A cybersecurity company listed on the Shanghai stock exchange, Integrity Technology Group (also known as Yongxin Zhicheng), has been accused of involvement in China’s state-sponsored cyberattacks. The U.S. government, in a joint cybersecurity advisory, linked the company to a botnet associated with the hacking group Flax Typhoon, which has compromised hundreds of thousands of Internet of Things (IoT) devices since 2021.
FBI Director Christopher Wray named Integrity Tech during a speech at the Aspen Cyber Summit, identifying it as a key player in running the botnet. The advisory revealed that a MySQL database controlling the botnet contained over 1.2 million records of compromised devices, with more than 260,000 machines infected by June 2024. The company is accused of using the same IP addresses involved in other cyber incidents to access U.S. operational infrastructure.
The FBI’s investigation into U.S. victims determined that the compromises were consistent with Flax Typhoon’s tactics, techniques, and infrastructure, a group known for espionage activities targeting corporations, media organizations, universities, and government agencies, especially in Taiwan. Notably, around half of the botnet’s hijacked devices were located in the United States.
Integrity Tech is not only a cybersecurity company but also plays a significant role in China’s hacking talent development ecosystem. The company organizes the Matrix Cup, a Chinese hacking competition instrumental in cultivating domestic talent and identifying critical vulnerabilities for China’s intelligence agencies.
Eugenio Benincasa, a senior cyberdefense researcher at the Center for Security Studies at ETH Zurich, noted that Integrity Tech’s involvement in China’s state-sponsored hacking activities is particularly significant given the company’s size and public listing. Integrity Tech, with a market capitalization of $318 million and reported revenues of $56 million, primarily sells network security products to Chinese customers and employs nearly 500 staff, with a large portion working in its technology division.
This is one of the latest allegations connecting Chinese commercial entities with state-sponsored hacking activities, following a 2017 indictment involving Boyusec. However, the scale of Integrity Tech’s involvement is unprecedented, raising concerns about the overlap between China’s commercial and state-sponsored cyber activities.

