FBI Warns China-Linked Hackers Ran Portal for Stolen Emails

Article Highlights
Off On

Operating through the sanctioned Integrity Technology Group, attackers deployed a scanning tool featuring over thirteen hundred scripts to identify vulnerabilities in global network infrastructures. This ongoing operation, recently exposed by a multi-national coalition led by the FBI, has targeted a diverse array of sectors including government organizations, law enforcement agencies, healthcare systems, and religious institutions. While the activity has roots in previous years, the current campaign observed throughout 2026 demonstrates an alarming level of technical maturity and a persistent focus on Southeast Asia, Africa, and North America. The hackers have not only focused on traditional espionage but have also established a sophisticated web-based application that provides third-party access to stolen email content. This indicates a commercial or cooperative model where the fruits of their cyber intrusions are shared with or sold to other unidentified entities, further complicating the global threat landscape.

The collaborative advisory, which includes contributions from seven different countries, describes a threat actor that is both for-profit and government-linked. This duality allows the group to maintain a high level of infrastructure while pursuing targets that align with state interests. By the mid-point of 2026, the sheer volume of hijacked devices and compromised accounts has necessitated a massive coordinated response. Security researchers have noted that the group’s Chairman has previously admitted to performing reconnaissance for security agencies, cementing the link between private corporate operations and state-sponsored intelligence gathering. The use of over a thousand scripts for scanning ensures that no common vulnerability is overlooked, allowing the attackers to maintain a constant stream of new victims across various industries and geographic regions.

1. Comprehensive Scope: The Global Impact of Stolen Communications

The geographical and sectoral reach of this hacking campaign is particularly broad, encompassing everything from critical manufacturing in North America to healthcare systems in Africa. Investigators found that the group, often tracked by industry names such as Flax Typhoon or RedJuliett, has been actively breaking into networks with a focus on collecting sensitive communications. By compromising law enforcement and education sectors, the attackers gain access to sensitive personal data and internal policy discussions. In Southeast Asia, the focus has been notably intense, with religious organizations and governmental bodies frequently finding their email servers under siege. This widespread targeting suggests a strategy of gathering broad intelligence that can be filtered and utilized for a variety of strategic or financial purposes by third-party users of their stolen data portal.

The disruption of a massive botnet in late 2024, known as Raptor Train, provided the initial evidence needed to dismantle the group’s wider infrastructure. This network once consisted of over 200,000 compromised devices, including consumer routers and cameras, which served as a staging ground for the hackers’ activities. Even after the botnet’s disruption, the threat actors shifted their focus toward more direct exploitation of web applications and network services. The sanctioned status of Integrity Technology Group by both the United States and the United Kingdom in 2025 has not deterred their operations. Instead, they have refined their methods, continuing to leverage automated tools to identify and exploit weaknesses in global network defenses throughout 2026, showing a resilient operational capacity that continues to challenge international cybersecurity norms.

2. Vulnerability Assessment: Probing and Automated Exploitation

The attackers utilize a sophisticated initial access strategy that begins with wide-scale scanning for network flaws. Using common open-source tools such as Nmap, masscan, and WPScan, they systematically probe ports 21, 22, 53, 80, 443, and 1080. This approach allows them to identify vulnerable services across the internet with minimal effort. However, their most potent weapon is a custom Python-based application called MicroScan. Since the beginning of 2026, this tool has been observed using over 1,300 penetration testing scripts to target specific vulnerabilities in services like OpenSSL, Oracle WebLogic, and WordPress. The automation provided by these scripts allows the group to strike quickly once a flaw is identified, often before organizations have the opportunity to apply necessary security patches.

Specific vulnerabilities targeted by this group include high-profile flaws such as CVE-2021-22205 in GitLab and CVE-2023-22894 in Strapi. The hackers also exploit legacy issues like the GNU Bash “Shellshock” flaw and vulnerabilities in Apache Struts and Pulse Connect Secure. By focusing on a mix of modern and older vulnerabilities, the threat actors ensure they can compromise a wide variety of targets, from high-tech firms to organizations still running legacy hardware. Furthermore, the use of AI-driven automated scanning, as noted by the UK’s National Cyber Security Centre, represents a significant leap in their ability to conduct reconnaissance at scale. This automated approach reduces the time between the discovery of a vulnerability and the actual breach, making rapid patch management a critical requirement for any organization hoping to remain secure.

