On October 8, a significant alert was jointly issued by the United States, the United Kingdom, and several allied nations, focusing on a sanctioned Chinese organization known as Integrity Technology Group. This advisory detailed various tactics, techniques, and procedures (TTPs) that have come to light regarding this group, revealing their connections to multiple Beijing-backed cybercriminal factions.
Integrity Technology Group has been linked with notorious entities such as Flax Typhoon, also known as Ethereal Panda and Red Juliett. The advisory outlines how this organization’s operations have enabled these hacking groups to execute sophisticated cyberattacks against various targets globally.
The advisory explains that Integrity Tech employs personnel who are engaged in various forms of malicious cyber activities. These activities range from acquiring and building cyber tools intended for use and sale to compromising networks on a worldwide scale. This level of malicious activity has been monitored and categorized by the authoring organizations as indicative of China-based cyber threats. The report emphasizes that the services provided by Integrity Tech play a vital role in a larger Chinese cyber ecosystem, which is specifically geared towards exfiltrating sensitive data from victims worldwide, underscoring the global implications of their actions.
The report further elaborates on the technical aspects associated with Integrity Tech’s operations, highlighting several notable methodologies. Among these is the use of open-source scanning tools aimed at identifying vulnerabilities in networks and web applications. A specialized tool known as “MicroScan,” with over 1,300 penetration testing scripts designed to detect specific flaws on websites, is also utilized.
The group reportedly gains initial access to various networks and cloud services by leveraging command-line utilities built upon exploit codes developed in programming languages like Python and Go. One of the more troubling techniques employed includes the exploitation of cross-site scripting (XSS) vulnerabilities to compromise third-party applications.
In addition, Integrity Tech has been accused of using a tool known as EBurst for password spraying or guessing attacks against Microsoft 365 email accounts. They maintain persistence on victim systems by installing VPN clients, like SoftEther, on compromised devices, which helps obfuscate command and control communications.
Details regarding their data exfiltration practices paint a grim picture of their operational methodology. The organization often stages exfiltrated data using different file names, which minimizes the chance of detection by cybersecurity measures. They also create bots using a PHP script labeled Curlc4.txt to extract email information from victims. Notably, techniques have been reported where they trick domain controllers into revealing sensitive Active Directory information, including user account credentials.
The report indicates that their malicious activities often target specific sectors such as government, law enforcement, healthcare, and religious institutions across Southeast Asia. Techniques like the continuous use of command-line utilities, such as office-cli, enable them to access Microsoft Outlook 365 accounts, allowing for the theft of email data with relative ease.
To combat these pervasive threats, the report offers crucial guidelines for network defenders and incident response teams. It includes an extensive list of indicators of compromise (IoCs), along with resources and mitigation strategies. The primary recommendations for organizations looking to mitigate threats from Integrity Tech include disabling unnecessary services and ports; sanitizing user input within web applications to prevent potential XSS payload injections; and implementing identity, credential, and access management (ICAM) policies that enforce multifactor authentication (MFA) wherever feasible.
Paul Chichester, the director of operations for the National Cyber Security Centre (NCSC), expressed grave concern regarding the extensive activities carried out by Integrity Tech. He emphasized that the diversity of sectors targeted worldwide signifies the magnitude of the threat posed by this organization. Chichester urged all organizations to heed this warning and engage proactively with the NCSC’s advice and guidelines to ensure their cybersecurity posture is fortified against such malevolent threats.
Additionally, on the same day, the U.S. government announced the seizure of various domains associated with the hacking tools MicroScan and FishHub. This action aims to disrupt the operations of Integrity Technology Group and its associated threat actors, further illustrating the significant steps being taken to combat these cyber threats on a global scale.

