Threat reportAPTTL-2026-3054

Chinese Government-linked Actors Enabled by Integrity Technology Group Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data (CISA AA26-281A)

highACTIVE

Chinese Government-linked Actors Enabled by Integrity (TL-2026-3054), also tracked as AA26-281A, is a high-severity advanced persistent threat campaign, first published 2026-10-08 and last reviewed 2026-10-09. It is attributed to Integrity Technology Group-enabled actors (China) with high confidence, affects GNU Bash, references 8 CVEs (CVE-2014-6278, CVE-2015-3306, CVE-2015-5477), maps to 24 MITRE ATT&CK techniques (T1003.006, T1020, T1036.003), and is covered by 9 detection rules and 74 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
8Referenced vulnerabilities
Techniques
24MITRE ATT&CK
Actors
1Integrity Technology Group-enabled actors
Detection rules
9SPL · KQL · Sigma
IOCs
74Indicators of compromise

Key facts for TL-2026-3054

Threat ID
TL-2026-3054
Also known as
AA26-281A, Integrity Tech botnet and email theft campaign
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
Integrity Technology Group-enabled actors
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, critical-manufacturing, health, information-technology, police - law enforcement, education, religious-organizations
Target regions
united states of america, North America, Southeast Asia, Africa
Detection rules
9
Indicators of compromise
74
Updates
2026-10-09 · 5 updates · revalidated 5× · latest source

Malware and tooling in Chinese Government-linked Actors Enabled by Integrity

Malware and tooling: JuicyPotato, MicroScan, eburst.py

How Chinese Government-linked Actors Enabled by Integrity works

A joint FBI/CISA/NSA and international advisory attributes a long-running intrusion set to China-linked actors enabled by Integrity Technology Group (Integrity Tech), whose TTPs align with Flax Typhoon, Ethereal Panda and Red Juliett. The actors pair automated scanning, botnet-hosted infrastructure and hands-on exploitation of eight older CVEs to steal email and other sensitive data from US critical infrastructure and organizations in Southeast Asia, Africa and North America.

CISA Advisory AA26-281A (released 2026-10-08) was authored by the FBI, CISA, NSA, UK NCSC, Australia's ACSC, the Canadian Cyber Centre, Japan's NPA and NCO, New Zealand's NCSC-NZ and Spain's CNI, based on multiple FBI investigations related to Integrity Technology Group, a China-based for-profit company with links to the Chinese government that builds or acquires cyber tools, hosts infrastructure and compromises networks. The advisory states the observed TTPs are consistent with vendor-tracked clusters Flax Typhoon, Ethereal Panda and Red Juliett, but cautions vendor names may not map 1:1 to US government attribution and that these actors may conduct activity unrelated to Integrity Tech.

Reconnaissance and initial access are heavily automated. Actors scan for vulnerable internet-facing services (focus ports 21, 22, 53, 80, 443, 1080) with open-source tools including BBScan, dirsearch, Fscan, ksubdomain, masscan, Nmap, OneForAll, ShuiZe and wpscan, and use MicroScan, a Python web application bundling more than 1,300 penetration-testing scripts that has been in use since 2017. Successfully exploited vulnerabilities are CVE-2014-6278 (GNU Bash), CVE-2015-3306 (ProFTPD 1.3.5), CVE-2015-5477 (ISC BIND 9), CVE-2016-3081 (Apache Struts), CVE-2019-11510 (Pulse Connect Secure), CVE-2021-22205 (GitLab), CVE-2021-3199 (ONLYOFFICE DocumentServer) and CVE-2023-22894 (Strapi); five of these were newly added to CISA KEV with this advisory. A second vector injects XSS payloads into vulnerable third-party websites that rewrite the page into a fake login form and then offer a password-protected ZIP containing live700_v1.exe, which launches DiagTrack.exe, a masquerading email-querying implant that talks over encrypted HTTP to dns.studiocloud.xyz.

