Global Cyber-Espionage Alert: Chinese-Linked "Integrity Technology Group" Exposed in Massive Email Theft Campaign

In a coordinated international effort released on October 8, the FBI and cybersecurity agencies from six allied nations have unveiled a sprawling, multi-year cyber-espionage campaign orchestrated by a China-based entity known as the Integrity Technology Group. The investigation reveals a systematic effort to infiltrate government, law enforcement, healthcare, and religious organizations across Southeast Asia, Africa, and North America.

The scale of the operation is significant, characterized by the use of sophisticated, automated toolsets designed to bypass security measures, harvest sensitive communications, and maintain persistent access to high-value networks. While the group has previously been identified in connection with massive botnets, this latest advisory sheds light on their primary objective: the large-scale theft of private and governmental email intelligence.


The Anatomy of the Campaign: Methods and Tactics

The Integrity Technology Group operates at the intersection of private-sector cyber services and state-aligned espionage. According to the joint advisory, the threat actors utilize a methodical, tiered approach to compromise victims.

Initial Access: The Automated Web Scan

The group relies heavily on "reconnaissance at scale." By employing open-source scanners such as Nmap, masscan, and WPScan, the attackers identify unpatched vulnerabilities across a wide range of web applications. Their scanning infrastructure specifically targets critical network ports, including 21 (FTP), 22 (SSH), 80/443 (HTTP/HTTPS), and 1080 (SOCKS proxy).

Most notably, the group has utilized a proprietary Python-based tool dubbed "MicroScan" since at least 2017. This framework integrates over 1,300 penetration testing scripts, allowing the attackers to automatically query services for known exploits in platforms like Apache Struts, Juniper ScreenOS, Oracle WebLogic, and various WordPress configurations.

Credential Harvesting and "Password Spraying"

Beyond exploiting software flaws, the group engages in aggressive credential theft. They employ a specialized tool known as "EBurst," an open-source Python script tailored to target Microsoft 365 and Exchange environments. By "spraying" common passwords against a vast array of accounts, the attackers attempt to gain a foothold without triggering traditional account-lockout security protocols.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Furthermore, the FBI has identified the use of sophisticated phishing techniques, including cross-site scripting (XSS) payloads. In these instances, attackers inject malicious fields into legitimate web pages, tricking unsuspecting users into providing their credentials. Once the user enters their information, they are prompted to download a "password-protected" ZIP file containing a malicious executable, live700_v1.exe, which establishes a covert communication channel with the attacker’s command-and-control infrastructure.


A Chronology of Malicious Activity

The timeline of the Integrity Technology Group’s activities suggests a long-term, patient strategy designed for endurance and maximum intelligence extraction.

  • 2016–2017: The group begins utilizing the "MicroScan" tool and establishes early infrastructure that remains active for years.
  • January 2021: The earliest confirmed evidence of the group’s systematic penetration of target networks. This period marks the beginning of their sustained campaign to harvest data from government and law enforcement sectors.
  • August–September 2024: The FBI and international partners successfully disrupt the "Raptor Train" botnet, a network of over 200,000 compromised routers and IoT devices controlled by the group.
  • January 2025: The U.S. Treasury Department officially sanctions Integrity Technology Group for its role in multiple cyber-intrusions. Despite these sanctions, the group’s operations continue to be observed in active, ongoing attacks.
  • December 2025: The United Kingdom imposes its own sanctions on the company, citing "reckless and irresponsible" behavior in cyberspace.
  • October 2026: A new, comprehensive advisory is issued by the FBI and international partners, detailing the specific technical methods used for post-exploitation and email theft.

Technical Infrastructure and Persistence

Once inside a network, the Integrity Technology Group prioritizes persistence and data exfiltration. Their techniques are designed to blend in with legitimate system traffic to evade detection by standard antivirus and EDR (Endpoint Detection and Response) solutions.

Maintaining Access

To maintain long-term control over compromised systems, the attackers deploy legitimate VPN software, such as SoftEther. By renaming the installer files to match innocuous Windows processes like conhost.exe or dllhost.exe, the attackers ensure the software runs silently in the background, reconnecting automatically upon system reboot.

