Full Report
Joint advisory with international partners highlights malicious targeting of organisations from a range of sectors across the globe.
Analysis Summary
# Threat Actor: Integrity Technology Group (Integrity Tech)
## Attribution & Identity
* **Actor Identification:** Integrity Technology Group (Integrity Tech), a China-based technology company with links to the Chinese Government.
* **Aliases:** The activity enabled by this group is consistent with campaigns known as **Flax Typhoon**, **Ethereal Panda**, and **Red Juliett**.
* **Known Associations:** Linked to the wider Chinese cyber ecosystem; operates as a facilitator for Advanced Persistent Threat (APT) groups, specifically Flax Typhoon.
## Activity Summary
Integrity Tech operates as a provider of malicious cyber services, employing individuals who develop tools, acquire hosting infrastructure, and manage large-scale botnets. Their recent operations involve the exploitation of networks globally to steal confidential and sensitive data. The group is noted for enabling "hands-on" exploitation following automated discovery phases.
## Tactics, Techniques & Procedures
* **AI-Enabled Tools:** Use of artificial intelligence for automated scanning and vulnerability discovery to identify targets at scale.
* **Botnet Operations:** Management of a substantial botnet consisting of thousands of infected internet-connected devices (IoT, etc.) used to mask origin and facilitate attacks.
* **Manual Exploitation:** Transition from automated tools to "hands-on" manual techniques to navigate compromised networks and exfiltrate data.
* **Tool Development:** Development and sale of exploit tools within the Chinese cyber ecosystem.
* **Infrastructure Hosting:** Acquiring and managing covert infrastructure to support global malicious campaigns.
## Targeting
* **Sectors:** Critical sectors, government, and a wide range of commercial organizations.
* **Geography:** Global targeting, with specific mentions of the UK and its international allies (US, Australia, Canada, Japan, New Zealand, and Spain).
* **Victims:** Sensitive data-holding organizations across multiple continents.
## Tools & Infrastructure
* **Malware Families:** Mention of botnet malware used to infect internet-connected devices (specific family names not listed in the summary, but associated with Flax Typhoon activity).
* **Infrastructure:**
* Large-scale botnets of compromised devices.
* Covert networks designed to obfuscate actor location.
* *Note: Specific IPs/URLs are contained in the full FBI/NCSC technical advisory linked in the article (e.g., hxxps[:]//www[.]ic3[.]gov/CSA/2026/261008[.]pdf).*
## Implications
The use of AI-enabled scanning combined with commercial-style "cyber-for-hire" ecosystems (like Integrity Tech) significantly lowers the barrier for large-scale exploitation. This represents a strategic shift where state-linked entities provide the infrastructure and initial access that multiple APT groups can leverage, increasing the volume and speed of global espionage campaigns.
## Mitigations
* **Strengthen Cyber Resilience:** Implement robust patch management to defend against the automated scanning of known vulnerabilities.
* **Botnet Defense:** Monitor for traffic to/from known botnet C2 nodes and secure IoT/internet-facing devices to prevent them from being recruited into botnets.
* **Network Defense:** Engage with NCSC and international partner guidance regarding "covert networks" and "living off the land" techniques.
* **Monitoring:** Implement enhanced logging and monitoring to detect manual, "hands-on" lateral movement after an initial breach.