Post-compromise the actors use Impacket secretsdump, a DCSync tool (dc.exe) and JuicyPotato for credential theft and privilege escalation, deploy webshells (b374.php, back.pl, error.jsp, file_back.aspx, gf.phtml, yaml-payload.jar), and persist and obscure C2 with SoftEther VPN clients renamed to conhost.exe and dllhost.exe, configured to reconnect on startup and often unflagged by endpoint tools because SoftEther is legitimate software. Email theft is the core objective: curlc4.txt, a standalone PHP bot, uses the Exchange Web Services API to pull mail, calendars and contacts, stages them in a writable directory (e.g. /var/tmp/.sess.zip), compresses and sometimes encrypts them with RC4 or AES-128-CBC, and uploads to natcloudservice.com infrastructure; office-cli, a Linux binary, repeatedly accesses Microsoft 365 mailboxes using client_id/tenant_id/secret values from JSON config, and eburst.py sprays passwords against Exchange/O365 endpoints. The actors rotate to fresh accounts and run a custom web application that serves stolen email to third parties. Victims include US Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, Information Technology, law enforcement, education and religious organizations, plus government, law enforcement, healthcare and religious institutions in Southeast Asia, and targets in Africa and North America. Observed indicators span 2016-2026 and the advisory warns that older IOCs must be vetted before blocking. Related prior public reporting (September 2024) tied the Raptor Train botnet, a Mirai variant botnet of 260,000+ devices, to Integrity Tech and Flax Typhoon; the FBI disrupted it.

MITRE ATT&CK techniques used in TL-2026-3054

Credential Access

T1003.006 OS Credential Dumping: DCSync; T1110.001 Brute Force: Password Guessing; T1110.003 Brute Force: Password Spraying

Exfiltration

T1020 Automated Exfiltration

Stealth

T1036.003 Masquerading: Rename Legitimate Utilities

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python; T1059.007 Command and Scripting Interpreter: JavaScript

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1572 Protocol Tunneling

Collection

T1074.001 Data Staged: Local Data Staging; T1114.002 Email Collection: Remote Email Collection; T1560.003 Archive Collected Data: Archive via Custom Method

Persistence

T1133 External Remote Services; T1505.003 Server Software Component: Web Shell

Initial Access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566 Phishing; T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1584.005 Compromise Infrastructure: Botnet

Reconnaissance

T1595.002 Active Scanning: Vulnerability Scanning

Affected products and versions in Chinese Government-linked Actors Enabled by Integrity

  • GNU — Bash
    Vulnerable versions: through 4.3 (bash43-026)
  • ProFTPD — ProFTPD
    Vulnerable versions: 1.3.5
  • ISC — BIND 9
    Vulnerable versions: before 9.9.7-P2; 9.10.x before 9.10.2-P3
    Fixed in: 9.9.7-P2; 9.10.2-P3
  • Apache — Struts
    Vulnerable versions: 2.3.19-2.3.20.2; 2.3.21-2.3.24.1; 2.3.25-2.3.28
  • Pulse Secure — Pulse Connect Secure
    Vulnerable versions: 8.2 before 8.2R12.1; 8.3 before 8.3R7.1; 9.0 before 9.0R3.4
    Fixed in: 8.2R12.1; 8.3R7.1; 9.0R3.4
  • GitLab — GitLab
    Vulnerable versions: all versions from 11.9
  • ONLYOFFICE — DocumentServer
    Vulnerable versions: 5.1.5-5.6.2
  • Strapi — Strapi
    Vulnerable versions: up to 4.5.5
  • Microsoft — Exchange / Microsoft 365 mail
    Vulnerable versions: targeted via EWS, password spraying and app credentials

Remediation for Chinese Government-linked Actors Enabled by Integrity

Patches

  • Bash: patch beyond bash43-026 (CVE-2014-6278)
  • ProFTPD: upgrade from 1.3.5 (CVE-2015-3306)
  • ISC BIND: 9.9.7-P2 / 9.10.2-P3 or later (CVE-2015-5477)
  • Apache Struts: upgrade to a release fixing CVE-2016-3081
  • Pulse Connect Secure: 8.2R12.1 / 8.3R7.1 / 9.0R3.4 or later (CVE-2019-11510)
  • GitLab: upgrade past versions affected by CVE-2021-22205
  • ONLYOFFICE DocumentServer: upgrade past 5.6.2 (CVE-2021-3199)
  • Strapi: upgrade past 4.5.5 (CVE-2023-22894)