Data Exfiltration: The "Curlc4.txt" Bot

For email theft, the group employs a custom PHP-based bot, Curlc4.txt. This tool interfaces directly with Exchange Web Services (EWS) to systematically compress, encrypt, and upload mailbox contents to remote servers. The group’s operations are so refined that they maintain a dedicated web application for third parties—or potentially other state actors—to browse stolen email content in real-time, often restricting access to specific IP addresses located in Xiamen, China.

The DCSync Technique

The attackers frequently utilize DC.exe, a tool that leverages the DCSync technique to mimic domain controller replication. This allows them to copy sensitive Active Directory data, including user credentials, group memberships, and organizational trust relationships, effectively granting them administrative-level visibility into the entire victim network.

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Official Responses and Geopolitical Implications

The disclosure of these activities has triggered significant diplomatic friction. The U.S. government, through the FBI and the Treasury, has been explicit in its assessment that Integrity Technology Group is a for-profit enterprise with deep-seated ties to Chinese state security apparatuses.

The late FBI Director Christopher Wray previously noted that the company’s leadership had publicly acknowledged conducting intelligence gathering and reconnaissance on behalf of Chinese state agencies. This revelation underscores a growing trend where the Chinese government outsources cyber-espionage to private "contractor" firms, providing the state with plausible deniability.

Predictably, the Chinese government has rejected these allegations. Following the January 2025 sanctions, Integrity Technology Group issued statements through the Shanghai Stock Exchange claiming the U.S. accusations were baseless. The Chinese Foreign Ministry has consistently labeled these sanctions as politically motivated, accusing the U.S. of attempting to contain China’s technological development.


Defensive Recommendations: A Call to Action

The joint advisory provides 39 pages of technical indicators, including IP addresses, domain names, and file hashes. However, given the age of some of this infrastructure, the agencies urge network defenders to treat these indicators with caution and perform thorough verification before implementing blocklists.

Strategic Mitigation Steps

  1. Audit Vulnerabilities: Organizations must prioritize patching the eight specific CVEs listed in the advisory (including Gitlab, Apache Struts, and Pulse Connect Secure vulnerabilities).
  2. Monitor EWS and M365 Interfaces: Given the group’s focus on email harvesting, administrators should strictly audit access to ECP, EWS, OWA, and PowerShell interfaces.
  3. Implement Robust Logging: Because the attackers use legitimate software (like SoftEther) and native Windows processes for persistence, defenders should focus on behavioral analysis rather than simple signature-based detection.
  4. Network Segmentation: By isolating sensitive databases and mail servers, organizations can significantly hinder the attackers’ ability to move laterally using DCSync and other credential-theft tools.

Handling a Compromise

If a breach is detected, the agencies recommend a "contain, analyze, and purge" strategy. Organizations should:

  • Isolate affected hosts immediately to prevent further exfiltration.
  • Conduct forensic analysis to determine the scope of the data theft.
  • Report the incident to the relevant national cybersecurity authority.
  • Hardening: Only after full data collection should the attackers be purged, followed by a comprehensive network-wide hardening process to prevent re-entry.

The Integrity Technology Group case serves as a stark reminder that in the modern era, the threat is no longer just from shadowy, disconnected hackers. It is a well-funded, professionalized ecosystem where corporate entities operate as an arm of the state, turning the tools of global commerce into weapons of strategic espionage. Organizations must remain vigilant, as the persistence and adaptability demonstrated by this group indicate that their campaign is far from over.

Related Posts

The New Frontier of Oversight: UK Privacy Watchdog Forces AI Titans to Commit to Data Accountability

The landscape of artificial intelligence regulation in the United Kingdom has shifted significantly. In a coordinated move to rein in the data-hungry practices of the world’s most powerful technology firms,…

Sophos Firewall v23: A Paradigm Shift in Network Security, Automation, and AI Integration

The cybersecurity landscape is undergoing a seismic shift. As network perimeters dissolve into hybrid cloud environments and the threat surface expands through sophisticated automated attacks, the tools used to defend…