securityonline.info 9 Oct 2026, 03:31 UTC

Chinese Hackers Target Critical Infrastructure to Steal Data and Spy

Chinese Hackers Target Critical Infrastructure to Steal Data and Spy

THREAT actors described as Chinese state hackers are alleged to be targeting critical infrastructure worldwide to steal data for long‑term intelligence collection. The piece pools together claims that these actors use automated tooling to identify weaknesses, harvest credentials through cross‑site scripting, and mass‑scan Microsoft Exchange servers via password guessing, with a focus on unpatched, older software versions.

It also notes that actors establish persistent access through SoftEther VPN and disguise installer activity to evade endpoint detection, including hosting connections on compromised subdomains.

Data extraction is described as sweeping, with custom PHP scripts connecting to Microsoft interfaces to copy mailboxes and automatically uploading stolen emails to remote servers, often compressing and encrypting the data before transfer. The article attributes the operations to a group linked to Integrity Technology Group, asserting law enforcement confidence and noting FBI involvement in recovering payloads.

It further claims victims span government services, healthcare providers, and manufacturing facilities, with particular attention paid to Active Directory environments and the use of DCSync to copy trust relationships. A joint advisory is cited as acknowledging global targeting, including US critical infrastructure sectors, religious institutions and educational establishments.

Defence guidance offered in the piece emphasises immediate improvements to identity management, mandatory multi‑factor authentication for essential services, replacing default passwords, auditing administrative privileges, and sanitising web input to block injections. It also urges monitoring for abnormal traffic, suspicious Active Directory replication, and automatic patching from trusted sources as core defence measures. The article stops short of disclosing verifiable, independently validated specifics beyond the cited attribution and general indicators.

View full article

Article by CyberSIXT