Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

FBI screenshot of a Chinese-language web dashboard titled E-commerce Order Management, served from 127.0.0.1:8080, showing counts of 694 low, 160 medium and 1,138 high threats, 649 completed scans and 21,851 total reports, a redacted list of the five most vulnerable hosts and a top-five plugin list led by sensitive information collection.
Screenshot: FBI, via joint Cybersecurity Advisory AA26-281A, a MicroScan account dashboard showing detected vulnerabilities, recovered in FBI investigations of Integrity Technology Group, Oct 8, 2026 (fair use).

Threat Intel

FBI Seizes Integrity Tech Hacking Tools as Allies Detail How China-Linked Hackers Steal Government Email

The FBI and nine partner agencies said on October 8 that hackers tied to Integrity Technology Group, a China-based company with links to the Chinese government, stole email from government, law enforcement, healthcare and religious organizations in Southeast Asia, as the Justice Department seized domains behind the company's Microscan scanner and FishHub phishing tool.

Priya Shah, Threat IntelSingapore6 min read

SINGAPORE - The FBI and nine partner agencies in the United States and six other countries said on Thursday that hackers tied to Integrity Technology Group, a China-based company with links to the Chinese government, have stolen email from government organizations, law enforcement agencies, healthcare systems and religious institutions in Southeast Asia. The same day, the Justice Department and the FBI announced court-authorized seizures of domains behind two of the company's hacking tools: a vulnerability scanner called Microscan and a spear-phishing platform called FishHub. The joint advisory, AA26-281A, draws on technical evidence from multiple FBI investigations and says the actors use methods consistent with activity the security industry tracks as Flax Typhoon, Ethereal Panda and Red Juliett. It also lists targets across U.S. government services, critical manufacturing, healthcare and information technology, along with U.S. law enforcement, education and religious organizations. For security operations teams, the value is in the detail: file names, scripts, mail-theft tooling and an indicator appendix that runs to 39 pages.

Cover of the TLP:CLEAR joint Cybersecurity Advisory AA26-281A with the seals and logos of the FBI, CISA, NSA, NCSC-UK, ASD's ACSC, the Canadian Centre for Cyber Security, Japan's National Police Agency and National Cybersecurity Office, New Zealand's NCSC and Spain's CNI above the title Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data.
Graphic: FBI, CISA, NSA and partner agencies in the United Kingdom, Australia, Canada, Japan, New Zealand and Spain, cover of joint Cybersecurity Advisory AA26-281A, Oct 8, 2026 (fair use).Nine agencies signed the joint advisory AA26-281A.

According to court documents unsealed in the Western District of Pennsylvania, Integrity Tech built Microscan to probe victim networks for vulnerabilities that its clients would later exploit, in part by scanning through a botnet of internet-of-things devices infected with a variant of the Mirai malware. Targets included a U.S. power company in South Carolina, a multinational nongovernmental organization, airports in Japan and Poland, Taiwanese natural gas and power companies and two Taiwanese universities, the Justice Department said. The advisory says the actors have used Microscan since as early as 2017 and describes it as a Python-based web application with more than 1,300 penetration testing scripts aimed at software including Oracle WebLogic Server, Jenkins, Apache Struts, WordPress and Juniper ScreenOS. FishHub delivered follow-on malware after spear-phishing compromises, and the department said its confirmed victims included about 20 Taiwanese universities. The seized domains include c0cc[.]cc, through which Integrity Tech accessed Microscan, and five FishHub delivery domains: 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com and linkedinns[.]net. The department called the action its second public technical disruption of Integrity Tech's infrastructure, after the September 2024 takedown of a Mirai botnet of more than 200,000 consumer devices.

Since at least mid-January 2021, the advisory says, the actors have broken in mainly with command-line exploit utilities written in Python and Go, and they scan with open-source tools such as Fscan, masscan, Nmap, dirsearch and WPScan, mostly on ports 21, 22, 53, 80, 443 and 1080. The FBI also recovered a cross-site scripting payload that rewrites a vulnerable web page to show username and password fields. Whatever a visitor types, the page then offers a password-protected .zip file holding live700_v1.exe, which starts a process named DiagTrack.exe, the name of legitimate Windows software, and communicates over encrypted HTTP with dns.studiocloud[.]xyz, a domain the FBI attributes to Integrity Tech. Because the program contains functions that query user mailboxes, the FBI assesses that it likely targets email. Against Microsoft Exchange and Office 365 accounts, the actors use EBurst, an open-source Python tool, to spray and guess passwords across Outlook Web Access, Exchange Web Services, the Exchange Control Panel, the Offline Address Book, Autodiscover, MAPI, RPC, PowerShell, ActiveSync and the API. "Network defenders should include these interfaces when defending against EBurst," the advisory says.

Browser window on a localhost Chat/Login page loaded from payload_page.html, with a Chinese-language heading meaning customer service center login, username and password fields and a login button.
Screenshot: FBI, via joint Cybersecurity Advisory AA26-281A, a cross-site scripting payload recovered by the FBI after it runs, turning a web page into a customer service login form that collects usernames and passwords, Oct 8, 2026 (fair use).The recovered script rewrites a page into a login form.

To stay inside networks, the actors install the SoftEther VPN client, downloading installers with PowerShell or other built-in Windows tools, or with curl or wget on Linux, and set the client to reconnect at startup. They often name the installers conhost.exe or dllhost.exe, and the advisory warns that "endpoint detection software is less likely to flag SoftEther because it is a legitimate VPN software." The advisory lists domains and subdomains that hosted the SoftEther connections, among them hmbcloud[.]net, 98aiblog[.]com, javaupdate.giize[.]com and twimg.co[.]uk, and says the actors also accessed other targets connected to those hubs, including cybersecurity websites. Inside Windows domains, they used a tool called DC.exe to run the DCSync technique, pulling account credentials, group memberships and trust relationships from Active Directory through the Directory Replication Service on a domain controller.

The mail theft itself is methodical. The FBI observed the actors staging stolen MySQL email dumps under innocuous names such as 001.gif, Css.js, Include.png and M2k.js. A PHP bot called Curlc4.txt pulls mail through the Exchange Web Services API, which also exposes calendars and contacts, compresses the haul, sometimes encrypts it with RC4 or AES-128-CBC, renames its child process "crypto" and uploads it to natcloudservice[.]com; the script itself was downloaded from upl.natcloudservice[.]com at 149.28.132[.]137. A Linux utility called office-cli uses stored client_id, tenant_id and secret values to keep pulling mail from Outlook 365 accounts through legitimate access methods, which the advisory says helps it evade detection. The actors also run a custom web application that gives third parties access to stolen email by account, and in some cases they restricted access to the exfiltrated data to IP addresses in Xiamen, China.

Advisory page headed Curlc4.txt with text on the EWS email bot, the IP address 149.28.132[.]137 and RC4 or AES-128-CBC encryption, and Table 1 listing the directories the script searches: /, /home, /var/www, /usr and /var/tmp.
Screenshot: FBI, joint Cybersecurity Advisory AA26-281A, page 9, describing Curlc4.txt, a PHP bot that pulls email through the Exchange Web Services API and uploads it to natcloudservice[.]com, Oct 8, 2026 (fair use).Curlc4.txt pulls mail through Exchange Web Services.

For hunters, the advisory translates into a short list of checks. On endpoints, that means SoftEther binaries running as conhost.exe or dllhost.exe, PowerShell, curl or wget fetching VPN installers from unfamiliar hosts, a DiagTrack.exe process making HTTP connections to the listed domains, and Curlc4 artifacts such as /var/tmp/.sess.zip, a .run file under storage/fm and a process named crypto. In identity and mail logs, it means password spraying spread across many Exchange interfaces rather than one login page, unexpected Active Directory replication, and cloud applications that can reach mailbox or file data. On the network, the domains, IP addresses and hashes are published as STIX XML and JSON files. The agencies caution that several indicators date to as early as 2016 and should be vetted before anything is blocked.

The recommended fixes are familiar: disable unused services and ports, sanitize web application input against cross-site scripting, require multifactor authentication, particularly for webmail, VPNs and accounts that reach critical systems, use protective DNS and patch. Appendix B lists eight successfully exploited vulnerabilities recovered from the actors' penetration testing scripts, most of them years old, including CVE-2014-6278 in GNU Bash, CVE-2019-11510 in Pulse Connect Secure and CVE-2021-22205 in GitLab. The advisory does not say how many organizations were breached or when the thefts took place. "The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity," Brett Leatherman, assistant director of the FBI's Cyber Division, said in the Justice Department's announcement. "By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure." The FBI's San Diego and Baltimore field offices are investigating the case.

Sources:


Priya Shah covers threat intelligence, intrusion analysis, and adversary tradecraft for SOCtember from Singapore.

Related stories

Threat Intel desk