Breaking
Cyber CrimeConfirmed

FBI Ties Chinese Firm to Email Theft Portal

A joint advisory says hackers linked to Integrity Technology Group stole email and ran a web app giving third parties access to it.

··3 hours ago·8 min read
black laptop computer with white paper
Photo by FlyD on Unsplash

Government inboxes are the quietest place a breach can land, and a joint advisory from the FBI and agencies in six other countries describes a campaign built specifically around getting into them. The targets named in the advisory span government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, with the same hackers also hitting U.S. government services, critical manufacturing, healthcare, and IT organizations, along with U.S. law enforcement, education, and religious groups. Organizations in Southeast Asia, Africa, and North America were also targeted.

The advisory says the hacking has been going on since at least mid-January 2021. It describes the activity in the present tense but provides no date for any theft and does not specify how many organizations were breached.

A company and its hackers

The agencies describe Integrity Technology Group as "a China-based for-profit company with links to the Chinese government" whose employees build or get cyber tools "for use and sale," host infrastructure, and break into networks. The same document leans on a single label — "the threat actors" — for the company and the hackers it enables, and it does not say which of them carried out each break-in.

The company has been sanctioned by the U.S. and the UK. The U.S. Treasury sanctioned the company in January 2025 for its role in several computer break-ins against U.S. victims, and the UK sanctioned it in December 2025.

The advisory says the hackers' methods are "consistent with" activity that security companies track as Flax Typhoon, Ethereal Panda, and RedJuliett, among others. Those names may not match the U.S. government's own tracking one-to-one, and the same hackers may also carry out work unrelated to Integrity Technology Group. Flax Typhoon is Microsoft's name for a China-based group that it described in 2023 as targeting organizations in Taiwan.

Integrity Technology Group rejected the U.S. accusations in January 2025. It told the Shanghai Stock Exchange that the U.S. move had no factual basis, the Associated Press reported. A Chinese Foreign Ministry spokesperson, asked about the sanctions, said China firmly opposed the U.S. action, according to the same report.

Scanning for the way in

The hackers look for flaws in networks and web applications with open-source scanners such as Nmap, masscan, and WPScan, the advisory said. Their scans focus on ports 21, 22, 53, 80, 443, and 1080.

"The use of open source tools typically found on GitHub suggests the threat actors tend to look for more vulnerable targets," the agencies said.

— the agencies behind the joint advisory

They have also used a scanner called MicroScan since as early as 2017. It is a Python web application containing more than 1,300 penetration testing scripts designed to scan websites for specific flaws. Those scripts have been run against services including OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts.

The UK's National Cyber Security Centre, one of the agencies behind the advisory, said in its news release that the hackers are "uniquely using AI tools, such as automated scanning." The advisory itself does not mention AI.

Eight flaws carried into the field

The hackers mostly get in with command-line tools built on exploit code written in languages such as Python and Go. The advisory lists 8 known flaws that it says were successfully exploited. Those flaws were found in the hackers' penetration testing scripts.

  • CVE-2014-6278 affects GNU Bash, through 4.3 bash43-026; no fix was confirmed.
  • CVE-2015-3306 affects ProFTPD 1.3.5; fixed in 1.3.5a.
  • CVE-2015-5477 affects ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3; fixed in 9.9.7-P2 or 9.10.2-P3.
  • CVE-2016-3081 affects Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28; fixed in 2.3.20.3, 2.3.24.3, or 2.3.28.1.
  • CVE-2019-11510 affects Pulse Connect Secure 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4; fixed in 8.2R12.1, 8.3R7.1, or 9.0R3.4, per the advisory's ranges.
  • CVE-2021-22205 affects all GitLab versions starting from 11.9; fixed in 13.8.8, 13.9.6, or 13.10.3, per its NVD record.
  • CVE-2021-3199 affects ONLYOFFICE Document Server 5.1.5 through 5.6.2; fixed in 5.6.3.
  • CVE-2023-22894 affects Strapi up to 4.5.5; fixed in 4.8.0.

The advisory marks 5 of the 8 with an asterisk and describes them as newly added to the Known Exploited Vulnerabilities (KEV) catalog, the list of flaws that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) says have been used in attacks. They were not in the catalog data that CISA publishes on GitHub (version 2026.10.04) when The Hacker News checked at 18:05 UTC on October 8.

Strapi's own advisory gives a wider range than the joint advisory. It says versions from 3.2.1 through 4.7.9, but not including 4.8.0, are affected.

Two flaws depend on a setting. The Apache Struts flaw works only when Dynamic Method Invocation is turned on, and Apache says turning it off is an alternative to upgrading. The ONLYOFFICE flaw applies when JWT is used, according to its NVD record. The BIND flaw is a denial-of-service bug that makes the DNS server exit.

