Thank you for reading or listening to The Realist Juggernaut. Independent journalism should be accessible to everyone.
THREAT SUMMARY
Category: State-Sponsored Cyber Espionage / Critical Infrastructure Threat
Threat Actor: China government-linked cyber operators enabled by Integrity Technology Group
Associated Activity: Flax Typhoon, Ethereal Panda, Red Juliett and related China-based malicious cyber activity
Primary Risks: Network compromise, credential theft, email collection, Active Directory credential access, persistence, data exfiltration
Affected Environments: Government, Critical Manufacturing, Healthcare and Public Health, Information Technology, Law Enforcement, Education, Religious Organizations
Attack Methods: Vulnerability scanning, botnets, cross-site scripting, password spraying, password guessing, VPN persistence, living-off-the-land techniques, remote email collection
Observed CVEs: CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894
Threat Status: Active government-linked cyber threat activity documented across multiple countries
Required Response: Hunt for compromise, isolate affected systems, harden exposed services, deploy MFA, patch vulnerable systems, review email and Active Directory activity, strengthen network segmentation and monitor for data exfiltration
A newly released multinational cybersecurity advisory provides one of the clearest technical pictures to date of how China government-linked cyber actors are combining automation, botnets, vulnerability exploitation and direct hands-on intrusion techniques to penetrate organizations and steal sensitive information.
The October 8 advisory was jointly issued by the FBI, Cybersecurity and Infrastructure Security Agency, National Security Agency, United Kingdom National Cyber Security Centre, Australian Signals Directorate’s Australian Cyber Security Centre, Canadian Centre for Cyber Security, Japan’s National Police Agency and National Cybersecurity Office, New Zealand National Cyber Security Centre and Spain’s Centro Nacional de Inteligencia.
The report centers on Integrity Technology Group, a China-based company linked to the Chinese government that authorities say enables malicious cyber operations by supplying infrastructure, tools and technical capabilities used to compromise networks around the world.
According to the advisory, the operators combine automated vulnerability discovery with manual exploitation after identifying promising targets. Their activity has affected U.S. critical infrastructure and organizations in multiple foreign jurisdictions, creating a threat structure that begins with broad scanning and can progress into credential theft, remote access, persistence and data exfiltration.
The advisory identifies U.S. victims across Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health and Information Technology. Authorities also documented activity affecting law enforcement agencies, educational institutions, religious organizations and targets across Southeast Asia, Africa and North America.
Integrity Tech is described as a for-profit Chinese company whose personnel acquire or build cyber tools, obtain infrastructure and compromise networks. The advisory states that those services feed a wider Chinese cyber ecosystem focused on stealing sensitive information from targets around the world.
The threat activity observed by investigators overlaps with behavior publicly tracked under names including Flax Typhoon, Ethereal Panda and Red Juliett, although the advisory cautions that private cybersecurity companies and government agencies do not always group threat activity in exactly the same way.
Vulnerability Details
The campaign relies heavily on reconnaissance.
Investigators found that the operators use a wide range of publicly available scanning utilities, including BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe and wpscan. These tools can identify exposed services, enumerate web applications, test authentication interfaces and reveal vulnerable systems suitable for later exploitation.
The actors were observed concentrating scans against commonly exposed network services, including FTP on port 21, SSH on port 22, DNS on port 53, HTTP on port 80, HTTPS on port 443 and SOCKS on port 1080. Web scanning also targeted PHP and ASP.NET pages in an effort to identify exploitable applications.
A central component of the operation is a tool known as MicroScan.
Authorities say MicroScan has been used since at least 2017. The Python-based web application contains more than 1,300 penetration-testing scripts designed to scan websites for specific vulnerabilities affecting technologies including OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins and Apache Struts.
The advisory identifies eight CVEs associated with observed exploitation activity: CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199 and CVE-2023-22894.
The operation does not stop at automated reconnaissance.
Since at least January 2021, authorities say the actors have gained access to victim environments using command-line exploit tools written in Python and Go, along with JavaScript and HTML used to conduct cross-site scripting attacks.
