FBI Warns Chinese Hackers Use Automated Tools and Botnets to Steal Sensitive Data
FBI and partners warn China-linked Integrity Technology Group uses scanning, botnets, and hands-on access to steal data.
On October 8, 2026, the FBI and partner agencies warned that China-based Integrity Technology Group supports intrusions overlapping Flax Typhoon, Ethereal Panda, and Red Juliett. Operators scan exposed services with Nmap, masscan, Fscan, and MicroScan, then use password spraying, VPN clients, and email-collection tools against critical infrastructure, government, and healthcare. Investigations described Exchange password spraying, SoftEther VPN persistence, Exchange Web Services mail theft, and DCSync collection of Active Directory data. Agencies recommend patching, multifactor authentication, and hunting for unexpected replication, VPN installs, and outbound uploads.