Threat reportAPTTL-2026-3054
Chinese Government-linked Actors Enabled by Integrity Technology Group Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data (CISA AA26-281A)
Chinese Government-linked Actors Enabled by Integrity (TL-2026-3054), also tracked as AA26-281A, is a high-severity advanced persistent threat campaign, first published 2026-10-08 and last reviewed 2026-10-09. It is attributed to Integrity Technology Group-enabled actors (China) with high confidence, affects GNU Bash, references 8 CVEs (CVE-2014-6278, CVE-2015-3306, CVE-2015-5477), maps to 24 MITRE ATT&CK techniques (T1003.006, T1020, T1036.003), and is covered by 9 detection rules and 74 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 8Referenced vulnerabilities
- Techniques
- 24MITRE ATT&CK
- Actors
- 1Integrity Technology Group-enabled actors
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 74Indicators of compromise
Key facts for TL-2026-3054
- Threat ID
- TL-2026-3054
- Also known as
- AA26-281A, Integrity Tech botnet and email theft campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- Integrity Technology Group-enabled actors
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government administration, critical-manufacturing, health, information-technology, police - law enforcement, education, religious-organizations
- Target regions
- united states of america, North America, Southeast Asia, Africa
- Detection rules
- 9
- Indicators of compromise
- 74
- Updates
- 2026-10-09 · 5 updates · revalidated 5× · latest source
Malware and tooling in Chinese Government-linked Actors Enabled by Integrity
Malware and tooling: JuicyPotato, MicroScan, eburst.py
How Chinese Government-linked Actors Enabled by Integrity works
A joint FBI/CISA/NSA and international advisory attributes a long-running intrusion set to China-linked actors enabled by Integrity Technology Group (Integrity Tech), whose TTPs align with Flax Typhoon, Ethereal Panda and Red Juliett. The actors pair automated scanning, botnet-hosted infrastructure and hands-on exploitation of eight older CVEs to steal email and other sensitive data from US critical infrastructure and organizations in Southeast Asia, Africa and North America.
CISA Advisory AA26-281A (released 2026-10-08) was authored by the FBI, CISA, NSA, UK NCSC, Australia's ACSC, the Canadian Cyber Centre, Japan's NPA and NCO, New Zealand's NCSC-NZ and Spain's CNI, based on multiple FBI investigations related to Integrity Technology Group, a China-based for-profit company with links to the Chinese government that builds or acquires cyber tools, hosts infrastructure and compromises networks. The advisory states the observed TTPs are consistent with vendor-tracked clusters Flax Typhoon, Ethereal Panda and Red Juliett, but cautions vendor names may not map 1:1 to US government attribution and that these actors may conduct activity unrelated to Integrity Tech.
Reconnaissance and initial access are heavily automated. Actors scan for vulnerable internet-facing services (focus ports 21, 22, 53, 80, 443, 1080) with open-source tools including BBScan, dirsearch, Fscan, ksubdomain, masscan, Nmap, OneForAll, ShuiZe and wpscan, and use MicroScan, a Python web application bundling more than 1,300 penetration-testing scripts that has been in use since 2017. Successfully exploited vulnerabilities are CVE-2014-6278 (GNU Bash), CVE-2015-3306 (ProFTPD 1.3.5), CVE-2015-5477 (ISC BIND 9), CVE-2016-3081 (Apache Struts), CVE-2019-11510 (Pulse Connect Secure), CVE-2021-22205 (GitLab), CVE-2021-3199 (ONLYOFFICE DocumentServer) and CVE-2023-22894 (Strapi); five of these were newly added to CISA KEV with this advisory. A second vector injects XSS payloads into vulnerable third-party websites that rewrite the page into a fake login form and then offer a password-protected ZIP containing live700_v1.exe, which launches DiagTrack.exe, a masquerading email-querying implant that talks over encrypted HTTP to dns.studiocloud.xyz.
Post-compromise the actors use Impacket secretsdump, a DCSync tool (dc.exe) and JuicyPotato for credential theft and privilege escalation, deploy webshells (b374.php, back.pl, error.jsp, file_back.aspx, gf.phtml, yaml-payload.jar), and persist and obscure C2 with SoftEther VPN clients renamed to conhost.exe and dllhost.exe, configured to reconnect on startup and often unflagged by endpoint tools because SoftEther is legitimate software. Email theft is the core objective: curlc4.txt, a standalone PHP bot, uses the Exchange Web Services API to pull mail, calendars and contacts, stages them in a writable directory (e.g. /var/tmp/.sess.zip), compresses and sometimes encrypts them with RC4 or AES-128-CBC, and uploads to natcloudservice.com infrastructure; office-cli, a Linux binary, repeatedly accesses Microsoft 365 mailboxes using client_id/tenant_id/secret values from JSON config, and eburst.py sprays passwords against Exchange/O365 endpoints. The actors rotate to fresh accounts and run a custom web application that serves stolen email to third parties. Victims include US Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, Information Technology, law enforcement, education and religious organizations, plus government, law enforcement, healthcare and religious institutions in Southeast Asia, and targets in Africa and North America. Observed indicators span 2016-2026 and the advisory warns that older IOCs must be vetted before blocking. Related prior public reporting (September 2024) tied the Raptor Train botnet, a Mirai variant botnet of 260,000+ devices, to Integrity Tech and Flax Typhoon; the FBI disrupted it.
MITRE ATT&CK techniques used in TL-2026-3054
Credential Access
T1003.006 OS Credential Dumping: DCSync; T1110.001 Brute Force: Password Guessing; T1110.003 Brute Force: Password Spraying
Exfiltration
Stealth
T1036.003 Masquerading: Rename Legitimate Utilities
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python; T1059.007 Command and Scripting Interpreter: JavaScript
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1572 Protocol Tunneling
Collection
T1074.001 Data Staged: Local Data Staging; T1114.002 Email Collection: Remote Email Collection; T1560.003 Archive Collected Data: Archive via Custom Method
Persistence
T1133 External Remote Services; T1505.003 Server Software Component: Web Shell
Initial Access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566 Phishing; T1566.002 Phishing: Spearphishing Link
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1584.005 Compromise Infrastructure: Botnet
Reconnaissance
Affected products and versions in Chinese Government-linked Actors Enabled by Integrity
- GNU — Bash
Vulnerable versions: through 4.3 (bash43-026) - ProFTPD — ProFTPD
Vulnerable versions: 1.3.5 - ISC — BIND 9
Vulnerable versions: before 9.9.7-P2; 9.10.x before 9.10.2-P3
Fixed in: 9.9.7-P2; 9.10.2-P3 - Apache — Struts
Vulnerable versions: 2.3.19-2.3.20.2; 2.3.21-2.3.24.1; 2.3.25-2.3.28 - Pulse Secure — Pulse Connect Secure
Vulnerable versions: 8.2 before 8.2R12.1; 8.3 before 8.3R7.1; 9.0 before 9.0R3.4
Fixed in: 8.2R12.1; 8.3R7.1; 9.0R3.4 - GitLab — GitLab
Vulnerable versions: all versions from 11.9 - ONLYOFFICE — DocumentServer
Vulnerable versions: 5.1.5-5.6.2 - Strapi — Strapi
Vulnerable versions: up to 4.5.5 - Microsoft — Exchange / Microsoft 365 mail
Vulnerable versions: targeted via EWS, password spraying and app credentials
Remediation for Chinese Government-linked Actors Enabled by Integrity
Patches
- Bash: patch beyond bash43-026 (CVE-2014-6278)
- ProFTPD: upgrade from 1.3.5 (CVE-2015-3306)
- ISC BIND: 9.9.7-P2 / 9.10.2-P3 or later (CVE-2015-5477)
- Apache Struts: upgrade to a release fixing CVE-2016-3081
- Pulse Connect Secure: 8.2R12.1 / 8.3R7.1 / 9.0R3.4 or later (CVE-2019-11510)
- GitLab: upgrade past versions affected by CVE-2021-22205
- ONLYOFFICE DocumentServer: upgrade past 5.6.2 (CVE-2021-3199)
- Strapi: upgrade past 4.5.5 (CVE-2023-22894)
Immediate actions
- Hunt for and vet (do not blindly block) the advisory IOCs: natcloudservice.com, studiocloud.xyz, SoftEther hosts and the listed hashes
- Review web logs for directory traversal, command injection and enumeration, and look for the listed webshell filenames
- Hunt for renamed SoftEther clients (conhost.exe / dllhost.exe outside system paths) and unexpected outbound VPN sessions
- Monitor for unexpected AD replication (DCSync), high-volume outbound uploads, abnormal logons and cloud-connected apps accessing email
- Isolate affected hosts, scope the intrusion, report per national requirements and apply CISA Eviction Strategies Tool guidance
Workarounds
- Replace end-of-life products that cannot be patched
- Remove internet exposure of file-sharing, remote-access and automatic-configuration services
Longer-term hardening
- Require phishing-resistant MFA, especially for webmail, VPNs and critical systems; replace default passwords; audit admin accounts
- Sanitize user input to prevent XSS and harden internet-facing applications
- Segment networks and edge devices; apply least-privilege connectivity
- Enable protective DNS and download/domain reputation screening; keep AV with real-time detection updated
- Use attack surface management; disable unused services and ports; minimize login-banner information
- Maintain offline access-controlled backups and test controls against the listed ATT&CK techniques
CVEs associated with Chinese Government-linked Actors Enabled by Integrity
CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894
Weaknesses (CWE) in Chinese Government-linked Actors Enabled by Integrity
CWE-78, CWE-284, CWE-19, CWE-77, CWE-22, CWE-94, CWE-312, CWE-79, CWE-617
Timeline of Chinese Government-linked Actors Enabled by Integrity
Showing the 20 most recent tracked events.
- A Taiwanese university was scanned via MicroScan prior to a subsequent breach (August 2022).
- A second Taiwanese university was scanned via MicroScan prior to breach (March 2023).
- Raptor Train peaked at roughly 60,000 actively compromised devices (June 2023).
- Microsoft publishes analysis of Flax Typhoon targeting Taiwanese organizations with legitimate software, including SoftEther VPN persistence.