One recovered XSS payload was designed to alter a compromised web page so that victims would see username and password fields. Credentials entered into that page could then be harvested by the attackers.
Investigators also recovered malicious code that delivered an executable called live700_v1.exe. Once launched, the malware started a process named DiagTrack.exe, imitating the name of legitimate Windows software, and established encrypted communications with infrastructure attributed by the FBI to Integrity Tech.
Analysis showed the program contained functions capable of querying user mailboxes, leading investigators to assess that it was likely designed to steal email data.
Another tool identified in the operation is EBurst, an open-source Python utility used against Microsoft Office 365 and Exchange environments.
EBurst can conduct password spraying and password guessing across multiple Microsoft interfaces, including Exchange Control Panel, Exchange Web Services, Offline Address Book, Outlook Web Access, Remote Procedure Call, APIs, MAPI, PowerShell, Autodiscover and Microsoft-Server-ActiveSync.
Persistence and Remote Access
Once inside a network, the operators frequently install legitimate VPN software to maintain persistence and obscure their command-and-control traffic.
The advisory identifies SoftEther as one of the primary tools used for this purpose.
Attackers downloaded SoftEther installers through PowerShell on Windows systems or curl and wget on Linux and Unix systems. They then configured the VPN client to reconnect automatically during startup.
To reduce the likelihood of detection, installers were sometimes renamed conhost.exe or dllhost.exe, names associated with legitimate Windows executables. Because SoftEther itself is legitimate software, conventional endpoint-security products may not immediately treat its presence as malicious.
This creates a significant defensive challenge. A legitimate remote-access product can become a persistence mechanism when installed by an attacker, giving the operator continued access without relying exclusively on obvious malware.
The advisory identifies multiple domains associated with observed SoftEther activity, including 98aiblog[.]com, hmbcloud[.]com, hmbcloud[.]net, hmbiplc-01[.]com, iepl.node[.]cm, javacheck.ooguy[.]com, javaupdate.giize[.]com, sexytube0[.]com and twimg.co[.]uk.
Collection and Data Theft
Once persistent access is established, the operation shifts toward collection.
The FBI observed attackers downloading databases and manually extracting information from compromised email environments. Stolen data was sometimes staged under filenames intended to reduce suspicion, including names ending in .gif, .png and .js even when the underlying data was not an ordinary image or JavaScript file.
One tool, identified as Curlc4.txt, used a PHP script to access victim email through Microsoft Exchange Web Services.
The script could retrieve emails, calendars and contacts, compress stolen messages and upload them to remote infrastructure. Investigators observed the tool encrypting email archives with RC4 or AES-128-CBC in some cases before exfiltration.
The operators also used DC.exe to execute the DCSync technique against Microsoft Active Directory.
DCSync can allow an attacker with sufficient access to imitate domain-controller replication activity and obtain highly sensitive information from Active Directory, including account credentials, group membership data and trust relationships.
The advisory states that DC.exe communicated directly with victim domain controllers and retrieved information associated with Active Directory security and replication structures.
That level of access can transform an individual server compromise into a broader domain-level intrusion because Active Directory sits at the center of authentication and identity management inside many enterprise networks.
Investigators also recovered an archived email database showing that the operators targeted organizations across Southeast Asia, including government agencies, law enforcement organizations, healthcare systems and religious institutions.
In some cases, access to stolen data was restricted to IP addresses originating in Xiamen, China.
Another tool, office-cli, was used to continuously access Microsoft Outlook 365 accounts and automate email theft over extended periods.
The operators configured the utility using information such as client IDs, tenant IDs and secrets, allowing automated access to cloud-hosted mailboxes. The tool could save stolen email content into organized dump directories while relying on legitimate access mechanisms that could make malicious activity harder to distinguish from authorized use.
The advisory states that the operators also maintained a custom web application that allowed third parties to view stolen email content for selected accounts.
