Full Report
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more
Analysis Summary
# Threat Actor: Integrity Technology Group
## Attribution & Identity
* **Actor Identification:** Integrity Technology Group (a China-based for-profit cybersecurity company).
* **Known Aliases:** Activity is consistent with groups tracked as **Flax Typhoon** (Microsoft), **Ethereal Panda** (CrowdStrike), and **RedJuliett** (Recorded Future).
* **Associations:** Linked to the Chinese government. The company's chairman has publicly admitted to performing reconnaissance and intelligence collection for Chinese government security agencies.
## Activity Summary
* **Duration:** Active since at least mid-January 2021; some tools (MicroScan) date back to 2017.
* **Recent Campaigns:** Operation of a massive IoT botnet (disrupted in September 2024) and large-scale email theft operations.
* **Operational Scope:** The group maintains a web application portal that provides unidentified third parties with access to stolen email content.
## Tactics, Techniques & Procedures
* **Reconnaissance & Scanning:** Uses open-source tools like **Nmap**, **masscan**, and **WPScan** to identify vulnerabilities. Specific focus on ports 21, 22, 53, 80, 443, and 1080.
* **Vulnerability Research:** Utilizes a proprietary Python-based tool called **MicroScan**, containing over 1,300 scripts to scan for flaws in OpenSSL, Oracle WebLogic Server, and Rejetto.
* **Credential Access:** Password guessing/brute-forcing against Microsoft 365 and Exchange accounts.
* **Exfiltration:** Copying entire mailboxes using specialized mail collection tools.
* **Botnet Operations:** Management of a 200,000-node botnet ("Raptor Train") consisting of hijacked routers, cameras, and consumer IoT devices to facilitate operations.
## Targeting
* **Sectors:** Government organizations, law enforcement, healthcare, religious institutions, critical manufacturing, IT organizations, and education.
* **Geography:** Southeast Asia (primary focus), North America (U.S.), Africa, and Taiwan.
* **Victims:** Specific entities are not named, but the advisory highlights broad targeting of U.S. government services and international law enforcement agencies.
## Tools & Infrastructure
* **Malware/Tools:**
* **MicroScan:** Custom Python web application for vulnerability scanning.
* **Open Source:** Nmap, masscan, WPScan.
* **Infrastructure:**
* **Raptor Train Botnet:** Over 200,000 compromised IoT devices (routers, IP cameras).
* **C2/Access Portal:** A web application used to host and distribute stolen email data to "third parties."
* **Defanged IPs/Ports:** Scanned ports 21, 22, 53, 80, 443, 1080.
## Implications
This actor represents a "cyber-mercenary" or state-sponsored contractor model where a private company provides offensive capabilities for government intelligence requirements. The existence of a dedicated portal for stolen emails suggests a highly organized, "data-as-a-service" operation, potentially allowing multiple Chinese state entities to consume intercepted communications. The group's ability to maintain a 200,000-node botnet demonstrates significant scale and technical sophistication in infrastructure obfuscation.
## Mitigations
* **Identity Security:** Implement Multi-Factor Authentication (MFA) across all Microsoft 365 and Exchange environments to thwart password-guessing attacks.
* **Vulnerability Management:** Prioritize patching for edge-facing services, specifically Oracle WebLogic and OpenSSL.
* **IoT Security:** Ensure consumer-grade devices (routers/cameras) on corporate networks are updated or segmented to prevent inclusion in botnets like Raptor Train.
* **Exposure Monitoring:** Use attack surface management tools to monitor for unauthorized scanning activity on the specific ports (21, 22, 53, etc.) favored by the actor.