A fake login and a lookalike process

Another way in is a fake login. The FBI recovered a cross-site scripting (XSS) payload that changes a vulnerable web page to show username and password fields.

After a visitor enters any username and password, the page offers a password-protected ZIP file that holds a program named live700_v1.exe. That program starts a process named DiagTrack.exe, the same name as a legitimate Windows program, which sends encrypted traffic to dns.studiocloud[.]xyz.

The FBI attributes that domain to Integrity Technology Group and assesses that the malware likely targets email.

The hackers also use password spraying, which means trying a few common passwords against many accounts. For that they use EBurst, an open-source Python tool that targets Microsoft 365 and Exchange accounts. EBurst tries logins through Exchange interfaces that include ECP, EWS, OAB, OWA, RPC, API, MAPI, PowerShell, Autodiscover, and Microsoft-Server-ActiveSync, according to its README file. Defenders should cover these interfaces, the agencies said.

Holding the door open

To keep access, the hackers install SoftEther, a legitimate VPN program that security software is less likely to flag, the advisory said. They often rename the installer conhost.exe or dllhost.exe so it looks like a Windows file, and they set the client to reconnect each time the machine starts.

To take credentials, they ran a tool named DC.exe that uses DCSync, a technique that copies data from a domain controller through Active Directory's replication service. It copied account credentials, group membership details, and trust relationships.

For email, the hackers built a bot from a PHP script named Curlc4.txt. It collects mail through Exchange Web Services (EWS), an interface that also gives access to calendars and contacts. The bot compresses the mail, sometimes encrypts it, and uploads it to a remote server. The script appears to be stand-alone rather than installed on a hacked device, and its main command-and-control domain was natcloudservice[.]com.

A second tool, office-cli, keeps going back to Microsoft 365 accounts to take mail from different time periods. It works from configuration files that hold a client ID, tenant ID, and secret, and it avoids detection by using legitimate access methods, the agencies said. The FBI also saw the hackers download databases or pull data from victims' email by hand.

In some cases, the hackers limited access to the stolen data to IP addresses in Xiamen, China. Users of the web application for third parties can view the mail of a specific account by adding arguments to a URL.

What defenders are told to check

The agencies urge defenders to hunt for signs of this activity in their own networks. Their recommended steps include turning off unused services and ports such as remote access and file sharing; sanitizing user input in web applications to block XSS; requiring multifactor authentication, especially for webmail, VPNs, and accounts that reach critical systems; watching for unexpected Active Directory replication, a sign of DCSync; checking cloud accounts for connected applications that can read files and email; reviewing web application logs for attack attempts; applying patches, including for the 8 flaws listed above; and replacing products that no longer get updates.

For a suspected compromise, the advisory's steps are to isolate the affected hosts, hunt to learn how far the break-in went, and report it under national rules. The hackers should be removed after enough hunting data has been collected, and the network then hardened.

Indicators that need a second look

The advisory has 39 pages of indicators of compromise (IOCs), the domains, IP addresses, and file hashes linked to the hackers. The agencies say several date back to as early as 2016 and recommend checking them before blocking.

Some are not new. The Hacker News found that 10 IP addresses in the list also appeared in the September 2024 advisory on the botnet, where they were tied to its command-and-control servers. That botnet held more than 200,000 routers, cameras, and other consumer devices, and Lumen researchers had named it Raptor Train.

The dates do not match. The new list shows those 10 addresses as last seen on June 5, 2024. The 2024 advisory showed them as last seen between August 28 and September 4, 2024. So a "last seen" date in the new list is not always the latest one on record. Apart from dates that show when a domain's registration expires, the most recent "last seen" dates in the tables are from 2025.

Why the portal changes the response

The advisory's account of a web application that "provides third-party access to stolen email content" is the part that sits differently from the rest of the document. The agencies do not identify those third parties, and the document does not say how the access was granted or who used it. What it does establish is that the FBI recovered evidence and observed this activity during several investigations related to the company, and that the resulting guidance covers both how the hackers get into networks and what they take.

For an organization in the affected sectors, the practical consequence is that the scope of an incident may extend past the mailbox that was read. If stolen mail was reachable through a separate application, an internal review focused only on the breached network could leave unanswered who else had a way to look at the correspondence. The advisory's own instructions reflect that uncertainty: defenders are told to check cloud accounts for connected applications that can read files and email, and to review web application logs for attack attempts, alongside more familiar hardening steps.

The mixed dates in the IOC tables add a second, smaller problem. The agencies recommend checking indicators before blocking them, and the overlap with the 2024 botnet list means some entries describe infrastructure that was already known. Treating the newest list as entirely fresh could send defenders after addresses whose "last seen" dates are older than those in the earlier advisory, while the tools and techniques described elsewhere in the document remain the part that defenders can act on regardless of which addresses are still live.

#china#email theft#fbi advisory#cyber espionage#integrity technology group#sanctions

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories