Back to Feed
Nation-stateOct 8, 2026

Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

Chinese government-linked actors via Integrity Technology Group use automated tools and VPN persistence to steal data

Summary

A joint cybersecurity advisory from FBI, CISA, NSA, and international partners details Chinese government-linked cyber threat actors enabled by Integrity Technology Group, targeting US critical infrastructure and organizations globally. The actors combine automated scanning tools, botnets, XSS attacks, password spraying, and VPN software for persistence while exfiltrating email data and credentials. Extensive IOCs, malware samples, and mitigation strategies are provided.

Full text

Cybersecurity Advisory Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Release DateOctober 08, 2026 Alert CodeAA26-281A Related topics: Cybersecurity Best Practices , Nation-State Threats , Critical Infrastructure Security and Resilience Advisory at a Glance Title Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Original Publication October 8, 2026 Executive Summary Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide, including US critical infrastructure sectors. These actors exploit vulnerabilities by using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while establishing persistence through VPN software and exfiltrating emails and credentials using scripts. To help mitigate against this activity, organizations should prioritize disabling unused services and ports, sanitizing web application inputs to prevent injection attacks, implementing multifactor authentication for all services, and applying timely patches to reduce risks of compromise. Affected Products CVE-2014-6278 CVE-2015-3306 CVE-2015-5477 CVE-2016-3081 CVE-2019-11510 CVE-2021-22205 CVE-2021-3199 CVE-2023-22894 Key Actions Disable unused services and ports, such as automatic configuration, remote access, or file sharing protocols. Sanitize user input in web applications to prevent possible cross-site scripting (XSS) payload injection. Implement identity, credential, and access management (ICAM) policies, and then require multifactor authentication (MFA) for services (to the extent possible). Indicators of Compromise For a downloadable copy of indicators of compromise, see: AA26-281A STIX XML AA26-281A STIX JSON Intended Audience Organizations: Government; Federal Civilian Executive Branch (FCEB); State, Local, Tribal, and Territorial (SLTT); Critical Infrastructure. Sectors: Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology. Roles: Defensive Cybersecurity Analysts, Vulnerability Analysts, Security Systems Managers, Incident Response Analysts Introduction Integrity Technology Group, a China-based company with links to the Chinese government, enables China-linked threat actors to exploit US and foreign organization networks across multiple sectors using various tools and techniques. This advisory provides an analysis of tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) from Integrity Technology Group and the threat actors they enable (hereafter referred to as “the threat actors”). The analysis in this advisory provides network defenders with detection and mitigation guidance to reduce the risk of threat actors compromising critical data. The threat actors use a unique combination of large-scale botnets, virtual private network (VPN) infrastructure, living-off-the-land (LOTL) techniques, and repositories of computer network exploitation (CNE) tools. Although these techniques are not unique to Chinese threat actors, this advisory details how the threat actors use them to support CNE activity. The threat actors targeted victims across multiple US critical infrastructure sectors, including: Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology. The actors also targeted victims in US law enforcement, education, and religious organizations, as well as organizations across Southeast Asia, Africa, and North America. The information in this advisory originates from technical evidence recovered from, and observed during, multiple Federal Bureau of Investigation (FBI) investigations related to Integrity Technology Group. The FBI, Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), United Kingdom National Cyber Security Centre (NCSC-UK), Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), the Canadian Centre for Cyber Security (Cyber Centre), Japan’s National Police Agency (NPA) and National Cybersecurity Office (NCO), New Zealand’s National Cyber Security Centre (NCSC-NZ), and Spain’s Centro Nacional de Inteligencia (CNI), hereafter referred to as “the authoring organizations”—are releasing this joint cybersecurity advisory to urge network defenders from government and relevant organizations to: Hunt for potential compromises from this activity. Better protect against this threat activity and other Chinese government-linked cyber targeting. This advisory also provides our US federal, state, local, territorial, and tribal (FSLTT) government agencies, and international and industry partners, with the indicators and details necessary to proactively defend their networks against this threat and protect critical data. For more information on People’s Republic of China (PRC) state-sponsored malicious cyber activity in general, see the FBI’s Cyber Threat Overview: China webpage. For more information on China-linked malicious cyber activity, see CISA’s People’s Republic of China Threat Overview and Advisories webpage. The authoring organizations encourage network defenders to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of these incidents. Download the PDF version of this report: Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data (PDF, 1.41 MB ) For a downloadable copy of IOCs, see: AA26-281A STIX (JSON, 1,021.16 KB ) AA26-281A STIX XML (XML, 658.87 KB ) Threat Actor Background Integrity Technology Group (Integrity Tech) is a China-based for-profit company with links to the Chinese government. Integrity Tech employs individuals who support malicious cyber activity in different ways, including acquiring or building cyber tools for use and sale, acquiring and hosting infrastructure, and compromising networks across global victims, which the authoring organizations track as China-based malicious cyber activity. The services provided by Integrity Tech also contribute to the larger Chinese cyber ecosystem, which aims to exfiltrate sensitive data from victims around the world. Notably, the threat actors enabled by Integrity Tech use TTPs consistent with the cyber activity publicly known as Flax Typhoon, Ethereal Panda, and Red Juliett, among others. However, these threat actors may also perform activity not associated with Integrity Tech. Note: Cybersecurity companies have different methods of tracking and attributing cyber actors and these may not be a 1:1 correlation to the US Government's methodology and understanding for all activity related to these groupings. Technical Details Note: This advisory uses the MITRE ATT&CK® Matrix for Enterprise framework, version 19. See Appendix A: Indicators of Compromise and the MITRE ATT&CK Tactics and Techniques section of this advisory for a table of the threat actors’ activity mapped to MITRE ATT&CK tactics and techniques. Reconnaissance The threat actors use a variety of open source scanning tools to find vulnerabilities in networks and web-based applications, including: BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe, and wpscan [T1595.002]. See Appendix A: Indicators of Compromise for a complete list of scanning tools. Some of these tools contain features useful for fingerprinting remote applications, testing remote authentication protocols, or enumerating the pages of a website. The use of open source tools typically found on GitHub suggests the threat actors tend to look for more vulnerable targets. In general, the threat actors focus on scanning ports 21 (file transfer protocol [FTP]), 22 (SSH), 53 (domain name system

Indicators of Compromise

  • domain — dns.studiocloud.xyz
  • domain — natcloudservice.com
  • domain — studiocloud.xyz
  • ip — 149.28.132.137
  • url — https://upl.natcloudservice.com/ews
  • hash_md5 — 6d57c42dee8bd7789969e2dd28671162
  • hash_sha256 — 804a53be802378a8ec4c94602fd3d6584e0d472d83148e8a42c731950fec415d
  • hash_md5 — 1bcaef76b2063f1b80b0fa0d277ec9c5
  • cve — CVE-2019-11510
  • cve — CVE-2021-22205
  • cve — CVE-2023-22894
  • malware — MicroScan
  • malware — EBurst

Entities

Integrity Technology Group (threat_actor)Flax Typhoon (threat_actor)Ethereal Panda (threat_actor)Red Juliett (threat_actor)SoftEther VPN (technology)Microsoft Exchange (product)