Seven nations expose Chinese firm fueling global email theft

Published

Government cyber agencies from seven countries have named a Chinese company, Integrity Technology Group, as the engine behind a long-running hacking operation that breaks into organizations around the world and walks off with their email. The joint advisory AA26-281A, published on October 8, says the threat actors it enables combine automated scanning tools, large botnets and hands-on intrusion work to steal sensitive data, including from US critical infrastructure.

The evidence comes from multiple FBI investigations. The FBI, CISA and NSA co-authored the advisory with the UK's National Cyber Security Centre, Australia's ASD's ACSC, the Canadian Centre for Cyber Security, Japan's National Police Agency and National Cybersecurity Office, New Zealand's NCSC and Spain's CNI.

A contractor, not a lone hacking crew

The agencies describe Integrity Tech as a for-profit company with links to the Chinese government whose staff build and buy hacking tools, host attack infrastructure and break into networks themselves. The activity is consistent with what the security industry tracks as Flax Typhoon, Ethereal Panda and Red Juliett, though the advisory cautions that the mapping is not one to one. The NCSC notes that the UK sanctioned the company last year and that it was exposed in September 2024 as the operator of a large botnet used by Flax Typhoon.

Victims span US government services, critical manufacturing, healthcare and IT, plus US law enforcement, education and religious organizations, and targets across South East Asia, Africa and North America. The FBI recovered an archived email database showing stolen mail from government bodies, police agencies, health systems and religious institutions in South East Asia, and in some cases the actors restricted access to that stolen data to IP addresses in Xiamen, China.

Scanners first, then mailboxes

The operation starts wide. The actors run common open-source scanners such as Fscan, masscan, Nmap and dirsearch, and since at least 2017 have used a Python web tool called MicroScan that carries more than 1,300 scripts for probing specific products. The advisory lists eight CVEs, dating from 2014 to 2023, that those scripts exploited successfully.

Once inside, the focus is email. The actors password-spray Microsoft Exchange and Office 365 accounts with an open-source tool called EBurst, pull mail through the Exchange Web Services API with a PHP bot the FBI calls Curlc4, and use a command-line utility, office-cli, to keep harvesting Outlook 365 mailboxes over time. They also ran a DCSync tool, DC.exe, to copy credentials out of Active Directory. For persistence they install the legitimate SoftEther VPN client, often renamed conhost.exe or dllhost.exe, which security software is less likely to flag. That SoftEther habit echoes our earlier report on Flax Typhoon turning ArcGIS into a year-long backdoor.

One recovered cross-site scripting payload displayed fake username and password fields on a vulnerable site, then offered a password-protected zip holding live700_v1.exe. That file starts a process named DiagTrack.exe, mimicking a real Windows component, which talks to a domain the FBI attributes to Integrity Tech. The FBI assesses that this malware likely targets mailbox data.

Turn off what you do not use, and enforce MFA

The agencies ask defenders to hunt for this activity now. Their priority actions are to disable unused services and ports, sanitize web application input to block cross-site scripting, require multifactor authentication on every service possible, and patch promptly. Teams running Exchange should cover every interface EBurst can spray, including OWA, EWS, ECP, ActiveSync, Autodiscover and MAPI. Unexpected SoftEther installs deserve a close look.

Indicators named in the advisory include natcloudservice[.]com and upl[.]natcloudservice[.]com (the Curlc4 command server), 149[.]28[.]132[.]137, and dns[.]studiocloud[.]xyz. CISA publishes the full set as STIX files alongside the advisory.

The point of naming a company rather than a codename is that the tools, the infrastructure and the hands at the keyboard all trace back to one business. For defenders the lesson is more mundane: almost every step here, from spraying passwords to parking a VPN client on a server, works best against exposed services and accounts without MFA.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions