A cybersecurity analyst monitors cloud systems as officials confront a global network of connected-device threats.
A China-based company that sells cybersecurity services is now accused of something else: supplying hackers with tools, infrastructure and stolen access. On October 8, 2026, the FBI, CISA, NSA and allied agencies published joint advisory AA26-281A about Integrity Technology Group, usually shortened to Integrity Tech. Several parts of it apply directly to Windows administrators: password spraying against Microsoft 365 and Exchange, VPN backdoors renamed to look like Windows processes, and theft of Active Directory credentials.

The same day, the U.S. Justice Department and FBI announced court-authorized seizures of domains connected to two of the company's tools. Here is what has been confirmed, what is still second-hand, and what defenders can do now.

A cybersecurity analyst monitors cloud systems as officials confront a global network of connected-device threats. What the agencies said​

CISA described Integrity Tech as a China-based cybersecurity company with ties to the Chinese government. According to CISA, it helps threat actors attack critical infrastructure sectors worldwide using large botnets, VPN infrastructure and "living off the land" techniques, meaning abuse of legitimate system tools. CISA said the advisory draws on real investigations and activity observed in North America, Southeast Asia and Africa.

The agencies did not say Integrity Tech is any particular hacking group. Their wording is that the actors it enables use tactics "consistent with" activity publicly tracked as Flax Typhoon, Ethereal Panda and Red Juliett. One analysis of the advisory also notes that commercial threat labels may not directly correspond to state attribution. Those names are vendor tracking labels, not three aliases for one company.

According to CISA, the targets included government, critical manufacturing and healthcare organizations, plus U.S. law enforcement and education. Inception Security's write-up of the advisory adds IT to that list. Infosecurity Magazine's report, as summarized by SC Media, also mentions religious institutions and a focus on Southeast Asia. CISA's press release does not include those two details, so treat them as reported rather than confirmed.

According to the DEV Community summary, the co-sealing agencies came from the U.S., the U.K., Australia, Canada, Japan, New Zealand and Spain. The UK's National Cyber Security Centre added that the actors are using AI tools, such as automated scanning, alongside large-scale botnets and manual exploitation.

Section summary: This is a multinational advisory about a contractor that allegedly supplies tools and access to state-linked hackers. The group names describe overlapping behavior, not a confirmed identity.

The domain seizures: MicroScan and FishHub​

The Justice Department's announcement confirms two of the tools independently. According to court documents unsealed in the Western District of Pennsylvania:

  • MicroScan is a vulnerability scanner Integrity Tech built to probe victim networks for weaknesses that its clients would exploit later. Some of that scanning ran through a botnet of internet-of-things devices infected with a Mirai variant. DOJ listed scanning targets including a South Carolina power company, a multinational NGO, airports in Japan and Poland, Taiwanese natural-gas and power companies, and two Taiwanese universities. Integrity Tech reached MicroScan through c0cc[.]cc, one of the seized domains.
  • FishHub allegedly supported spear-phishing. After an initial compromise, it downloaded more malware that gave clients remote access or searched for specific files and sent them to servers Integrity Tech controlled. DOJ says confirmed victims included about 20 Taiwanese universities. Five seized domains delivered the malware: 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com and linkedinns[.]net.

Two cautions apply. First, being scanned is not the same as being breached. The power company and airports appear as scanning targets. The Taiwanese universities are the only organizations DOJ calls confirmed victims. Second, these are allegations from court filings. The seizures cut off access to domains; nobody has been arrested.

Domain names such as outlook3650[.]com and linkedinns[.]net were plainly chosen to look like familiar Microsoft and LinkedIn addresses. Add them to your blocklists and DNS hunting queries.

DOJ called this its second public technical disruption of Integrity Tech. In September 2024, it disrupted the company's Mirai botnet, which it said included more than 200,000 consumer devices worldwide.

How the attacks unfold​

Infosecurity Magazine reported the attack chain, and several published analyses of the advisory back it up. In order:

1. Reconnaissance​

The actors scan with open-source tools and MicroScan. SafeBreach describes a custom platform containing over 1,300 penetration testing scripts.

2. Initial access​

They use Python- and Go-based exploit code, exploit cross-site scripting (XSS) flaws in third-party web apps, and password-spray Microsoft accounts. Aviatrix's analysis says known CVEs were involved, including CVE-2021-22205 (GitLab) and CVE-2019-11510 (Pulse Connect Secure). The same analysis says XSS payloads delivered malware disguised as DiagTrack.exe. DiagTrack is the name of a real Windows telemetry service, which makes the disguise effective.

3. EBurst against Exchange and Microsoft 365​

This is the part most relevant to Microsoft administrators. The FBI-hosted advisory PDF says the actors use EBurst, an open source Python-based tool, to target accounts in the Microsoft Office365 Cloud environment. SafeBreach says EBurst works through many Exchange interfaces: Exchange Control Panel (ECP), Exchange Web Services (EWS), Offline Address Book (OAB), Outlook Web Access (OWA), Remote Procedure Call (RPC), API, MAPI, PowerShell, Autodiscover, and Microsoft-Server-ActiveSync. The agencies tell defenders to protect all of them.

This is password spraying: a few common passwords tried against many accounts. Nothing in the advisory suggests Microsoft's cloud service itself was breached.

4. Persistence that looks like Windows​

The actors install legitimate SoftEther VPN clients to hide command-and-control traffic. Several analyses say the installers were typically renamed conhost.exe or dllhost.exe — process names that match legitimate Windows components — and configured to reconnect automatically at startup. SafeBreach says the installers arrive on Windows machines through PowerShell and built-in system binaries.

5. Collection and exfiltration​

  • Stolen data is staged under changing filenames. Infosecurity says this is meant to minimize detection of the MySQL email dump.
  • A PHP script named Curlc4.txt runs a bot that collects victims' email.
  • DC.exe imitates a domain controller to obtain Active Directory data. Inception Security says it binds over RPC to a domain controller and uses the Directory Replication Service to copy credentials, group memberships, and trusts. That is the technique known as DCSync.
  • office-cli is a Linux utility that keeps reading Outlook 365 mailboxes, configured with values such as client_id, tenant_id and secret. Those are the credentials of a registered app, which means the access can survive a user password reset. Inception says a custom web application also lets third parties view the stolen mail.

What Windows and Microsoft 365 admins should do​

The official recommendations, as reported, are to disable unused services, sanitize user input in web applications, and enforce strong identity and access management with multifactor authentication (MFA). CISA also asks organizations to patch the known-exploited CVEs listed in the advisory and to secure edge devices. Here is how that maps to a Microsoft environment:

  1. Close password spraying gaps. Require MFA on every interface EBurst targets, not only OWA. Legacy protocols such as ActiveSync, EWS and Autodiscover are frequently overlooked. TechTimes reports that MFA is described as the single most effective mitigation against EBurst-style password spraying.
  2. Read your sign-in logs. Look for many accounts failing from a small set of IP addresses, followed by a successful login, a pattern Innovation Network Design highlights.
  3. Audit app registrations and consented apps. office-cli authenticates with client IDs and secrets, so look for unfamiliar registered apps, new secrets and mailbox-read permissions you cannot explain.
  4. Hunt for impostor system binaries. From general Windows knowledge: legitimate conhost.exe and dllhost.exe live in System32 and are signed by Microsoft. A file with either name elsewhere, signed by someone else, starting at boot, or making outbound VPN-style connections deserves a close look. Check the path, signature and behavior before calling it malicious. A matching name alone proves nothing.
  5. Watch directory replication. TechTimes notes that unexpected Active Directory replication requests are the main way to spot DCSync. From general practice, replication requests coming from anything other than a domain controller warrant investigation.
  6. Patch edge devices and web apps. According to Innovation Network Design, CISA added five actively exploited flaws, in ProFTPD, ONLYOFFICE, Strapi, Apache Struts and ISC BIND, to its Known Exploited Vulnerabilities catalog after the advisory. Check the advisory's own CVE list against your inventory rather than relying on second-hand lists.
  7. Block the seized domains and the advisory's indicators. Then check past DNS logs for earlier connections to them.

Analysis: why this one matters​

These techniques are not new. Password spraying, abused VPN software and DCSync are all well documented. What stands out is the business model. The FBI's Brett Leatherman said the PRC relies on contractor and enabling companies. Actually, that quote is from the advisory's description of Integrity Tech as a for-profit company that builds tools for use and sale; the DOJ statement attributed to Leatherman makes the same point about China relying on contractors to extend the reach of its hacking. If a company sells scanning, phishing and access to multiple clients, seizing a few domains is a setback for it, not the end of it. DOJ itself describes this as the second disruption in two years.

There is also a fair counterpoint. Joint advisories rest on intelligence that is only partly made public, and some details here are still second-hand. Defenders do not need to settle the attribution question to act, though. A spray against ActiveSync or a VPN client posing as conhost.exe is worth investigating whoever is behind it.

Bottom line: For most Windows shops, this is not a new zero-day. It is a reminder to cover every Exchange login interface, audit app permissions, check that system binaries are where they should be, and patch internet-facing devices before someone else's scanner finds them first.

 

References

  1. Joint alert details Chinese cyber activity linked to Integrity Technology Group - SC Media SC Media 2026-10-11T17:56:06+00:00
  2. FBI Exposes China-Linked Hackers Running Portal for Stolen Emails aviatrix.ai
  3. Beijing Firm Integrity Technology Group Hacked Government Email, Built Third-Party Portal techtimes.com