Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
Joint advisory says Integrity Technology Group-enabled Chinese actors steal data from critical infrastructure using botnets and hands-on hacking.
CISA, the FBI, the NSA, and partner agencies issued joint advisory AA26-281A on Chinese government-linked actors enabled by Integrity Technology Group. The actors combine automated scanning, large-scale botnets, cross-site scripting, password spraying, and hands-on exploitation, including against Microsoft Exchange, to steal data. They persist through VPN software and use scripts to exfiltrate emails and credentials, targeting US critical infrastructure and organizations in Southeast Asia, Africa, and North America. Defenders are urged to hunt for compromise, disable unused services, sanitize web inputs, require MFA, and patch listed vulnerabilities.