That detail points to an operational structure extending beyond collection alone. The stolen information was organized in a way that could be accessed by additional users rather than remaining solely in the hands of the original intrusion operators.
Operational Impact
The activity described in the advisory represents a layered cyber-espionage model.
Automated scanning identifies vulnerable systems at scale. Exploit tools and cross-site scripting create initial access. Password spraying attacks cloud and Exchange accounts. Legitimate VPN software establishes persistence. Active Directory tools expand credential access. Custom scripts and command-line utilities then collect and remove email and other sensitive data.
The result is a cyber operation capable of moving from broad internet reconnaissance to targeted theft without relying on a single malware family or vulnerability.
That architecture also creates defensive blind spots.
Some components of the operation are openly available security tools. Others are legitimate remote-access products. Some activity relies on normal Microsoft authentication and email interfaces. Those methods can reduce the effectiveness of defenses built only around identifying known malware signatures.
International Response
The advisory was produced from technical evidence recovered during multiple FBI investigations into Integrity Technology Group and related threat activity.
U.S., British, Australian, Canadian, Japanese, New Zealand and Spanish cyber and law-enforcement agencies jointly issued the document to give network defenders a consolidated set of tactics, techniques, procedures and indicators of compromise.
The publication follows the Justice Department and FBI’s separate seizure of cyber infrastructure tied to Integrity Tech and tools including Microscan and FishHub, adding a detailed defensive counterpart to the government’s law-enforcement disruption activity.
The combined approach demonstrates two distinct parts of the U.S. response: taking infrastructure away from alleged operators when legal authority permits it and providing defenders with technical information needed to locate remaining compromises.
Defensive Guidance
The advisory directs organizations to begin with basic attack-surface reduction: disable unused network services and ports, remove unnecessary remote-access and file-sharing capabilities and reduce the information exposed by publicly accessible applications.
Organizations are also urged to sanitize user input in web applications to reduce cross-site scripting risk and deploy identity, credential and access-management controls throughout their environments.
Multifactor authentication should be required wherever practical, particularly for webmail, VPN access and accounts connected to critical systems.
Default passwords should be eliminated, administrative privileges should be tightly restricted and access rights should be reviewed regularly under the principle of least privilege.
Network segmentation is another central recommendation because a compromised endpoint should not automatically provide an attacker with access to sensitive resources elsewhere in the organization.
Defenders are also advised to monitor cloud accounts for unfamiliar applications with access to email or files, review web-application logs for exploitation attempts, apply security patches promptly and replace end-of-life technology that no longer receives vendor support.
Monitoring should include unusually high inbound scanning activity, abnormal outbound traffic, unexpected IP addresses or ports appearing in command lines and firewall logs, suspicious account activity outside normal working hours and impossible-travel login patterns.
Organizations should maintain multiple protected backups of critical data, with offline copies that cannot be modified or deleted from compromised production systems.
Security-awareness training and regular penetration testing are also recommended to determine whether controls can detect the same techniques documented in the advisory.
TRJ VERDICT
The October 8 advisory expands the picture of Integrity Technology Group-linked cyber activity far beyond a single hacking tool or botnet. The operation documented by investigators combines large-scale automated discovery with targeted hands-on intrusion activity, creating a system capable of identifying vulnerable networks, exploiting them, maintaining access and extracting selected information over extended periods.
The threat is significant because the same infrastructure and operating model can reach government agencies, critical infrastructure providers, manufacturers, hospitals, universities, law-enforcement organizations and cloud-based email systems without requiring the attackers to rebuild their methods for every target.
The advisory makes one point especially clear: malware detection alone is not enough. Defending against this class of state-linked cyber operation requires attention to exposed services, identity security, Active Directory behavior, cloud-account permissions, remote-access software, network segmentation, email activity and outbound data movement.
The tools may change. The vulnerabilities may change. The objective remains the same: gain access, maintain persistence, identify valuable information and remove it without detection.
FBI, CISA, NSA and international cybersecurity partners — Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data, Joint Cybersecurity Advisory AA26-281A, published October 8, 2026. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



