Skip to main content
Threat IntelligenceEmerging Threats

UK Warns of China's Integrity Tech Cyber Threat Tactics

Modern tech company HQ with blurred computer screens and subtle global network hints in background.

"Integrity Tech employs individuals who support malicious cyber activity in different ways, including acquiring or building cyber tools for use and sale, acquiring and hosting infrastructure and compromising networks across global victims, which the authoring organizations track as China-based malicious cyber activity,” the joint advisory published on October 8 warned.

The actors named and the advisory’s scope

The advisory, issued jointly by the US, the UK and several allied countries and published on October 8, ties the activities of Integrity Technology Group (also referenced as Integrity Tech) to support for prolific Beijing‑backed groups such as Flax Typhoon (aka Ethereal Panda, Red Juliett). It says Integrity Technology Group’s work has “enabled” those groups and that its services “contribute to the larger Chinese cyber ecosystem,” specifically by helping to exfiltrate sensitive data from victims globally.

Techniques, tools and indicators described

The report lists a range of tactics, techniques and procedures (TTPs) and names multiple specific tools and artifacts. Among the technical details it highlights are:

  • Use of open source scanning tools to find vulnerabilities in networks and web‑based applications.
  • Employment of the “MicroScan” hacking tool, described as containing over 1,300 pen‑testing scripts designed to scan sites for specific flaws.
  • Initial access to networks and cloud services via command‑line utilities built on exploit code written in Python and Go.
  • Exploitation of cross‑site scripting (XSS) bugs to compromise third‑party applications.
  • Use of the EBurst tool for password spraying/guessing to compromise Microsoft 365 email accounts.
  • Persistence achieved by installing VPN clients (for example SoftEther) on victim devices to obfuscate command‑and‑control communications.
  • Staging exfiltration with different file names to minimize detection of a MySQL email dump, and creation of a bot using the PHP script Curlc4.txt to obtain emails.
  • Use of a utility called DC.exe to trick a domain controller into handing over sensitive Active Directory information, including account credentials.
  • Exfiltration of email data from both on‑premises systems and cloud‑based services, with targeted verticals identified as government, law enforcement, healthcare and religious institutions located in Southeast Asia.
  • Use of the command‑line utility office‑cli to continuously access Microsoft Outlook 365 accounts and steal emails.

Mitigations and the advisory’s practical advice for defenders

The advisory provides a large set of indicators of compromise (IoCs), additional resources, mitigations and incident responder advice. Its principal, distilled recommendations for reducing risk include:

  • Disable unused services and ports, including automatic configuration, remote access and file‑sharing protocols.
  • Sanitize user input in web applications to prevent XSS payload injection.
  • Implement identity, credential and access management (ICAM) policies and require multifactor authentication (MFA) where possible.

It also explicitly directs incident responders who think they may already be compromised to consult the listed IoCs and guidance included in the report.

Government response: domain seizures and naming of tools

Also on October 8, the US announced the seizure of several domains associated with hacking tools Microscan and FishHub in a bid to disrupt the operations of Integrity Tech and associated threat groups. The advisory and the domain actions together represent coordinated steps to both inform network defenders and degrade infrastructure tied to the described operations.

How security teams, national authorities and affected organizations are likely to respond

  • Security teams and incident responders: They will need to examine the advisory’s IoCs and the list of tools (including MicroScan, EBurst, DC.exe, office‑cli and the PHP script Curlc4.txt), prioritize detection signatures for password‑spraying and Outlook‑365 access, and consider the advisory’s guidance to disable unused services and enforce MFA.
  • National authorities and CERTs: Given the advisory’s international authorship and the announced domain seizures, these actors are likely to coordinate on sharing IoCs and on outreach to sectors identified in the report.
  • Affected organizations in Southeast Asia — government, law enforcement, healthcare and religious bodies: The advisory specifically names these verticals as targets for email exfiltration, indicating they should evaluate on‑premises and cloud email protections and review exposure to the enumerated TTPs.

NCSC director of operations Paul Chichester framed the advisory as a broad warning: “The breadth of sectors that have been targeted across the globe demonstrate the extent of the threat and all organizations should take note of this warning and engage with NCSC advice and guidance,” he said. “We will continue to call out malicious actors and the malevolent ecosystem they operate in.”

The advisory and the US domain seizures together create a clear, actionable record: named tools, specific techniques and sectoral targets that defenders can hunt for now. The record also leaves a practical question at its center — whether organizations with vulnerable Outlook‑365, on‑premises mail systems and exposed web apps have already seen the subtle staging behaviors the report describes, such as renamed MySQL dumps and persistent VPN clients that mask C2 traffic.

Original advisory: https://www.infosecurity-magazine.com/news/uk-allies-threat-china-integrity/