THE UK’s National Cyber Security Centre (NCSC) and partners from Australia, Canada, Japan, New Zealand, Spain and the United States have issued an advisory about cyber activity enabled by China-based Integrity Technology Group. The agencies say the company, which has links to the Chinese Government, supports actors who compromise networks and steal confidential data from organisations worldwide, including those in critical sectors. The activity is consistent with campaigns also known as Flax Typhoon, Ethereal Panda and Red Juliett.
The advisory describes attackers combining AI-enabled tools, including automated scanning, with large botnets and hands-on exploitation. It says Integrity Tech’s employees have supported malicious activity by developing and selling tools, obtaining and hosting infrastructure, and compromising networks. The NCSC had previously identified Integrity Tech as the operator of a substantial botnet used by Flax Typhoon; the UK sanctioned the company last year. The latest announcement describes activity reported in the advisory, but does not give figures for victims or confirm specific incidents of data theft.
The NCSC is urging organisations to understand the techniques and follow the advisory’s mitigation guidance to strengthen their defences. The joint advisory is available through the FBI website.