3. Establishing Persistence: Tactics for Network Domination

Once an initial foothold is established, the threat actors prioritize maintaining long-term access to the victim’s environment. They frequently deploy SoftEther VPN, a legitimate and highly capable VPN software, which they rename to mimic standard Windows system files like conhost.exe or dllhost.exe. This masquerading technique helps the malicious software evade detection by basic antivirus programs and system monitors. By configuring the VPN client to reconnect automatically upon system startup, the hackers ensure a persistent bridge back into the network, even if specific user sessions are terminated. This reliable access allows them to move laterally within the network at their leisure, searching for high-value assets such as domain controllers or sensitive database servers.

Credential harvesting is another core component of their persistence strategy. The group utilizes a tool named EBurst to perform password spraying attacks against Microsoft 365 and Exchange accounts. Instead of brute-forcing a single account, they try a handful of common passwords across many different accounts to avoid triggering lockout policies. Once they obtain valid credentials, they can bypass traditional security perimeters and access email accounts directly through various Exchange interfaces. In more advanced stages of an intrusion, the group uses a tool called DC.exe to execute DCSync attacks, allowing them to impersonate a domain controller and request account password hashes from the Active Directory, effectively giving them the “keys to the kingdom” and allowing for the creation of unauthorized accounts.

4. Data Exfiltration: The Infrastructure of Systematic Theft

The ultimate goal of these intrusions is the systematic exfiltration of sensitive data, with a primary focus on email communications. To facilitate this, the threat actors developed a specialized PHP-based bot known as Curlc4.txt, designed to interface directly with Exchange Web Services to collect mailboxes, calendars, and contact lists. The data is then compressed, and in many cases encrypted, before being uploaded to a remote command-and-control server. Another tool in their arsenal, a command-line utility called office-cli, allows the attackers to repeatedly return to Microsoft 365 environments to harvest mail from specific time periods. This ensures that they maintain a current stream of intelligence from their victims rather than just a single snapshot of data.

To manage and distribute this stolen information, the group operates a web application that acts as a portal for third parties, allowing users to view the contents of specific stolen email accounts simply by modifying arguments within a URL. The FBI has observed that access to this stolen data is sometimes restricted to specific IP addresses in Xiamen, China, suggesting a controlled distribution network. This commercialization of stolen intelligence represents a significant shift in the threat actor’s business model, suggesting they are a provider of intelligence-as-a-service. It suggests that the Integrity Technology Group is not just a group of hackers, but a provider of intelligence-as-a-service, where the privacy of global organizations is commodified for the benefit of state actors and other paying or authorized third-party entities.

5. Tactical Defensive Measures: Eight Steps to Secure Critical Assets

Defenders must adopt a rigorous and structured approach to mitigate the risks posed by these sophisticated threat actors. The advisory emphasizes that network hardening is not a one-time event but a continuous process of refinement. To effectively protect against the methods used by Integrity Technology Group, security teams are encouraged to follow these specific steps:

  1. Disable unnecessary features: Shut down any ports or services that are not in use, particularly those involving file sharing or remote access.
  2. Cleanse web inputs: Implement strict input sanitization in web apps to prevent cross-site scripting (XSS) attacks.
  3. Mandate multifactor authentication (MFA) for all users, focusing heavily on VPNs and email platforms.
  4. Monitor directory traffic: Keep a close watch for unauthorized Active Directory replication, which may indicate a DCSync attack.
  5. Audit cloud permissions: Regularly inspect cloud environments for third-party applications that have been granted access to read emails or files.
  6. Analyze server records: Scrutinize web application logs for any signs of attempted exploits or unusual patterns.
  7. Update software immediately: Prioritize patching the eight specific vulnerabilities identified in the report.
  8. Retire legacy systems: Phase out and replace hardware or software that is no longer supported by the manufacturer.

Each of these steps addresses a specific stage of the attack lifecycle observed throughout 2026. For instance, sanitizing web inputs directly counters the group’s use of XSS payloads to trick users into downloading malware. Similarly, auditing cloud permissions is vital because the group’s use of office-cli relies on legitimate access methods that often bypass standard alerts. By systematically closing these avenues of attack, organizations can significantly raise the cost of entry for the hackers, forcing them to seek easier targets elsewhere. Continuous monitoring of Active Directory is particularly critical, as it remains one of the group’s favorite methods for achieving total network control once they have bypassed the initial perimeter defenses.

