptographic file hashes associated with the threat group’s operations. Organizations are strongly advised to review enterprise logs for historical anomalies, audit administrative access points across cloud and on-premises environments, and enforce robust multi-factor authentication policies resilient against password spraying and adversary-in-the-middle techniques.

While many of the associated indicators date back several years—with some overlapping with infrastructure documented during previous botnet disruptions in 2024—investigators emphasize that the threat group continues to adapt its operational infrastructure. Network defenders are encouraged to treat the advisory’s technical disclosures as foundational intelligence for retroactive threat hunting and comprehensive perimeter hardening.

Leave a Reply

Your email address will not be published. Required fields are marked *