Overview of the Joint International Advisory
A joint advisory issued by the FBI and security agencies across six countries has revealed that a China-based private contractor operated a centralized web application providing third parties with direct access to stolen email data, according to The Hacker News. The malicious activity is attributed to Integrity Technology Group, a for-profit entity sanctioned by both the United States and the United Kingdom. Operating since at least January 2021, the group targeted government organizations, law enforcement agencies, healthcare systems, and religious institutions across multiple regions, including Southeast Asia, Africa, and North America.
The operation relies on a blend of credential guessing against Microsoft 365 and Exchange environments, automated infrastructure scanning, and custom exfiltration utilities. Security researchers have linked the campaign’s tactics, techniques, and procedures (TTPs) to clusters commonly tracked under identifiers such as Flax Typhoon, Ethereal Panda, and RedJuliett.
Technical Analysis and Exploitation TTPs
The threat actors utilized both commodity open-source scanners and proprietary tooling to map networks and identify vulnerable web applications. Initial reconnaissance frequently involved the use of Nmap, masscan, and WPScan targeting common administrative and service ports including 21, 22, 53, 80, 443, and 1080.
Beyond standard network discovery, the actors deployed a custom Python-based web application known as MicroScan, which has been active since 2017. MicroScan incorporates more than 1,300 penetration testing scripts targeting a wide array of enterprise software and infrastructure components, including OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts.
In addition to software exploitation, investigators uncovered credential harvesting campaigns utilizing cross-site scripting (XSS) payloads injected into compromised web pages. These scripts modified legitimate login interfaces to prompt users for credentials, subsequently serving a password-protected archive containing a malicious executable named live700_v1.exe. This binary spawned a process mimicking the legitimate Windows diagnostic utility DiagTrack.exe to exfiltrate data over encrypted DNS channels.
Threat Actor Infrastructure and Disruption
Integrity Technology Group operates as a commercial entity closely tied to state intelligence requirements, employing individuals responsible for tool development, infrastructure hosting, and direct network intrusions. Prior to the release of the updated advisory detailing credential theft and initial access vectors, the U.S. Department of Justice disrupted a massive botnet controlled by the same firm in September 2024. Known to researchers as Raptor Train, the botnet compromised more than 200,000 consumer routers, IP cameras, and edge devices to serve as proxy infrastructure.
Despite heavy financial and diplomatic sanctions imposed by the U.S. Treasury in January 2025 and the UK in December 2025, representatives for the company have publicly rejected the allegations, claiming the measures lack factual grounding.
Actionable Mitigations for Defenders
Security teams defending enterprise networks against campaigns associated with state-sponsored commercial espionage contractors should prioritize the following defensive measures:
- Enhance Authentication Monitoring: Closely monitor Microsoft 365 and Microsoft Exchange authentication logs for anomalous concurrent logins, impossible travel indicators, and unexpected access from known proxy infrastructure.
- Harden Perimeter Applications: Conduct comprehensive asset discovery to identify exposed web applications, ensuring that software components listed in advisory scan profiles—such as Apache Struts, Oracle WebLogic, and WordPress plugins—are patched to their latest secure releases.
- Inspect Endpoint Activity: Hunt for unauthorized processes masking as legitimate system binaries, specifically scrutinizing instances where utilities such as
DiagTrack.exeinitiate outbound encrypted connections over non-standard DNS channels.
Related: Emerging Cyber Threats and Espionage Risks in Neurotechnology, Browser Attacks and EDR Blind Spots: Mitigating SaaS Threats