
FBI Seizes Integrity Tech Hacking Tools as Allies Detail How China-Linked Hackers Steal Government Email
The FBI and nine partner agencies said on October 8 that hackers tied to Integrity Technology Group, a China-based company with links to the Chinese government, stole email from government, law enforcement, healthcare and religious organizations in Southeast Asia, as the Justice Department seized domains behind the company's Microscan scanner and FishHub phishing tool.
Priya Shah, Threat IntelSingapore6 min read
SINGAPORE - The FBI and nine partner agencies in the United States and six other countries said on Thursday that hackers tied to Integrity Technology Group, a China-based company with links to the Chinese government, have stolen email from government organizations, law enforcement agencies, healthcare systems and religious institutions in Southeast Asia. The same day, the Justice Department and the FBI announced court-authorized seizures of domains behind two of the company's hacking tools: a vulnerability scanner called Microscan and a spear-phishing platform called FishHub. The joint advisory, AA26-281A, draws on technical evidence from multiple FBI investigations and says the actors use methods consistent with activity the security industry tracks as Flax Typhoon, Ethereal Panda and Red Juliett. It also lists targets across U.S. government services, critical manufacturing, healthcare and information technology, along with U.S. law enforcement, education and religious organizations. For security operations teams, the value is in the detail: file names, scripts, mail-theft tooling and an indicator appendix that runs to 39 pages.

According to court documents unsealed in the Western District of Pennsylvania, Integrity Tech built Microscan to probe victim networks for vulnerabilities that its clients would later exploit, in part by scanning through a botnet of internet-of-things devices infected with a variant of the Mirai malware. Targets included a U.S. power company in South Carolina, a multinational nongovernmental organization, airports in Japan and Poland, Taiwanese natural gas and power companies and two Taiwanese universities, the Justice Department said. The advisory says the actors have used Microscan since as early as 2017 and describes it as a Python-based web application with more than 1,300 penetration testing scripts aimed at software including Oracle WebLogic Server, Jenkins, Apache Struts, WordPress and Juniper ScreenOS. FishHub delivered follow-on malware after spear-phishing compromises, and the department said its confirmed victims included about 20 Taiwanese universities. The seized domains include c0cc[.]cc, through which Integrity Tech accessed Microscan, and five FishHub delivery domains: 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com and linkedinns[.]net. The department called the action its second public technical disruption of Integrity Tech's infrastructure, after the September 2024 takedown of a Mirai botnet of more than 200,000 consumer devices.
Since at least mid-January 2021, the advisory says, the actors have broken in mainly with command-line exploit utilities written in Python and Go, and they scan with open-source tools such as Fscan, masscan, Nmap, dirsearch and WPScan, mostly on ports 21, 22, 53, 80, 443 and 1080. The FBI also recovered a cross-site scripting payload that rewrites a vulnerable web page to show username and password fields. Whatever a visitor types, the page then offers a password-protected .zip file holding live700_v1.exe, which starts a process named DiagTrack.exe, the name of legitimate Windows software, and communicates over encrypted HTTP with dns.studiocloud[.]xyz, a domain the FBI attributes to Integrity Tech. Because the program contains functions that query user mailboxes, the FBI assesses that it likely targets email. Against Microsoft Exchange and Office 365 accounts, the actors use EBurst, an open-source Python tool, to spray and guess passwords across Outlook Web Access, Exchange Web Services, the Exchange Control Panel, the Offline Address Book, Autodiscover, MAPI, RPC, PowerShell, ActiveSync and the API. "Network defenders should include these interfaces when defending against EBurst," the advisory says.

