Nine-Nation Alliance Warns of Integrity Tech-Linked Data Theft Campaign

A coalition of cybersecurity and intelligence agencies from nine countries has just published a joint warning about hacking activity believed to be linked to the Chinese government. According to the alert AA26-281A issued by CISA on October 8, 2026, agents supported by Integrity Technology Group have combined large-scale automated scanning, botnets, exploits, and manual operations to penetrate, maintain presence, and steal emails, credentials, and sensitive data.

The warning is notable because victims range from government agencies, law enforcement and education to health, information technology, critical manufacturing and religious institutions. The activity recorded in Southeast Asia, Africa and North America, shows that this is not a campaign limited to one country or one industry.

An IT technician works in a server room, illustrating infrastructure protection
Public-facing Internet infrastructure is a key entry point for large-scale scanning and exploitation campaigns. Real-world illustrative photo: Pexels.

Who Is Behind the Reported Activity?

CISA describes Integrity Technology Group, or Integrity Tech, as a company based in China and with ties to the Chinese government. The company is said to provide tools, infrastructure, and services that support a broader attack ecosystem. The observed techniques are consistent with the activity monitored by the cybersecurity industry under such names as Flax Typhoon, Ethereal Panda, and Red Juliett, although the CISA notes how the government and security enterprise teams may not be fully aligned.

The data in the alert comes from multiple FBI investigations. The document was released with the participation of the FBI, CISA, NSA and partner agencies in the UK, Australia, Canada, Japan, New Zealand and Spain. The goal is to help organizations hunt for signs of intrusion and reduce the risk of losing critical data.

From Automated Scanning to Hands-On Exploitation

At the reconnaissance stage, the team operates many familiar open source tools such as masscan, Nmap, dirsearch, BBScan, Fscan, OneForAll and wpscan. Common ports reviewed include FTP 21, SSH 22, DNS 53, HTTP 80, HTTPS 443, and socks 1080. This approach helps to quickly find public services, outdated software, or weakly configured web applications.

A prominent component is MicroScan, a web application written in Python that contains more than 1,300 penetration test scenarios. CISA says the tool has been used since 2017 to detect bugs in OpenSSL, Oracle WebLogic, WordPress, Jenkins, Apache Struts, and more. Once a matching target is detected, the agent switches to direct mining using Python, Go, JavaScript, or HTML code.

Old Vulnerabilities Still Create New Risks

The list of successful exploits spans several years, including Shellshock CVE-2014-6278, ProFTPD CVE-2015-3306, BIND CVE-2015-5477, Apache Struts CVE-2016-3081, Pulse Secure CVE-2019-11510, GitLab CVE-2021-22205, and CVE-2021-3199 and CVE-2023-22894. Some bugs are more than a decade old but are still useful when the Internet device has not been patched or has reached the end of its support life.

The CISA also added five of these vulnerabilities to the Known Exploited Vulnerabilities category. That underscores a fact: CVE's age does not reflect the urgency if attackers still find vulnerable systems on the Internet.

Email and Credentials Are Primary Targets

Agents use EBurst to spray passwords and guess passwords across multiple Microsoft Exchange interfaces, including OWA, EWS, ECP, ActiveSync, MAPI, RPC, PowerShell, and Autodiscover. An XSS download recovered by the FBI also created a fake login form on the compromised website, then lured the victim into downloading a compressed file with a malicious program.

At the collection stage, the PHP script Curlc4.txt accesses EWS to retrieve emails, calendars, and contacts, compress the data, and transfer it to the remote server. The office-cli tool is used to automatically access Microsoft 365 mailboxes using client IDs, tenant IDs, and secrets. The FBI also observed DC.exe implementing the DCSync technique to copy sensitive information from Active Directory, including credentials, team members, and trust relationships.

Legitimate Software Turned Into a Persistence Tool

To hold on, the team installs SoftEther VPN on the victim's machine and then configures the connection on startup. Installer can be renamed to conhost.exe hoặc dllhost.exe to resemble the normal Windows process. Since SoftEther is a legitimate VPN software, it is easy to miss suspicious behavior based on the product name alone.

This is a good example of the technique of living off existing tools or dual-purpose software. A more valuable indication is an unapproved VPN that appears on the server, an automatic connection to an unknown infrastructure, an abnormal increase in upload traffic, or a legitimate process running from a non-standard path.

What Should Organizations Prioritize?

  1. Make a list of all Internet exposure services; close unused ports and features, and replace products that have reached end of support.
  2. Patch the CVEs outlined in AA26-281A and collate the KEV catalogue, rather than just focusing on the newly released vulnerability.
  3. Mandatory MFA for webmail, VPN, and critical system access accounts; separation of administrative accounts and regular review of privileges.
  4. Check web logs for signs of scanning, traversal, command injection, or XSS; monitor DCSync behavior, and the cloud app has permission to read emails.
  5. Unlicensed SoftEther hunting, connection to domain or IP in CISA's IOC kit, impossible login and abnormal upload traffic.
  6. If intrusion is detected, preserve evidence before expelling the agent; password rotation, service lock, and application secret are likely to be exposed.

Lessons From Advisory AA26-281A

Campaigns show that automation and manual action are not mutually exclusive. Wide-area scanning helps find targets at low cost, and operators intervene when deep mining, evading defenses, or selecting valuable data is needed. Outdated systems, redundant services, and email accounts lacking MFA become the juncture between these two periods.

Effective defenses must therefore cover the surface of the Internet, identity, and post-intrusion behavior. Patching is fundamental, but organizations also need to segment networks, centralize logs, monitor cloud accounts, test MITRE ATT&CK controls, and maintain a recovery plan. The Stix IOC kit provided by CISA should be entered into the monitoring tool, but should not replace behavior-based detection.

VNCyberS compiled from CISA, FBI, NSA, and international partner agencies

Contact Us

Email: [email protected]
Phone: +84 903260277