www.infosecurity-magazine.com 9 Oct 2026, 10:00 UTC

Allies expose how Chinese firm Integrity Tech enabled global cyber espionage attacks

CyberSIXT Evidence Panel
Threat Actor
Integrity Technology Group

A joint warning from the US, UK and allied countries outlines the tactics, techniques and procedures attributed to a sanctioned Chinese organisation known as Integrity Technology Group. The advisory connects Integrity Tech to Beijing-linked cyber operations and to prolific groups such as Flax Typhoon (also known as Ethereal Panda and Red Juliett).

It describes a range of activities that contribute to the broader Chinese cyber ecosystem, including developing or procuring tools, acquiring or hosting infrastructure, and compromising networks globally to exfiltrate sensitive data. The report notes that Integrity Tech’s work has historically supported adversaries by enabling access, tooling and infrastructure used in cyber campaigns, with targeted exfiltration across sectors.

Detailed technical findings highlight a suite of methods and tools associated with Integrity Tech’s TTPs. These include using open-source scanning tools to identify vulnerabilities, employing a “MicroScan” tool with more than 1,300 pen-testing scripts to probe sites, and gaining initial access through command-line utilities built on Python and Go exploits.

The advisory also cites exploitation of cross-site scripting (XSS) bugs, use of the EBurst tool for password spraying against Microsoft 365 accounts, and persistence tactics such as installing VPN clients like SoftEther to obfuscate C2 communications.

Other indicators include staged exfiltration of data with varied filenames, a bot created via a PHP script to harvest emails, and use of DC[.]exe to extract Active Directory credentials, with email data exfiltration from on-premises and cloud services across government, law enforcement, healthcare and religious organisations in Southeast Asia. The report also points to ongoing IoCs, mitigations and incident-response guidance for defenders. Finally, the US announced domain seizures linked to MicroScan and FishHub as part of disrupting Integrity Tech operations.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline