The United States, United Kingdom and multiple allied nations have released a joint security alert detailing the methods used by a sanctioned Chinese organization that has provided support to state-backed hacking groups. The advisory, published October 8, focuses on Integrity Technology Group, which has previously assisted high-profile Beijing-linked groups including Flax Typhoon, also tracked as Ethereal Panda and Red Juliett. The company employs staff who support malicious cyber operations through developing cyber tools for use and sale, acquiring and hosting infrastructure, and breaching networks of global victims, according to the alert.
The advisory outlined numerous technical tactics linked to Integrity Tech's operations. The firm uses open source scanning tools to identify vulnerabilities in networks and web applications, and deploys the MicroScan hacking tool, which contains more than 1,300 penetration testing scripts designed to scan websites for specific weaknesses. The group gains initial access to networks and cloud platforms through command line utilities built on exploit code written in Python and Go, and exploits cross-site scripting flaws to compromise third-party applications. For persistence, the organization installs VPN clients such as SoftEther on victim devices to hide command and control communications, and uses the EBurst tool for password spraying and guessing attacks to breach Microsoft 365 email accounts. The group stages data for theft by renaming files to avoid detection of MySQL email dumps, creates bots using the PHP script Curlc4.txt to harvest emails from victims, and employs DC.exe to deceive domain controllers into releasing sensitive Active Directory data including account credentials. Targeted sectors include government, law enforcement, healthcare and religious organizations located in Southeast Asia, with attackers stealing email data from both on-premises systems and cloud-based platforms using the command-line utility office-cli to continuously access Microsoft Outlook 365 accounts.
The report includes a substantial list of indicators of compromise, additional resources and mitigations, along with guidance for incident responders who suspect they've already been breached. Paul Chichester, director of operations at the UK's National Cyber Security Centre, said the scope of Integrity Tech's activities should alarm all security teams, noting that "the breadth of sectors that have been targeted across the globe demonstrate the extent of the threat." The alert's core recommendations for reducing the threat include disabling unused services and ports such as automatic configuration, remote access and file sharing protocols, sanitizing user input in web applications to block possible cross-site scripting payload injection, and implementing identity, credential and access management policies while requiring multifactor authentication wherever feasible.
According to the advisory, the services Integrity Tech provides contribute to the broader Chinese cyber ecosystem, which seeks to steal sensitive data from victims worldwide. Also on October 8, US authorities announced the seizure of multiple domains tied to hacking tools Microscan and FishHub in an effort to disrupt Integrity Tech's operations and associated threat groups. The NCSC pledged to continue exposing malicious actors and the harmful ecosystem in which they operate. The joint warning underscores that organizations across all sectors need to engage with official cyber security advice and guidance to defend against these evolving threats. For security leaders, the disclosure represents a test of whether attribution alone can shift defensive priorities, or whether disruption efforts must demonstrably raise costs for both the vendors and buyers of commercial intrusion services before investment patterns change.