- natcloudservice.com, the main Curlc4 email-bot C2, first seen (last seen 2024-09-08).
- 149.28.132.137, used for Curlc4 download, active from 2024-02-23 to 2024-07-05.
- Mirai-variant botnet database snapshot: 1.2M+ devices (385K+ in US), roughly 260K actively infected (~126K in US).
- SoftEther VPN persistence still present in compromised Taiwanese university networks through August 2024 (month precision).
- FBI and partners disrupt the Raptor Train botnet (260,000+ devices) attributed to Integrity Tech and linked to Flax Typhoon, per contemporaneous press coverage.
- UK sanctioned Integrity Tech (2025; year-level precision, day not stated).
- US Treasury (OFAC) sanctions Integrity Technology Group for its role in Flax Typhoon activity.
- UK sanctioned Integrity Technology Group and i-Soon (2025-12-09), citing a 260,000+ device botnet.
- EU sanctioned Integrity Tech (2026; year-level precision, day not stated in source).
- FishHub observed active as of March 2026 (month precision).
- MicroScan domain confirmed still online (September 2026), prior to the 2026-10-08 seizure.
- Microsoft disables Exchange Web Services by default in Exchange Online (full retirement 2027-04-01; on-premises unaffected), relevant to the EWS-based mailbox theft.
- US Magistrate Judge Maureen P. Kelly (W.D. Pa.) issues the seizure warrant for the Microscan/FishHub domains.
- FBI executed court-authorized seizure warrants (W.D. Pa.) for seven domains supporting the MicroScan scanner, FishHub spear-phishing platform and SoftEther VPN infrastructure; DOJ announced the action alongside AA26-281A.
- FBI, CISA, NSA and partners publish AA26-281A; five of the eight exploited CVEs are added to the CISA KEV catalog.
- Federal remediation deadline for the five CVEs newly added to the CISA KEV catalog with AA26-281A.
Update history for TL-2026-3054
- 2026-10-09 — Flax Typhoon (Integrity Technology Group) Exploits Five Flaws Added to CISA KEV (CVE-2015-3306, CVE-2021-3199, CVE-2023-22894, CVE-2016-3081, CVE-2015-5477) - Joint Advisory AA26-281A: What changed No field escalations. Additive intelligence only: CWE-617 (ISC BIND reachable assertion), KEV federal remediation deadline of 2026-10-11, and SoftEther persistence evidenced through August 2024. New indicators (8) 8 new indicat
- 2026-10-09 — US Disrupts China-Linked Integrity Technology Group (Flax Typhoon) Cyber Espionage Tools: Microscan, FishHub and Mirai-Variant Botnet (CISA AA26-281A): What changed No field escalation: severity HIGH, exploitability ACTIVE, status ACTIVE all already reflect the evidence. New indicators (7) 2 Microsoft-sourced Flax Typhoon IPs (39.98.208.61, 45.204.1.247), 4 advisory-named filenames (curlc4
- 2026-10-09 — FBI Disrupts Flax Typhoon Microscan and FishHub Infrastructure (Seven Domains Seized) - CISA AA26-281A: What changed No severity, exploitability or status change; existing values (HIGH / ACTIVE) already match the newer report. New indicators (7) 1 new domain (alitagotest.cf), 5 new IPs (3 from AA26-281A, 2 Microsoft-reported Flax Typhoon C2),
- 2026-10-09 — China-linked Integrity Technology Group (Flax Typhoon / Ethereal Panda / Red Juliett) enabling global data theft via botnets, MicroScan/FishHub tooling and hands-on exploitation (CISA AA26-281A): What changed No severity, exploitability, status or attribution change; severity stays HIGH and exploitability ACTIVE. Update is additive intelligence only. New indicators (10) 2 sample C2 domains, 1 additional SoftEther dllhost.exe hash, 3
- 2026-10-09 — FBI Disrupts Flax Typhoon (Integrity Technology Group) MicroScan and FishHub Tooling Used to Breach Critical Infrastructure (AA26-281A): What changed No severity, exploitability or status change (already HIGH / ACTIVE). The record gains law-enforcement disruption context: seizure of seven domains and identification of the FishHub spear-phishing platform. New indicators (11)
Sources cited for Chinese Government-linked Actors Enabled by Integrity
- CISA AA26-281A: Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
- CISA Known Exploited Vulnerabilities Catalog
- NVD - CVE-2019-11510 (Pulse Connect Secure)
- NVD - CVE-2021-22205 (GitLab)
- NVD - CVE-2016-3081 (Apache Struts)
- NVD - CVE-2023-22894 (Strapi)
- NVD - CVE-2021-3199 (ONLYOFFICE DocumentServer)
- FBI forced Flax Typhoon to abandon its botnet (Help Net Security)
- FBI operation against China botnet Flax Typhoon (CyberScoop)
- FBI disrupts another Chinese state-sponsored botnet (TechTarget)
- FBI Disrupts Another Massive Chinese-Linked Botnet (Security Boulevard)
Detection coverage for TL-2026-3054
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3054 across Splunk SPL, Microsoft KQL and Sigma, covering 74 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.