Joint Alert Exposes Integrity Tech TTPs
US, UK and allies issue a joint advisory detailing the tools and techniques of sanctioned Chinese firm Integrity Technology Group.
Government cybersecurity agencies from the US, UK and several allied nations have published a coordinated alert that lays out how a sanctioned Chinese company equips and supports state-aligned intrusion campaigns. The advisory, released on October 8, names Integrity Technology Group and describes the tools, infrastructure and access it provides to actors operating across the Chinese cyber ecosystem.
According to the alert, the group does not fit neatly into the mold of a traditional advanced persistent threat. Instead, it operates as a supplier, building and selling offensive tooling, hosting infrastructure, and compromising networks on behalf of others.
A Supplier Inside the Ecosystem
The advisory states that Integrity Tech's work has in the past enabled prolific Beijing-backed groups, including Flax Typhoon, also known as Ethereal Panda or Red Juliett.
Rather than running a single campaign, the company supports malicious activity through several lines of business. Those include acquiring or building cyber tools for use and sale, acquiring and hosting infrastructure, and compromising networks belonging to victims around the world.
“Integrity Tech employs individuals who support malicious cyber activity in different ways, including acquiring or building cyber tools for use and sale, acquiring and hosting infrastructure and compromising networks across global victims, which the authoring organizations track as China-based malicious cyber activity,” the advisory said.
The document adds that these services feed into a broader Chinese cyber ecosystem aimed at exfiltrating sensitive data from victims internationally. The advisory attributes that quoted language to the authoring organizations collectively.
Scanning Tools and MicroScan Scripts
On the technical side, the report describes a reconnaissance workflow that leans heavily on open source scanning tools to identify vulnerabilities in networks and web-based applications. It also flags a hacking tool called MicroScan, which carries more than 1,300 pen-testing scripts built to probe sites for specific flaws.
That volume of scripts gives operators a broad menu of known weaknesses to test against a target before committing to an intrusion path. The advisory positions scanning as the front end of a longer chain that moves from discovery into exploitation and, eventually, data theft.
Breaking In Through Python and Go
Initial access to networks and cloud services, according to the alert, comes through command line utilities built on exploit code written in Python and Go. The advisory also cites the exploitation of cross-site scripting bugs to compromise third-party applications.
For credential attacks, the group uses a tool called EBurst to carry out password spraying and guessing against Microsoft 365 email accounts. The combination of custom exploit utilities and off-the-shelf credential attacks reflects a playbook designed to work across both on-premises and cloud environments.
Holding Ground and Hiding Traffic
Once inside, the operators work to stay there. The advisory describes persistence achieved by installing VPN clients, such as SoftEther, on victim devices to obscure command and control communications.
Stolen data is staged under varying file names to reduce the chance that a MySQL email dump is spotted. The report also describes a bot built from a PHP script, Curlc4.txt, used to obtain emails from victims, and a utility called DC.exe that tricks a domain controller into handing over sensitive Active Directory information, including account credentials.
Email data is exfiltrated from both on-premises systems and cloud-based services. A command-line utility named office-cli is used to continuously access Microsoft Outlook 365 accounts and steal messages.
Who Is Being Targeted
The advisory identifies specific sectors in its description of victim targeting. According to the alert, targeted verticals include government, law enforcement, healthcare and religious institutions located in Southeast Asia.
That mix spans public services, sensitive records and organizations that may have limited defensive resources. The report presents these as the categories observed in connection with Integrity Tech's activity, rather than as an exhaustive list of every victim.
Advice for Network Defenders
The report includes a large number of indicators of compromise, additional resources, mitigations, and guidance for incident responders who suspect they may already have been compromised. Its core mitigation advice can be distilled into a handful of steps.
- Disable unused services and ports, including automatic configuration, remote access and file sharing protocols
- Sanitize user input in web applications to prevent possible XSS payload injection
- Implement identity, credential and access management (ICAM) policies, and require multifactor authentication where possible
These measures map directly onto the techniques described elsewhere in the advisory, from XSS exploitation to credential guessing against cloud email.
A Warning for Security Teams
Paul Chichester, director of operations at the UK's National Cyber Security Centre, said the scope of the group's activity should put security teams on notice.
“The breadth of sectors that have been targeted across the globe demonstrate the extent of the threat and all organizations should take note of this warning and engage with NCSC advice and guidance,” he said.
He added: “We will continue to call out malicious actors and the malevolent ecosystem they operate in.”
— Paul Chichester, director of operations, NCSC
Domain Seizures on the Same Day
Also on October 8, the US announced the seizure of several domains tied to the hacking tools Microscan and FishHub. The action was described as an effort to disrupt the operations of Integrity Tech and associated threat groups.
The timing places the enforcement action alongside the publication of the joint advisory, pairing technical disclosure with a move against infrastructure linked to the tools the report describes.
What the Alert Means for Defenders
For security teams, the practical value of the advisory lies less in any single tool than in the chain it documents. Reconnaissance through open source scanners, initial access via Python and Go-based utilities, credential attacks against Microsoft 365, persistence through VPN clients and Active Directory theft are not isolated tricks. They describe a repeatable path that defenders can map to their own environments.
The three core mitigations in the alert — closing unused services and ports, sanitizing web application input, and enforcing ICAM with MFA where possible — are not new ideas. What the advisory provides is a direct line between those controls and the specific behaviors observed in this ecosystem, which can help teams prioritize.
The sectors named in the report are a reminder that targeting is not limited to large enterprises or defense contractors. Government agencies, law enforcement, healthcare providers and religious institutions in Southeast Asia appear in the advisory's account of victim targeting. Organizations in those categories, and those that share infrastructure or supply chains with them, may want to review whether their exposure aligns with the techniques described.
The seizure of domains associated with Microscan and FishHub shows that disruption efforts are underway alongside the advisory. Whether that changes the operating picture for Integrity Tech or the groups it supports is not something the published material establishes. What the advisory does make clear is that the tooling and services it describes remain available to the broader ecosystem it names.
Sources
- Infosecurity Magazine Original source
- Flax Typhoon Also reporting
Continue Reading
FBI Arrests Another ShinyHunters Suspect
The FBI has arrested a second suspected ShinyHunters member in days, as the agency escalates pressure on the gang behind its breach.
GhostAction Returns, Hits 340+ Maintainer Repos
A credential-theft campaign has compromised two open-source maintainer accounts to push malicious GitHub Actions workflows into more than 340 repositories.
DarkSword Kit Grows a Wallet-Stealing Arm
A new P7 DarkSword variant trims its on-device footprint while adding keychain theft, crypto-wallet extraction, and two-way command control.