Skip to main content
Emerging ThreatsMalware & Ransomware

China-Linked Hackers Expose Email Portal With Stolen Data

Rows of computer servers and equipment with a monitor displaying a blurred screen.

"a China-based for-profit company with links to the Chinese government," the agencies' joint advisory said — a phrase that frames a sprawling account of email theft, botnets and an online portal that gave third parties access to stolen mail.

The accused company and the web portal

The advisory identifies Integrity Technology Group as the commercial operator tied to the activity it describes. The U.S. Treasury sanctioned the company in January 2025 and the UK followed with sanctions in December 2025. The same advisory says the hackers run a web application that "provides third-party access to stolen email content," and notes that users of that application can view the mail of a specific account by adding arguments to a URL. The advisory does not name those third parties.

Tactics and tools used to break in

The agencies describe a toolbox and workflow built largely from open-source scanners and command-line exploit code. The actors scan for flaws with Nmap, masscan and WPScan and focus their scans on ports 21, 22, 53, 80, 443 and 1080. They have used a Python web application called MicroScan, containing more than 1,300 penetration‑testing scripts, against services such as OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins and Apache Struts.

For password attacks they use EBurst, an open‑source Python tool that performs password spraying against Microsoft 365 and Exchange accounts. EBurst targets Exchange interfaces including ECP, EWS, OAB, OWA, RPC, API, MAPI, PowerShell, Autodiscover and Microsoft‑Server‑ActiveSync, the advisory notes.

The advisory lists eight known flaws the actors successfully exploited; five of those were newly added to the Known Exploited Vulnerabilities (KEV) catalog, according to the document. Two flaws depend on configuration: an Apache Struts issue that works only when Dynamic Method Invocation is enabled, and an ONLYOFFICE flaw that applies when JWT is used. A separate BIND flaw in the list causes the DNS server to exit (a denial‑of‑service impact).

How stolen mail was collected and shared

Once inside, the actors use a mixture of covert persistence and direct harvesting. They install SoftEther VPN software — sometimes renaming installers to conhost.exe or dllhost.exe — and configure it to reconnect at startup. To harvest credentials from Active Directory they ran a tool named DC.exe that leverages DCSync to copy account credentials, group membership and trust relationships.

For email collection the advisory details two primary tools. A PHP script named Curlc4.txt acts as a bot that collects mail through Exchange Web Services (EWS), compresses and sometimes encrypts it, and uploads it to a server; its main command‑and‑control domain was natcloudservice[.]com. A second tool, office‑cli, repeatedly accesses Microsoft 365 accounts using configuration files holding client ID, tenant ID and secret, and "avoids detection by using legitimate access methods," the agencies said. The FBI also observed manual downloading of databases and hand‑exfiltration of email.

The FBI recovered a cross‑site scripting (XSS) payload used to present a fake login that drops a password‑protected ZIP containing live700_v1.exe. That program starts a process named DiagTrack.exe and sends encrypted traffic to dns.studiocloud[.]xyz; the FBI attributes that domain to Integrity Technology Group and assesses the malware likely targets email. In some compromises the advisory says the actors limited access to stolen data to IP addresses in Xiamen, China.

Connections to the 2024 botnet disruption and indicators

The advisory builds on prior disruption of a botnet the Justice Department and FBI tied to Integrity Technology Group in September 2024. That botnet held more than 200,000 routers, cameras and other consumer devices and was identified by Lumen researchers as Raptor Train. The 2024 action targeted the botnet; the current advisory focuses on intrusion techniques and theft. The document contains 39 pages of indicators of compromise (IOCs) — domains, IP addresses and file hashes — some dating back as far as 2016. Ten IPs in the IOC list also appeared in the September 2024 botnet advisory, although the "last seen" dates differ between the two lists.

What the agencies tell defenders to do

  • Turn off unused services and ports such as remote access and file sharing.
  • Sanitize user input in web applications to block XSS.
  • Require multifactor authentication (MFA), especially for webmail, VPNs and accounts with access to critical systems.
  • Watch for unexpected Active Directory replication (a hallmark of DCSync activity).
  • Check cloud accounts for connected applications that can read files and email, and review web application logs for attack attempts.
  • Apply patches for the eight flaws listed in the advisory and replace products that no longer receive updates.
  • For suspected compromise: isolate affected hosts, conduct thorough hunting to determine scope, report under national rules, and remove the actors only after adequate hunting data has been collected.

Christopher Wray, then the FBI director, said in 2024 that the company's "chairman has publicly admitted that for years his company has collected intelligence and performed reconnaissance for Chinese government security agencies," a line the advisory echoes when describing ties between the firm and government entities. The advisory also notes that activity attributed to the actors is "consistent with" tracks security firms label Flax Typhoon, Ethereal Panda and RedJuliett, among others.

For defenders and administrators, the advisory replaces theory with a specific shopping list: the exploitable products and settings, the scanning and collection scripts, the domains and hashes. For policymakers and procurement officials, it furnishes the sanctions timeline and a link between commercial tooling and apparent third‑party access to stolen content. For affected organizations — governments, law enforcement, healthcare, education and religious institutions named in the advisory — the imperative is practical and immediate: hunt the IOCs, verify whether Active Directory replication was abused, and harden the Microsoft 365 and Exchange interfaces the actors targeted.

The advisory leaves at least one procedural question open in its own data: several IOC "last seen" dates do not align with earlier advisories, underscoring that timelines in different investigations can diverge. The document nonetheless supplies tools and specific, actionable IOCs that defenders can use now.

Original story at The Hacker News