FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
FBI and six countries say China-linked Integrity Technology Group stole emails and shared them via a third-party portal.
On October 8, the FBI and agencies in six other countries said hackers tied to China's Integrity Technology Group stole email from government, law enforcement, healthcare, and religious organizations since at least mid-January 2021. The actors scanned sites with tools including MicroScan, which holds more than 1,300 scripts, guessed Microsoft 365 and Exchange passwords, copied mailboxes, and run a web app that gives unnamed third parties access to stolen email. The joint advisory lists eight exploited flaws—CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, and CVE-2023-22894—and says five were newly added to CISA's KEV catalog. The activity is consistent with Flax Typhoon, Ethereal Panda, and RedJuliett; the U.S. and UK have sanctioned the company, previously linked to the Raptor Train botnet of more than 200,000 devices.