To stay inside networks, the actors install the SoftEther VPN client, downloading installers with PowerShell or other built-in Windows tools, or with curl or wget on Linux, and set the client to reconnect at startup. They often name the installers conhost.exe or dllhost.exe, and the advisory warns that "endpoint detection software is less likely to flag SoftEther because it is a legitimate VPN software." The advisory lists domains and subdomains that hosted the SoftEther connections, among them hmbcloud[.]net, 98aiblog[.]com, javaupdate.giize[.]com and twimg.co[.]uk, and says the actors also accessed other targets connected to those hubs, including cybersecurity websites. Inside Windows domains, they used a tool called DC.exe to run the DCSync technique, pulling account credentials, group memberships and trust relationships from Active Directory through the Directory Replication Service on a domain controller.
The mail theft itself is methodical. The FBI observed the actors staging stolen MySQL email dumps under innocuous names such as 001.gif, Css.js, Include.png and M2k.js. A PHP bot called Curlc4.txt pulls mail through the Exchange Web Services API, which also exposes calendars and contacts, compresses the haul, sometimes encrypts it with RC4 or AES-128-CBC, renames its child process "crypto" and uploads it to natcloudservice[.]com; the script itself was downloaded from upl.natcloudservice[.]com at 149.28.132[.]137. A Linux utility called office-cli uses stored client_id, tenant_id and secret values to keep pulling mail from Outlook 365 accounts through legitimate access methods, which the advisory says helps it evade detection. The actors also run a custom web application that gives third parties access to stolen email by account, and in some cases they restricted access to the exfiltrated data to IP addresses in Xiamen, China.
![Advisory page headed Curlc4.txt with text on the EWS email bot, the IP address 149.28.132[.]137 and RC4 or AES-128-CBC encryption, and Table 1 listing the directories the script searches: /, /home, /var/www, /usr and /var/tmp.](/photos/fbi-integrity-tech-microscan-fishhub-seizure-china-email-theft/inline-3.jpg)
For hunters, the advisory translates into a short list of checks. On endpoints, that means SoftEther binaries running as conhost.exe or dllhost.exe, PowerShell, curl or wget fetching VPN installers from unfamiliar hosts, a DiagTrack.exe process making HTTP connections to the listed domains, and Curlc4 artifacts such as /var/tmp/.sess.zip, a .run file under storage/fm and a process named crypto. In identity and mail logs, it means password spraying spread across many Exchange interfaces rather than one login page, unexpected Active Directory replication, and cloud applications that can reach mailbox or file data. On the network, the domains, IP addresses and hashes are published as STIX XML and JSON files. The agencies caution that several indicators date to as early as 2016 and should be vetted before anything is blocked.
The recommended fixes are familiar: disable unused services and ports, sanitize web application input against cross-site scripting, require multifactor authentication, particularly for webmail, VPNs and accounts that reach critical systems, use protective DNS and patch. Appendix B lists eight successfully exploited vulnerabilities recovered from the actors' penetration testing scripts, most of them years old, including CVE-2014-6278 in GNU Bash, CVE-2019-11510 in Pulse Connect Secure and CVE-2021-22205 in GitLab. The advisory does not say how many organizations were breached or when the thefts took place. "The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity," Brett Leatherman, assistant director of the FBI's Cyber Division, said in the Justice Department's announcement. "By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure." The FBI's San Diego and Baltimore field offices are investigating the case.
Sources:
- FBI IC3: Joint Cybersecurity Advisory AA26-281A (FBI and partners, Oct 8, 2026)
- CISA: AA26-281A with STIX XML and JSON (CISA)
- Justice Department: Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers (U.S. Department of Justice, Oct 8, 2026)
- NSA: NSA joins FBI and others to provide guidance to mitigate Chinese government-linked activity (NSA, Oct 8, 2026)
Priya Shah covers threat intelligence, intrusion analysis, and adversary tradecraft for SOCtember from Singapore.
Related stories
Threat Intel
Iran-Linked Hackers Posing as Dubai Airports Recruiters Hide Malware in a Visual Studio Coding Test
Threat Intel
Rapid7 Tracks BPFDoor and AVERAT Implants Mimicking Asian Mail Gateways
Detection
Microsoft Tracks EvilTokens Phishing Kit Behind Device Code Token Theft
Detection