6. Incident Response: Five Procedures for Rapid Mitigation

In the event that an organization detects signs of a potential compromise, such as unusual outbound traffic to known malicious domains or the presence of renamed VPN installers, a swift and organized response is essential. Moving too quickly to delete files can alert the attackers and cause them to destroy evidence or move to a more hidden part of the network. Instead, the following five procedures should be followed to ensure a complete and effective recovery:

  1. Quarantine impacted systems: Immediately disconnect and isolate any hosts showing signs of infection.
  2. Conduct a forensic search: Investigate the network to determine the full scale and depth of the intrusion.
  3. Notify authorities: Report the incident to the appropriate national law enforcement or cybersecurity agencies.
  4. Evict the attackers: Remove the threat actors from the system only after sufficient investigative data has been gathered.
  5. Strengthen network defenses: Perform a comprehensive hardening of the environment to prevent future re-entry.

The forensic search phase is vital because it allows the security team to understand how the attackers got in and what they touched. Without this information, the eviction process may be incomplete, leaving the door open for the group to return using a secondary backdoor or stolen credentials that were not changed. Notifying national authorities is also a crucial step, as the data gathered from individual breaches helps agencies like the FBI build a more complete picture of the threat actor’s global infrastructure. Once the eviction is complete, the focus must shift to hardening the environment. This includes resetting all administrative passwords, rotating secrets for cloud applications, and implementing the defensive protocols mentioned in the previous section to ensure the network is more resilient than it was before the breach.

7. Strategic Resilience: Future Outlook and Actionable Steps

The persistence of the Integrity Technology Group serves as a stark reminder that cyber threats in 2026 are increasingly characterized by high levels of automation and corporate-style organization. Organizations must move beyond reactive patching and adopt a posture of continuous vigilance. This includes not only technical defenses but also employee training to recognize the deceptive tactics, such as fake login pages, that often serve as the initial point of entry. The discovery of the stolen email portal highlights the reality that data theft is often just the beginning of a longer chain of exploitation where the stolen information is used for further intelligence operations or secondary attacks against partner organizations.

In the final assessment of this campaign, security teams successfully identified the core tools and infrastructure used by the attackers, which allowed for a more coordinated global response. They recommended that all system administrators review the provided indicators of compromise and check their logs for any historical activity matching the group’s patterns. By implementing multifactor authentication and retiring legacy systems, many organizations effectively closed the most common gaps utilized by the threat actors. The collaborative efforts between international law enforcement and the private sector proved essential in disrupting the group’s command-and-control structures, providing a roadmap for future defense against similar state-linked for-profit entities. Moving forward, the focus remained on proactive threat hunting and the rapid sharing of intelligence to stay ahead of evolving exploitation techniques.

Explore more

Will Lower Payroll Taxes Help Solve Youth Unemployment?

The transition from a classroom desk to a professional office chair has become an increasingly treacherous journey for hundreds of thousands of young adults across the United Kingdom. With youth unemployment figures hovering around 750,000 individuals, the disconnect between academic achievement and labor market stability has reached a critical juncture. This roundup examines the proposed fiscal strategies aimed at reversing

The Evolution of Revenue Operations via the CRO AI Framework

The effectiveness of an AI agent is fundamentally limited by the quality and connectivity of the data sources it is permitted to access. In the current enterprise sales environment of 2026, Chief Revenue Officers are no longer content with speculative pilot programs or isolated productivity tools that offer only marginal gains. Instead, there is a decisive move toward a comprehensive,

Cisco Transforms Webex with New Collaborative AI Agents

Digital collaboration has evolved from a utility for remote communication into a sophisticated ecosystem where artificial intelligence acts as a catalyst for deep organizational change. Cisco has recently pivoted the Webex platform toward “agentic” AI, signaling a fundamental move from simple, reactive chatbots to fully integrated digital colleagues. This transition is not merely a cosmetic update; it represents a strategic

Why Should HR Lead Your Agentic AI Talent Strategy?

When AI agents begin handling prospecting and data research, human representatives must be strategically redeployed into areas that prioritize relationship-building and strategic growth. This fundamental shift marks a departure from traditional automation, where software merely served as a static tool for human operators. In the current landscape of 2026, agentic Artificial Intelligence has evolved into a category of autonomous entities

How Will Google Cloud Modernize Simplify AI-Driven Migration?

The sheer scale of technical debt currently burdening global enterprises has reached a staggering tipping point where traditional migration methods simply cannot keep pace with the urgent demand for agility. The transition toward cloud computing has entered a sophisticated phase where simple “lift-and-shift” maneuvers no longer satisfy the complex requirements of modern business operations. Google Cloud recently introduced Google Cloud