# Integrity Tech enables China-linked cyber espionage

Published: 2026-10-08 · Severity: routine · Sectors: government-national, healthcare, manufacturing, technology, education
Canonical: https://vorant.io/reports/05542769-951d-5c4e-a563-e7a79bc69870/integrity-tech-enables-china-linked-cyber-espionage

> CISA and allies detail Integrity Technology Group-enabled Chinese threat actors using botnets, VPNs, and LOTL tools to steal email and AD data from critical infrastructure.

A joint advisory from CISA, FBI, NSA, and international partners (UK, Australia, Canada, Japan, New Zealand, Spain) details malicious cyber activity enabled by Integrity Technology Group, a China-based company with links to the Chinese government. The threat actors' TTPs overlap with activity publicly tracked as Flax Typhoon, Ethereal Panda, and Red Juliett. Victims span US critical infrastructure sectors including Government Services, Critical Manufacturing, Healthcare, and IT, as well as law enforcement, education, religious organizations, and targets across Southeast Asia, Africa, and North America.

The actors combine open-source reconnaissance tools (BBScan, Fscan, masscan, NMAP, dirsearch, wpscan, OneForAll, ShuiZe, ksubdomain) and a custom Python-based scanner called MicroScan (1,300+ penetration-testing scripts targeting OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins, Apache Struts) for initial vulnerability discovery. Initial access leverages exploit code in Python/Go, XSS payloads for credential harvesting leading to deployment of live700_v1.exe (masquerading as DiagTrack.exe, communicating with dns.studiocloud.xyz), and EBurst for password spraying/guessing against Microsoft Exchange/O365 interfaces (ECP, EWS, OWA, RPC, MAPI, PowerShell, Autodiscover, ActiveSync). For persistence, actors install SoftEther VPN clients (disguised as conhost.exe/dllhost.exe) to obscure C2 traffic, observed connecting through domains including 98aiblog.com, hmbcloud.com/net, hmbiplc-01.com, iepl.node.cm, javacheck.ooguy.com, javaupdate.giize.com, sexytube0.com, and twimg.co.uk. Collection/exfiltration tools include a PHP-based EWS bot (Curlc4.txt) communicating with natcloudservice.com (C2 at 149.28.132.137) that encrypts stolen emails with RC4 or AES-128-CBC, DC.exe for DCSync-based Active Directory credential dumping, and office-cli for automated, legitimate-looking O365 mailbox exfiltration. Some exfiltrated data access was restricted to IP ranges in Xiamen, China.

The advisory provides extensive IOC tables (domains, webshells, binaries, scripts) and MITRE ATT&CK mappings, along with detailed mitigation guidance emphasizing MFA, network segmentation, LOTL/AD replication monitoring, patch management, and protective DNS. Defenders should treat this as a mature, persistent espionage capability-for-hire operation rather than a single campaign, given activity dating back to at least 2016-2017 and ongoing use of commodity and custom tooling against government, healthcare, manufacturing, and IT targets globally.

## Mentioned in this report

- Threat actors: Flax Typhoon, Integrity Technology Group
- Malware: Curlc4.txt, DC.exe, EBurst, MicroScan, SoftEther, live700_v1.exe, office-cli

## Detection guidance (public sample)

### DCSync Replication Rights Used by Non-Machine Account

ATT&CK: T1003.006

Detects directory replication (DS-Replication-Get-Changes/-All) access by a non-computer account, indicating DCSync-style credential dumping such as DC.exe. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: DCSync Replication Rights Used by Non-Machine Account
description: Detects Security 4662 events where directory replication extended rights
  are exercised by a user account rather than a domain controller machine account
  - DCSync credential dumping (e.g. DC.exe, mimikatz lsadump::dcsync). Requires Directory
  Service Access auditing on the domain object.
tags:
- attack.credential-access
- attack.t1003.006
logsource:
  product: windows
  service: security
detection:
  selection:
    EventID: 4662
    AccessMask: '0x100'
    Properties|contains:
    - 1131f6aa-9c07-11d1-f79f-00c04fc2dcd2
    - 1131f6ad-9c07-11d1-f79f-00c04fc2dcd2
    - 89e95b76-444d-4c62-991a-0facbeda640c
  filter_machine_accounts:
    SubjectUserName|endswith: $
  condition: selection and not filter_machine_accounts
falsepositives:
- Azure AD Connect or similar directory sync service accounts that legitimately hold
  replication rights
- Identity or backup products that replicate AD using a dedicated service account
level: high
id: bb637bbd-141c-56a0-b067-1e2e632cc8ed
status: experimental
author: Vorant
references:
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
```

### conhost.exe or dllhost.exe Executed Outside System Directories

ATT&CK: T1036.003

Detects conhost.exe/dllhost.exe running from non-system paths, matching the SoftEther VPN client disguised as these binaries for C2 tunnelling. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: conhost.exe or dllhost.exe Executed Outside System Directories
description: Detects processes named conhost.exe or dllhost.exe launched from outside
  the Windows system directories. The actors disguised SoftEther VPN clients as these
  binaries to obscure C2 traffic.
tags:
- attack.stealth
- attack.t1036.003
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith:
    - \conhost.exe
    - \dllhost.exe
  filter_system_paths:
    Image|startswith:
    - C:\Windows\System32\
    - C:\Windows\SysWOW64\
    - C:\Windows\WinSxS\
  condition: selection and not filter_system_paths
falsepositives:
- Unusual OS installs on a non-C system drive
- Forensic or sandbox tooling that copies system binaries to other locations
level: high
id: 242aa586-b360-56e5-96a3-5f18a11d523f
status: experimental
author: Vorant
references:
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
```

### SoftEther VPN Client Execution

ATT&CK: T1133

Detects execution of SoftEther VPN client binaries by product metadata or filename, used by the actors for persistent covert VPN access. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: SoftEther VPN Client Execution
description: Detects SoftEther VPN client processes identified by PE metadata (Product/Description)
  or default client binary names. The actors installed SoftEther clients, sometimes
  renamed, to tunnel and obscure C2 traffic.
tags:
- attack.persistence
- attack.t1133
logsource:
  category: process_creation
  product: windows
detection:
  selection_meta:
  - Product|contains: SoftEther
  - Description|contains: SoftEther
  selection_names:
    Image|endswith:
    - \vpnclient.exe
    - \vpnclient_x64.exe
    - \vpncmd.exe
    - \vpncmd_x64.exe
  condition: 1 of selection_*
falsepositives:
- Administrators or users who intentionally deploy SoftEther VPN for remote access
- Security testing or lab environments
level: medium
id: db06ddbf-acfa-5efc-92a5-d5e692d6540b
status: experimental
author: Vorant
references:
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

4 more detections for this report are in the app: the rules that match its indicators, every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. A new account gets three days of them free.

Source reporting: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/05542769-951d-5c4e-a563-e7a79bc69870/integrity-tech-enables-china-linked-cyber-espionage.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
