Integrity Tech enables China-linked cyber espionage
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
CISA and allies detail Integrity Technology Group-enabled Chinese threat actors using botnets, VPNs, and LOTL tools to steal email and AD data from critical infrastructure.
A joint advisory from CISA, FBI, NSA, and international partners (UK, Australia, Canada, Japan, New Zealand, Spain) details malicious cyber activity enabled by Integrity Technology Group, a China-based company with links to the Chinese government. The threat actors' TTPs overlap with activity publicly tracked as Flax Typhoon, Ethereal Panda, and Red Juliett. Victims span US critical infrastructure sectors including Government Services, Critical Manufacturing, Healthcare, and IT, as well as law enforcement, education, religious organizations, and targets across Southeast Asia, Africa, and North America.
The actors combine open-source reconnaissance tools (BBScan, Fscan, masscan, NMAP, dirsearch, wpscan, OneForAll, ShuiZe, ksubdomain) and a custom Python-based scanner called MicroScan (1,300+ penetration-testing scripts targeting OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins, Apache Struts) for initial vulnerability discovery. Initial access leverages exploit code in Python/Go, XSS payloads for credential harvesting leading to deployment of live700_v1.exe (masquerading as DiagTrack.exe, communicating with dns.studiocloud.xyz), and EBurst for password spraying/guessing against Microsoft Exchange/O365 interfaces (ECP, EWS, OWA, RPC, MAPI, PowerShell, Autodiscover, ActiveSync). For persistence, actors install SoftEther VPN clients (disguised as conhost.exe/dllhost.exe) to obscure C2 traffic, observed connecting through domains including 98aiblog.com, hmbcloud.com/net, hmbiplc-01.com, iepl.node.cm, javacheck.ooguy.com, javaupdate.giize.com, sexytube0.com, and twimg.co.uk. Collection/exfiltration tools include a PHP-based EWS bot (Curlc4.txt) communicating with natcloudservice.com (C2 at 149.28.132.137) that encrypts stolen emails with RC4 or AES-128-CBC, DC.exe for DCSync-based Active Directory credential dumping, and office-cli for automated, legitimate-looking O365 mailbox exfiltration. Some exfiltrated data access was restricted to IP ranges in Xiamen, China.
The advisory provides extensive IOC tables (domains, webshells, binaries, scripts) and MITRE ATT&CK mappings, along with detailed mitigation guidance emphasizing MFA, network segmentation, LOTL/AD replication monitoring, patch management, and protective DNS. Defenders should treat this as a mature, persistent espionage capability-for-hire operation rather than a single campaign, given activity dating back to at least 2016-2017 and ongoing use of commodity and custom tooling against government, healthcare, manufacturing, and IT targets globally.
Mentioned in this report
Detection guidance
DCSync Replication Rights Used by Non-Machine Account
Detects directory replication (DS-Replication-Get-Changes/-All) access by a non-computer account, indicating DCSync-style credential dumping such as DC.exe. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: DCSync Replication Rights Used by Non-Machine Account
description: Detects Security 4662 events where directory replication extended rights
are exercised by a user account rather than a domain controller machine account
- DCSync credential dumping (e.g. DC.exe, mimikatz lsadump::dcsync). Requires Directory
Service Access auditing on the domain object.
tags:
- attack.credential-access
- attack.t1003.006
logsource:
product: windows
service: security
detection:
selection:
EventID: 4662
AccessMask: '0x100'
Properties|contains:
- 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2
- 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2
- 89e95b76-444d-4c62-991a-0facbeda640c
filter_machine_accounts:
SubjectUserName|endswith: $
condition: selection and not filter_machine_accounts
falsepositives:
- Azure AD Connect or similar directory sync service accounts that legitimately hold
replication rights
- Identity or backup products that replicate AD using a dedicated service account
level: high
id: bb637bbd-141c-56a0-b067-1e2e632cc8ed
status: experimental
author: Vorant
references:
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
conhost.exe or dllhost.exe Executed Outside System Directories
Detects conhost.exe/dllhost.exe running from non-system paths, matching the SoftEther VPN client disguised as these binaries for C2 tunnelling. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: conhost.exe or dllhost.exe Executed Outside System Directories
description: Detects processes named conhost.exe or dllhost.exe launched from outside
the Windows system directories. The actors disguised SoftEther VPN clients as these
binaries to obscure C2 traffic.
tags:
- attack.stealth
- attack.t1036.003
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- \conhost.exe
- \dllhost.exe
filter_system_paths:
Image|startswith:
- C:\Windows\System32\
- C:\Windows\SysWOW64\
- C:\Windows\WinSxS\
condition: selection and not filter_system_paths
falsepositives:
- Unusual OS installs on a non-C system drive
- Forensic or sandbox tooling that copies system binaries to other locations
level: high
id: 242aa586-b360-56e5-96a3-5f18a11d523f
status: experimental
author: Vorant
references:
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
SoftEther VPN Client Execution
Detects execution of SoftEther VPN client binaries by product metadata or filename, used by the actors for persistent covert VPN access. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: SoftEther VPN Client Execution
description: Detects SoftEther VPN client processes identified by PE metadata (Product/Description)
or default client binary names. The actors installed SoftEther clients, sometimes
renamed, to tunnel and obscure C2 traffic.
tags:
- attack.persistence
- attack.t1133
logsource:
category: process_creation
product: windows
detection:
selection_meta:
- Product|contains: SoftEther
- Description|contains: SoftEther
selection_names:
Image|endswith:
- \vpnclient.exe
- \vpnclient_x64.exe
- \vpncmd.exe
- \vpncmd_x64.exe
condition: 1 of selection_*
falsepositives:
- Administrators or users who intentionally deploy SoftEther VPN for remote access
- Security testing or lab environments
level: medium
id: db06ddbf-acfa-5efc-92a5-d5e692d6540b
status: experimental
author: Vorant
references:
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
4 more detections for this report are in the app — the rules that match its indicators, plus every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. Three days of it free, no card.
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,097 reports from 147 sources, 496 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs