THE FBI and six other countries’ agencies allege that a China-based for‑profit company, Integrity Technology Group, and the hackers it employs stole emails from government bodies, law enforcement, healthcare systems and religious organisations across Southeast Asia and beyond. The operation involved scanning public-facing websites with a toolset of more than 1,300 scripts, guessing passwords for Microsoft 365 and Exchange accounts, and copying mailboxes using specialised tools.
The joint advisory notes the intrusions began at least by mid‑January 2021 and, in addition to Southeast Asia, also targeted organisations in Africa and North America, including U.S. government services, critical manufacturing, healthcare, IT, law enforcement, education and religious groups. The hackers ran a web application that provides third parties with access to stolen email content, though the advisory does not identify those third parties.
The FBI recovered evidence linking Integrity Technology Group to these activities, including connections back to a botnet disruption in September 2024 known as Raptor Train, which involved hundreds of thousands of IoT devices.
Defence researchers say the intruders used open‑source scanners (Nmap, masscan, WPScan) to locate flaws on ports 21, 22, 53, 80, 443 and 1080, and employed a Python toolset with over 1,300 penetration scripts to exploit eight known vulnerabilities.
The advisory lists CVEs including CVE-2014-6278 (GNU Bash), CVE-2015-3306 (ProFTPD), CVE-2015-5477 (ISC BIND), CVE-2016-3081 (Apache Struts), CVE-2019-11510 (Pulse Connect Secure), CVE-2021-22205 (GitLab), CVE-2021-3199 (ONLYOFFICE Document Server), and CVE-2023-22894 (Strapi); several are marked as newly added to KEV.
The attackers used techniques such as DCSync to copy credentials from domain controllers, and a PHP bot (Curlc4[.]txt) to exfiltrate email via Exchange Web Services, with a separate tool (office-cli) continuing to harvest mail from Microsoft 365 accounts. The agencies urge swift remediation, including disabling unused services, MFA for critical access, patching the eight flaws, monitoring AD replication, and reviewing cloud app connections and web logs. 8 October 2026