Hackers linked to a Chinese cybersecurity firm have been accused of stealing emails from various organizations in Southeast Asia, including government agencies, law enforcement, healthcare facilities, and religious institutions. This revelation was made by the FBI and six other international agencies on October 8.
The firm in question, Integrity Technology Group, has faced sanctions from both the U.S. and the UK. The hackers associated with this company utilized sophisticated methods to breach networks, such as scanning websites for vulnerabilities, guessing passwords for Microsoft accounts, and extracting mailbox data using specialized tools.
These cyberattacks have been ongoing since at least mid-January 2021, as detailed in the joint advisory released by the agencies. While the exact extent of the breaches and the number of affected organizations remain unspecified, it is clear that a wide range of sectors have been targeted.
In addition to Southeast Asia, the same hackers have also targeted entities in Africa, North America, and the U.S., including government services, critical manufacturing, healthcare, IT firms, law enforcement agencies, educational institutions, and religious organizations.
The hackers have developed a web application that facilitates third-party access to stolen email content, although the specific third parties involved have not been disclosed.
In a significant development in September 2024, the FBI disrupted a botnet controlled by Integrity Technology Group, comprising over 200,000 compromised devices. Termed Raptor Train by Lumen researchers, this botnet posed a serious threat to cybersecurity.
The recent advisory sheds light on the modus operandi of the hackers and their connection to Integrity Technology Group. Described as a for-profit Chinese company with ties to the government, the firm’s employees are involved in developing cyber tools for malicious purposes, hosting infrastructure, and executing network intrusions.
The U.S. Treasury and the UK have imposed sanctions on Integrity Technology Group for its role in multiple cyber intrusions against American targets. Former FBI director Christopher Wray publicly stated the company’s admission of collaborating with Chinese government security agencies for intelligence gathering.
The hackers’ techniques align with known cyber threat groups such as Flax Typhoon, Ethereal Panda, and RedJuliett. These groups have been observed targeting various organizations worldwide, with a focus on specific regions like Taiwan.
Despite facing accusations from the U.S., Integrity Technology Group has vehemently denied any involvement in nefarious activities. The company has refuted the sanctions, emphasizing that they lack factual basis.
Methods of Intrusion
The hackers employ a range of tools and techniques to infiltrate networks, including open-source scanners like Nmap, masscan, and WPScan. They target specific ports and vulnerabilities to identify potential entry points.
One of their primary tools, MicroScan, comprises over 1,300 penetration testing scripts designed to exploit weaknesses in various services and applications. They have exploited vulnerabilities in products such as GNU Bash, ProFTPD, ISC BIND, Apache Struts, Pulse Connect Secure, GitLab, ONLYOFFICE Document Server, and Strapi.
The hackers also leverage AI tools and automated scanning to streamline their operations, making it challenging for defenders to detect and mitigate their activities.
Furthermore, the hackers use password spraying techniques to gain unauthorized access to Microsoft 365 and Exchange accounts. They target multiple interfaces to exploit weaknesses and extract sensitive information.
Persistence and Data Extraction
To maintain access to compromised networks, the hackers install legitimate VPN software like SoftEther, disguising it as legitimate system processes to evade detection. They also utilize tools like DC.exe to extract credentials from domain controllers and run scripts like Curlc4.txt to collect and upload email data to remote servers.
Additionally, the hackers employ phishing tactics, fake login pages, and password-protected ZIP files to trick users into disclosing their credentials. They have been observed targeting email accounts, calendars, and contact information for illicit purposes.
Defense Strategies
Defenders are advised to take proactive measures to safeguard their networks against such sophisticated attacks. Recommendations include disabling unused services, implementing input validation in web applications, enforcing multifactor authentication, monitoring Active Directory for suspicious replication, and patching known vulnerabilities.
In the event of a suspected breach, organizations should isolate affected systems, conduct thorough investigations to assess the extent of the compromise, and report the incident to relevant authorities. Implementing robust security measures and staying vigilant against emerging threats are vital in mitigating cybersecurity risks.
The advisory provides a comprehensive list of indicators of compromise (IOCs) associated with the hackers, enabling organizations to enhance their threat detection capabilities and strengthen their defenses.




