On October 8, the FBI, along with agencies from six other countries, revealed that hackers linked to a Chinese cybersecurity firm infiltrated email systems of various organizations in Southeast Asia. The firm, Integrity Technology Group, has been sanctioned by the U.S. and the UK for its involvement in these cyber activities.
Email Systems Compromised
Utilizing a toolkit of over 1,300 scripts, the hackers scanned various websites for vulnerabilities. They succeeded in breaching Microsoft 365 and Exchange accounts, enabling them to extract emails from affected systems. The advisory highlights that these cyber incursions have been ongoing since at least January 2021, with numerous organizations, including U.S. government and law enforcement agencies, being targeted.
The advisory also notes that the hackers operated a web application that facilitated third-party access to stolen email content, although details about these third parties remain undisclosed.
Sanctions and Cyber Attacks
In response to these activities, Integrity Technology Group was sanctioned in early 2025 by the U.S. Treasury and later by the UK. Despite these measures, the company denies any wrongdoing, asserting that the sanctions lack factual basis. The FBI’s 2024 disruption of a botnet, controlled by the same group, was part of ongoing efforts to curb their cyber operations.
The advisory identifies the hackers’ methods as consistent with those tracked by security firms under names like Flax Typhoon and RedJuliett, suggesting a broad operational scope beyond just Integrity Technology Group.
Methods of Infiltration
Hackers exploited known vulnerabilities in web applications, often using open-source scanning tools like Nmap and WPScan. Their focus included critical network ports and widely used services susceptible to attack. A significant portion of their efforts relied on password spraying and exploiting command-line tools to gain unauthorized access.
To maintain access, they installed legitimate software such as SoftEther VPN, which helped them avoid detection. Their sophisticated approach also involved leveraging tools to extract credentials and email content, subsequently uploading this data to remote servers for further misuse.
Defense Recommendations
The advisory underscores the importance of bolstering network defenses. Recommendations include disabling unnecessary services, implementing multifactor authentication, and routinely checking for unauthorized access or unusual activities. Applying security patches and replacing outdated software are essential steps to prevent similar breaches.
For organizations suspecting compromise, isolating affected systems and conducting thorough investigations are critical measures. The advisory provides a comprehensive list of indicators of compromise to aid in these efforts, enabling organizations to better safeguard against such sophisticated cyber threats.
