FBI Warns Chinese Hackers Use Automated Tools and Botnets to Steal Sensitive Data
FBI and partners warn China-linked Integrity Technology Group uses scanning, botnets, and hands-on access to steal data.
On October 8, 2026, the FBI and partner agencies warned that China-based Integrity Technology Group supports intrusions overlapping Flax Typhoon, Ethereal Panda, and Red Juliett. Operators scan exposed services with Nmap, masscan, Fscan, and MicroScan, then use password spraying, VPN clients, and email-collection tools against critical infrastructure, government, and healthcare. Investigations described Exchange password spraying, SoftEther VPN persistence, Exchange Web Services mail theft, and DCSync collection of Active Directory data. Agencies recommend patching, multifactor authentication, and hunting for unexpected replication, VPN installs, and outbound uploads.
- An October 8, 2026 joint advisory names Integrity Technology Group.
- Activity overlaps Flax Typhoon, Ethereal Panda, and Red Juliett.
- Operators scan with Nmap, masscan, Fscan, and MicroScan.
- They spray Exchange passwords, install SoftEther VPN, and steal mail.
- DCSync tooling was used to extract Active Directory credentials.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | dns.studiocloud.xyz | re, and established encrypted communications over HTTP with dns.studiocloud.xyz. Investigators determined that its mailbox-querying functio |
| domain | natcloudservice.com | ore uploading it to attacker infrastructure associated with natcloudservice.com. Additionally, a program called DC.exe performs DCSync repl |
Full article554 words · extracted from gbhackers.com · click to collapse
The FBI and international cybersecurity agencies have warned about hackers linked to the Chinese government who use automated vulnerability scanning, large-scale botnets, and hands-on exploitation to steal sensitive information worldwide.
A joint advisory released on October 8, 2026, identified China-based Integrity Technology Group as a facilitator of operations targeting critical infrastructure, government agencies, healthcare systems, and other organizations.
This advisory is based on evidence gathered during multiple FBI investigations. The Integrity Technology Group allegedly provides hacking tools, infrastructure, and operational support.
The techniques these hackers use overlap with activities publicly tracked as Flax Typhoon, Ethereal Panda, and Red Juliett. However, the agencies note that commercial threat-group labels do not always directly correlate with government attribution.
FBI Warns Chinese Hackers
The attackers use open-source scanning tools such as Nmap, masscan, Fscan, dirsearch, and WPScan to identify exposed services and vulnerable applications. Their scans typically target FTP, SSH, DNS, HTTP, HTTPS, and SOCKS ports, while website enumeration searches for PHP and ASP.NET pages.
A Python-based application known as MicroScan, observed since at least 2017, contains over 1,300 penetration-testing scripts. These scripts probe various technologies, including Oracle WebLogic Server, WordPress, Jenkins, Apache Struts, OpenSSL, and Juniper ScreenOS, helping operators identify exploitable weaknesses in potential victims.
Hackers also deploy cross-site scripting (XSS) payloads that modify vulnerable webpages to display credential-entry fields. One recovered payload offered a password-protected ZIP file containing live700v1.exe.
This executable launched DiagTrack.exe, which masqueraded as legitimate Windows software, and established encrypted communications over HTTP with dns.studiocloud.xyz. Investigators determined that its mailbox-querying functions likely supported email theft.
To compromise accounts, operators utilize EBurst, an open-source Python tool that facilitates password spraying and guessing against Microsoft Exchange interfaces. Targeted services include Outlook Web Access, Exchange Web Services, Autodiscover, PowerShell, and Microsoft-Server-ActiveSync.
To maintain persistent access, attackers install legitimate SoftEther VPN clients and configure them to reconnect automatically at startup.
Occasionally, the installers use filenames such as conhost.exe or dllhost.exe to mimic Windows components. Tools like PowerShell, curl, and wget help facilitate installation, while the VPN connections obscure malicious communications and support ongoing access.
Email collection relies on several specialized tools. A PHP script identified as Curlc4.txt interfaces with the Exchange Web Services API to retrieve emails, calendars, and contacts. This script compresses the collected data and, in some cases, encrypts it using RC4 or AES-128-CBC before uploading it to attacker infrastructure associated with natcloudservice.com.
Additionally, a program called DC.exe performs DCSync replication to extract Active Directory information, including credentials, group memberships, and trust relationships.
Another utility, office-cli, automates access to Microsoft Outlook 365 mailboxes and facilitates exfiltration using configuration files that contain client identifiers, tenant identifiers, and secrets. Stolen email content is also accessible through a custom web application.
The agencies recommend disabling unused services, patching software, sanitizing web inputs, and implementing multifactor authentication, especially for webmail, VPNs, and critical accounts.
Defenders should investigate unexpected Active Directory replication, unauthorized VPN installations, suspicious cloud-connected applications, and unusual outbound uploads.
Organizations that detect a compromise should isolate affected hosts, assess the intrusion’s scope, and coordinate remediation efforts. Validate historical indicators of compromise before blocking them, as some date back to 2016.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.