# Chinese Government-linked Actors Enabled by Integrity Technology Group Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data (CISA AA26-281A)

> A joint FBI/CISA/NSA and international advisory attributes a long-running intrusion set to China-linked actors enabled by Integrity Technology Group (Integrity Tech), whose TTPs align with Flax Typhoon, Ethereal Panda and Red Juliett. The actors pair automated scanning, botnet-hosted infrastructure and hands-on exploitation of eight older CVEs to steal email and other sensitive data from US critical infrastructure and organizations in Southeast Asia, Africa and North America.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-09T12:57:20.700Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3054
- **ID:** TL-2026-3054
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** Integrity Technology Group-enabled actors (China)
- **Detections:** 9 · **IOCs:** 74 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894

## Description

CISA Advisory AA26-281A (released 2026-10-08) was authored by the FBI, CISA, NSA, UK NCSC, Australia's ACSC, the Canadian Cyber Centre, Japan's NPA and NCO, New Zealand's NCSC-NZ and Spain's CNI, based on multiple FBI investigations related to Integrity Technology Group, a China-based for-profit company with links to the Chinese government that builds or acquires cyber tools, hosts infrastructure and compromises networks. The advisory states the observed TTPs are consistent with vendor-tracked clusters Flax Typhoon, Ethereal Panda and Red Juliett, but cautions vendor names may not map 1:1 to US government attribution and that these actors may conduct activity unrelated to Integrity Tech.

Reconnaissance and initial access are heavily automated. Actors scan for vulnerable internet-facing services (focus ports 21, 22, 53, 80, 443, 1080) with open-source tools including BBScan, dirsearch, Fscan, ksubdomain, masscan, Nmap, OneForAll, ShuiZe and wpscan, and use MicroScan, a Python web application bundling more than 1,300 penetration-testing scripts that has been in use since 2017. Successfully exploited vulnerabilities are CVE-2014-6278 (GNU Bash), CVE-2015-3306 (ProFTPD 1.3.5), CVE-2015-5477 (ISC BIND 9), CVE-2016-3081 (Apache Struts), CVE-2019-11510 (Pulse Connect Secure), CVE-2021-22205 (GitLab), CVE-2021-3199 (ONLYOFFICE DocumentServer) and CVE-2023-22894 (Strapi); five of these were newly added to CISA KEV with this advisory. A second vector injects XSS payloads into vulnerable third-party websites that rewrite the page into a fake login form and then offer a password-protected ZIP containing live700_v1.exe, which launches DiagTrack.exe, a masquerading email-querying implant that talks over encrypted HTTP to dns.studiocloud.xyz.

Post-compromise the actors use Impacket secretsdump, a DCSync tool (dc.exe) and JuicyPotato for credential theft and privilege escalation, deploy webshells (b374.php, back.pl, error.jsp, file_back.aspx, gf.phtml, yaml-payload.jar), and persist and obscure C2 with SoftEther VPN clients renamed to conhost.exe and dllhost.exe, configured to reconnect on startup and often unflagged by endpoint tools because SoftEther is legitimate software. Email theft is the core objective: curlc4.txt, a standalone PHP bot, uses the Exchange Web Services API to pull mail, calendars and contacts, stages them in a writable directory (e.g. /var/tmp/.sess.zip), compresses and sometimes encrypts them with RC4 or AES-128-CBC, and uploads to natcloudservice.com infrastructure; office-cli, a Linux binary, repeatedly accesses Microsoft 365 mailboxes using client_id/tenant_id/secret values from JSON config, and eburst.py sprays passwords against Exchange/O365 endpoints. The actors rotate to fresh accounts and run a custom web application that serves stolen email to third parties. Victims include US Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, Information Technology, law enforcement, education and religious organizations, plus government, law enforcement, healthcare and religious institutions in Southeast Asia, and targets in Africa and North America. Observed indicators span 2016-2026 and the advisory warns that older IOCs must be vetted before blocking. Related prior public reporting (September 2024) tied the Raptor Train botnet, a Mirai variant botnet of 260,000+ devices, to Integrity Tech and Flax Typhoon; the FBI disrupted it.

## MITRE ATT&CK

- T1595.002 Active Scanning: Vulnerability Scanning
- T1190 Exploit Public-Facing Application
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1059.006 Command and Scripting Interpreter: Python
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1133 External Remote Services
- T1505.003 Server Software Component: Web Shell
- T1036.003 Masquerading: Rename Legitimate Utilities
- T1003.006 OS Credential Dumping: DCSync
- T1110.001 Brute Force: Password Guessing
- T1110.003 Brute Force: Password Spraying
- T1114.002 Email Collection: Remote Email Collection
- T1560.003 Archive Collected Data: Archive via Custom Method
- T1074.001 Data Staged: Local Data Staging
- T1071.001 Application Layer Protocol: Web Protocols
- T1020 Automated Exfiltration
- T1583.001 Acquire Infrastructure: Domains
- T1566 Phishing
- T1189 Drive-by Compromise
- T1068 Exploitation for Privilege Escalation
- T1584.005 Compromise Infrastructure: Botnet
- T1566.002 Phishing: Spearphishing Link
- T1572 Protocol Tunneling

## Sources

- [CISA AA26-281A: Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [NVD - CVE-2019-11510 (Pulse Connect Secure)](https://nvd.nist.gov/vuln/detail/CVE-2019-11510)
- [NVD - CVE-2021-22205 (GitLab)](https://nvd.nist.gov/vuln/detail/CVE-2021-22205)
- [NVD - CVE-2016-3081 (Apache Struts)](https://nvd.nist.gov/vuln/detail/CVE-2016-3081)
- [NVD - CVE-2023-22894 (Strapi)](https://nvd.nist.gov/vuln/detail/CVE-2023-22894)
- [NVD - CVE-2021-3199 (ONLYOFFICE DocumentServer)](https://nvd.nist.gov/vuln/detail/CVE-2021-3199)
- [FBI forced Flax Typhoon to abandon its botnet (Help Net Security)](https://www.helpnetsecurity.com/2024/09/19/flax-typhoon-botnet-disrupted/)
- [FBI operation against China botnet Flax Typhoon (CyberScoop)](https://cyberscoop.com/fbi-operation-china-botnet-flax-typhoon/)
- [FBI disrupts another Chinese state-sponsored botnet (TechTarget)](https://www.techtarget.com/cybersecurity/news/366611357/FBI-disrupts-another-Chinese-state-sponsored-botnet)
- [FBI Disrupts Another Massive Chinese-Linked Botnet (Security Boulevard)](https://securityboulevard.com/2024/09/fbi-disrupts-another-massive-chinese-linked-botnet/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3054