Immediate actions

  • Hunt for and vet (do not blindly block) the advisory IOCs: natcloudservice.com, studiocloud.xyz, SoftEther hosts and the listed hashes
  • Review web logs for directory traversal, command injection and enumeration, and look for the listed webshell filenames
  • Hunt for renamed SoftEther clients (conhost.exe / dllhost.exe outside system paths) and unexpected outbound VPN sessions
  • Monitor for unexpected AD replication (DCSync), high-volume outbound uploads, abnormal logons and cloud-connected apps accessing email
  • Isolate affected hosts, scope the intrusion, report per national requirements and apply CISA Eviction Strategies Tool guidance

Workarounds

  • Replace end-of-life products that cannot be patched
  • Remove internet exposure of file-sharing, remote-access and automatic-configuration services

Longer-term hardening

  • Require phishing-resistant MFA, especially for webmail, VPNs and critical systems; replace default passwords; audit admin accounts
  • Sanitize user input to prevent XSS and harden internet-facing applications
  • Segment networks and edge devices; apply least-privilege connectivity
  • Enable protective DNS and download/domain reputation screening; keep AV with real-time detection updated
  • Use attack surface management; disable unused services and ports; minimize login-banner information
  • Maintain offline access-controlled backups and test controls against the listed ATT&CK techniques

CVEs associated with Chinese Government-linked Actors Enabled by Integrity

CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894

Weaknesses (CWE) in Chinese Government-linked Actors Enabled by Integrity

CWE-78, CWE-284, CWE-19, CWE-77, CWE-22, CWE-94, CWE-312, CWE-79, CWE-617

Timeline of Chinese Government-linked Actors Enabled by Integrity

Showing the 20 most recent tracked events.

  • A Taiwanese university was scanned via MicroScan prior to a subsequent breach (August 2022).
  • A second Taiwanese university was scanned via MicroScan prior to breach (March 2023).
  • Raptor Train peaked at roughly 60,000 actively compromised devices (June 2023).
  • Microsoft publishes analysis of Flax Typhoon targeting Taiwanese organizations with legitimate software, including SoftEther VPN persistence.
  • natcloudservice.com, the main Curlc4 email-bot C2, first seen (last seen 2024-09-08).
  • 149.28.132.137, used for Curlc4 download, active from 2024-02-23 to 2024-07-05.
  • Mirai-variant botnet database snapshot: 1.2M+ devices (385K+ in US), roughly 260K actively infected (~126K in US).
  • SoftEther VPN persistence still present in compromised Taiwanese university networks through August 2024 (month precision).
  • FBI and partners disrupt the Raptor Train botnet (260,000+ devices) attributed to Integrity Tech and linked to Flax Typhoon, per contemporaneous press coverage.
  • UK sanctioned Integrity Tech (2025; year-level precision, day not stated).
  • US Treasury (OFAC) sanctions Integrity Technology Group for its role in Flax Typhoon activity.
  • UK sanctioned Integrity Technology Group and i-Soon (2025-12-09), citing a 260,000+ device botnet.
  • EU sanctioned Integrity Tech (2026; year-level precision, day not stated in source).
  • FishHub observed active as of March 2026 (month precision).
  • MicroScan domain confirmed still online (September 2026), prior to the 2026-10-08 seizure.
  • Microsoft disables Exchange Web Services by default in Exchange Online (full retirement 2027-04-01; on-premises unaffected), relevant to the EWS-based mailbox theft.
  • US Magistrate Judge Maureen P. Kelly (W.D. Pa.) issues the seizure warrant for the Microscan/FishHub domains.
  • FBI executed court-authorized seizure warrants (W.D. Pa.) for seven domains supporting the MicroScan scanner, FishHub spear-phishing platform and SoftEther VPN infrastructure; DOJ announced the action alongside AA26-281A.
  • FBI, CISA, NSA and partners publish AA26-281A; five of the eight exploited CVEs are added to the CISA KEV catalog.
  • Federal remediation deadline for the five CVEs newly added to the CISA KEV catalog with AA26-281A.

Update history for TL-2026-3054

Sources cited for Chinese Government-linked Actors Enabled by Integrity

Detection coverage for TL-2026-3054

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3054 across Splunk SPL, Microsoft KQL and Sigma, covering 74 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
74 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats