A coalition of cybersecurity and law enforcement agencies, led by the FBI, has revealed details of a long-running cyber espionage campaign linked to Integrity Technology Group, a Chinese cybersecurity firm accused of conducting and supporting unauthorized network intrusions on behalf of Chinese state interests.
According to a joint advisory issued on October 8, the threat actors targeted a broad range of organizations, including government bodies, law enforcement agencies, healthcare providers, and religious institutions across Southeast Asia. Investigators say the same operation also focused on victims in the United States, Africa, and North America, affecting sectors such as critical manufacturing, education, information technology, healthcare, and public services.
Long-Term Intrusions and Email Theft
Authorities believe the campaign has been active since at least January 2021. While the advisory does not disclose the exact number of victims or dates of individual breaches, it details a sustained effort to infiltrate networks, harvest credentials, and exfiltrate large volumes of email communications.
The attackers reportedly used a combination of vulnerability scanning, password-spraying attacks, and email collection utilities to compromise systems. Their toolkit included software capable of copying mailboxes from Microsoft 365 and Exchange environments, allowing them to steal sensitive correspondence from targeted organizations.
One of the more concerning discoveries was an online portal allegedly operated by the threat actors that provided third parties with access to stolen email data. Investigators did not identify who those third parties were or how the information was subsequently used.
Integrity Technology Group Under Scrutiny
The advisory characterizes Integrity Technology Group as a China-based commercial cybersecurity company with connections to the Chinese government. Investigators allege that the company develops and acquires offensive cyber capabilities, maintains attack infrastructure, and facilitates network intrusions for intelligence-gathering purposes.
The U.S. Treasury sanctioned the company in January 2025 for its involvement in cyberattacks against American organizations, while the United Kingdom imposed sanctions later that year. U.S. officials have previously cited public statements from the company's leadership acknowledging work conducted for Chinese security agencies.
Researchers noted that the tactics and infrastructure used by the group align with threat activity tracked by several cybersecurity vendors under names including Flax Typhoon, Ethereal Panda, and RedJuliett.
Reconnaissance and Initial Access Techniques
The operation relied heavily on reconnaissance and vulnerability assessment tools. Investigators observed the attackers using publicly available scanners such as Nmap, Masscan, and WPScan to identify exposed internet-facing systems and weak services.

The group also leveraged a custom Python-based platform called MicroScan, which contains more than 1,300 penetration-testing scripts. These scripts were used to probe for security weaknesses in a variety of enterprise technologies, including:
- OpenSSL
- Oracle WebLogic Server
- WordPress
- Jenkins
- Apache Struts
- Juniper ScreenOS
- Rejetto HFS
The advisory identifies eight vulnerabilities that the attackers successfully exploited during operations, several of which are expected to be added to CISA's Known Exploited Vulnerabilities catalog.
In addition to exploiting software flaws, the attackers deployed credential-based attacks. Using an open-source tool called EBurst, they conducted password-spraying campaigns against Microsoft 365 and Exchange environments, attempting commonly used passwords across numerous accounts while avoiding account lockouts.
Credential Harvesting Through Fake Login Pages
Investigators also recovered malicious code designed to inject fake login prompts into vulnerable websites through cross-site scripting (XSS) attacks.
Victims who entered credentials into these counterfeit pages were presented with a password-protected ZIP file containing a malicious executable named live700_v1.exe. Once executed, the malware launched a process masquerading as the legitimate Windows component DiagTrack.exe and established encrypted communications with infrastructure linked to Integrity Technology Group.
The FBI believes this malware was primarily designed to support email-focused espionage activities.
Maintaining Access and Expanding Control
To maintain long-term persistence inside compromised environments, the attackers frequently installed SoftEther VPN, a legitimate remote-access utility commonly used by administrators.
To avoid suspicion, the software was often renamed to appear as trusted Windows files such as:
- conhost.exe
- dllhost.exe
The malicious VPN configuration ensured automatic reconnection whenever a compromised system rebooted.
Investigators also observed the use of a tool called DC.exe, which leveraged the DCSync technique to extract Active Directory information directly from domain controllers. This method enabled theft of:
- User credentials
- Group membership information
- Trust relationship data
Large-Scale Email Collection Operations
Email theft appeared to be one of the campaign's primary objectives.
One custom tool, developed from a PHP script called Curlc4.txt, accessed Exchange Web Services (EWS) to collect emails, calendars, and contact data. The tool compressed and occasionally encrypted harvested information before uploading it to remote command-and-control servers, including domains linked to attacker-controlled infrastructure.
A second utility, known as office-cli, enabled repeated collection of emails from Microsoft 365 tenants over various time periods. By using legitimate authentication mechanisms and configuration files containing client IDs, tenant IDs, and secrets, the tool blended into normal cloud activity and reduced the likelihood of detection.
Investigators additionally observed threat actors manually downloading database contents and directly reviewing victim email accounts.
In some instances, access to stolen information was reportedly restricted to IP addresses located in Xiamen, China.
FBI's Discovery of a Related Botnet
The newly released advisory follows a separate FBI operation conducted in September 2024, during which authorities dismantled the Raptor Train botnet.
According to the U.S. Department of Justice, the botnet was controlled by Integrity Technology Group and consisted of more than 200,000 compromised internet-connected devices, including routers, cameras, and other consumer hardware.
While the 2024 action focused on disrupting the botnet infrastructure itself, the latest advisory provides a deeper look into the intrusion techniques, credential theft methods, and intelligence collection activities employed by the operators.
Defensive Recommendations
The agencies urge organizations to proactively search for evidence of compromise and strengthen defenses against similar activity.
Recommended measures include:
- Disabling unnecessary services and exposed ports.
- Enforcing multi-factor authentication across email, VPN, and privileged accounts.
- Implementing strong input validation to prevent XSS attacks.
- Monitoring Active Directory replication activity for signs of DCSync abuse.
- Reviewing cloud application permissions and OAuth grants.
- Inspecting web application logs for exploitation attempts.
- Applying security updates promptly, particularly for known exploited vulnerabilities.
- Replacing unsupported software that no longer receives security fixes.
For organizations that suspect compromise, authorities recommend isolating affected systems, conducting a thorough forensic investigation to determine the scope of intrusion, removing attacker access only after sufficient threat-hunting has been completed, and implementing additional hardening measures before restoring normal operations.
Extensive Indicators of Compromise
The advisory concludes with 39 pages of indicators of compromise (IOCs), including domains, IP addresses, malware hashes, and infrastructure associated with the campaign. Some indicators date back as far as 2016, demonstrating the longevity and breadth of the operation.
Investigators caution defenders to carefully review the listed indicators before blocking them, noting that historical timestamps within the IOC dataset are not always the most recent observations and should be interpreted within the broader context of threat hunting and incident response activities.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
