UK and Allies Warn of Cyber Threat from China’s Integrity Technology Group
Allies warn Integrity Technology Group enables China-backed intrusions, email theft, and related hacking tools.
The United States, United Kingdom, and allied governments issued a joint alert on October 8 describing tactics used by China’s Integrity Technology Group. The sanctioned firm builds and sells cyber tools, hosts infrastructure, and compromises networks, activity previously linked to Flax Typhoon (Ethereal Panda, Red Juliett). Reported techniques include vulnerability scanning, MicroScan and Python or Go exploit utilities, cross-site scripting, EBurst password spraying against Microsoft 365, SoftEther VPN to hide command-and-control, and DC.exe to collect Active Directory credentials. Targets include government, law enforcement, healthcare, and religious organizations in Southeast Asia; the US also seized domains tied to Microscan and FishHub.