Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Hackers Exploited Flaws for Email Theft: FBI

Chinese Hackers Exploited Flaws for Email Theft: FBI

Posted on October 8, 2026 By CWS

On October 8, the FBI, along with agencies from six other countries, revealed that hackers linked to a Chinese cybersecurity firm infiltrated email systems of various organizations in Southeast Asia. The firm, Integrity Technology Group, has been sanctioned by the U.S. and the UK for its involvement in these cyber activities.

Email Systems Compromised

Utilizing a toolkit of over 1,300 scripts, the hackers scanned various websites for vulnerabilities. They succeeded in breaching Microsoft 365 and Exchange accounts, enabling them to extract emails from affected systems. The advisory highlights that these cyber incursions have been ongoing since at least January 2021, with numerous organizations, including U.S. government and law enforcement agencies, being targeted.

The advisory also notes that the hackers operated a web application that facilitated third-party access to stolen email content, although details about these third parties remain undisclosed.

Sanctions and Cyber Attacks

In response to these activities, Integrity Technology Group was sanctioned in early 2025 by the U.S. Treasury and later by the UK. Despite these measures, the company denies any wrongdoing, asserting that the sanctions lack factual basis. The FBI’s 2024 disruption of a botnet, controlled by the same group, was part of ongoing efforts to curb their cyber operations.

The advisory identifies the hackers’ methods as consistent with those tracked by security firms under names like Flax Typhoon and RedJuliett, suggesting a broad operational scope beyond just Integrity Technology Group.

Methods of Infiltration

Hackers exploited known vulnerabilities in web applications, often using open-source scanning tools like Nmap and WPScan. Their focus included critical network ports and widely used services susceptible to attack. A significant portion of their efforts relied on password spraying and exploiting command-line tools to gain unauthorized access.

To maintain access, they installed legitimate software such as SoftEther VPN, which helped them avoid detection. Their sophisticated approach also involved leveraging tools to extract credentials and email content, subsequently uploading this data to remote servers for further misuse.

Defense Recommendations

The advisory underscores the importance of bolstering network defenses. Recommendations include disabling unnecessary services, implementing multifactor authentication, and routinely checking for unauthorized access or unusual activities. Applying security patches and replacing outdated software are essential steps to prevent similar breaches.

For organizations suspecting compromise, isolating affected systems and conducting thorough investigations are critical measures. The advisory provides a comprehensive list of indicators of compromise to aid in these efforts, enabling organizations to better safeguard against such sophisticated cyber threats.

The Hacker News Tags:Chinese hackers, cyber threats, Cybersecurity, email theft, Exchange, FBI, hacking methods, Integrity Technology Group, Microsoft 365, network security

Post navigation

Previous Post: VirusTotal API Keys Allegedly Sold on Dark Web
Next Post: Tensorlake npm Package Exploited to Spread Malware

Related Posts

Agentic AI: Emerging Security Challenges Explained Agentic AI: Emerging Security Challenges Explained The Hacker News
Accelerating Exploit Timelines Challenge Defenders Accelerating Exploit Timelines Challenge Defenders The Hacker News
Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware Fake Moltbot AI Coding Assistant on VS Code Marketplace Drops Malware The Hacker News
AI Aids Researchers in Transferring RCE Exploit Across PLC Models AI Aids Researchers in Transferring RCE Exploit Across PLC Models The Hacker News
30,000 Facebook Accounts Hacked in Phishing Scam 30,000 Facebook Accounts Hacked in Phishing Scam The Hacker News
Understand Your Real Attack Surface in 45 Days Understand Your Real Attack Surface in 45 Days The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Tensorlake npm Package Exploited to Spread Malware
  • Chinese Hackers Exploited Flaws for Email Theft: FBI
  • VirusTotal API Keys Allegedly Sold on Dark Web
  • Fortinet Devices Targeted by FortiBleed Attackers
  • Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Tensorlake npm Package Exploited to Spread Malware
  • Chinese Hackers Exploited Flaws for Email Theft: FBI
  • VirusTotal API Keys Allegedly Sold on Dark Web
  • Fortinet Devices Targeted by FortiBleed Attackers
  • Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark