FBI details how Integrity Technology Group steals and sells email access
The FBI and international partners revealed how hackers linked to Integrity Technology Group exploit web flaws and use custom tools to steal emails from global organizations.
Bài viết này chỉ có sẵn bằng tiếng Anh.
On October 8, the FBI and agencies from six other countries released a joint advisory detailing cyber espionage operations tied to Integrity Technology Group. The report outlines how this China-based company has systematically breached government, healthcare, and religious institutions across Southeast Asia, Africa, and North America since at least January 2021.
What happened
Integrity Technology Group, a for-profit entity sanctioned by the U.S. and UK, operates as a hub for cyber tools and intrusion services. The advisory describes the group’s employees as building infrastructure, developing hacking tools, and directly breaking into networks. While the company denies the accusations, former FBI Director Christopher Wray noted in 2024 that the company’s chairman had publicly admitted to collecting intelligence for Chinese government security agencies.
The scope of the intrusions is broad, targeting U.S. critical manufacturing, law enforcement, and education sectors alongside similar entities abroad. The hackers do not just steal data for themselves; they operate a web application that grants third parties access to stolen email content. The advisory does not identify these third-party users or specify the total number of breached organizations, but it confirms the theft of sensitive communications from high-value targets.
This activity is distinct from, though related to, previous disruptions. In September 2024, the FBI dismantled the Raptor Train botnet, which controlled over 200,000 consumer devices. While that action focused on the botnet infrastructure, the new advisory details the specific methods used to infiltrate corporate and government networks and exfiltrate data.
How it works
The intrusion process begins with aggressive scanning. The attackers use open-source tools like Nmap and WPScan, along with a custom Python tool called MicroScan. MicroScan contains over 1,300 scripts designed to probe for specific vulnerabilities in services such as OpenSSL, WordPress, and Apache Struts. The UK’s National Cyber Security Centre noted that the group uniquely employs automated scanning tools, potentially leveraging AI, to identify vulnerable targets efficiently.
Once a vulnerability is found, the hackers exploit it using command-line tools written in Python and Go. The advisory lists eight specific common vulnerabilities and exposures (CVEs) that have been successfully exploited, including flaws in GNU Bash, Pulse Connect Secure, and GitLab. Five of these were recently added to the Known Exploited Vulnerabilities catalog. In some cases, they deploy cross-site scripting payloads to trick users into downloading malware disguised as legitimate Windows processes, such as DiagTrack.exe.
After gaining initial access, the attackers establish persistence using SoftEther VPN software, often renaming the installer to mimic system files like conhost.exe. They then move laterally through the network using DCSync techniques via a tool called DC.exe to harvest Active Directory credentials. For email theft, they deploy a PHP bot named Curlc4.txt that uses Exchange Web Services to collect, compress, and upload mail to remote servers. Another tool, office-cli, uses legitimate Microsoft 365 API credentials to continuously siphon email data without triggering typical detection alerts.
Key details
- Primary Actor: Integrity Technology Group, a China-based company sanctioned by the U.S. Treasury in January 2025 and the UK in December 2025.
- Custom Tooling: The group uses MicroScan, a Python application with 1,300+ penetration testing scripts, and EBurst for password spraying against Microsoft 365 accounts.
- Exploited Flaws: Eight specific CVEs were confirmed as exploited, including CVE-2021-22205 in GitLab and CVE-2019-11510 in Pulse Connect Secure.
- Data Exfiltration: Stolen emails are made available to third parties via a web application where users can view specific account contents by modifying URL arguments.
- Persistence Mechanism: Attackers install SoftEther VPN clients renamed to look like Windows system files to maintain access and evade security software.
- Geographic Focus: Victims include organizations in Southeast Asia, Africa, and North America, spanning government, healthcare, law enforcement, and religious sectors.
Why it matters
For security engineers and IT leaders, this advisory highlights the danger of relying solely on perimeter defenses against automated, script-driven attacks. The use of open-source scanners combined with custom exploitation scripts means that any unpatched public-facing service is a potential entry point. The fact that five of the eight exploited flaws were only recently added to the Known Exploited Vulnerabilities catalog suggests that defenders must monitor emerging threat intelligence closely, not just rely on static patch management schedules.
The use of legitimate tools like SoftEther and Microsoft 365 APIs for data exfiltration complicates detection. Traditional signature-based antivirus may miss renamed VPN installers, and traffic using valid API credentials looks like normal user activity. This shifts the burden of detection to behavioral analytics, such as monitoring for unusual Active Directory replication requests or unexpected application permissions in cloud environments. Organizations must assume that credential theft is a primary goal and that stolen data may be resold or shared with other threat actors.
What you can do
- Patch critical vulnerabilities: Immediately apply fixes for the eight CVEs listed in the advisory, particularly those in GitLab, Pulse Connect Secure, and Apache Struts.
- Enforce multifactor authentication: Require MFA for all webmail, VPN, and administrative accounts to mitigate password spraying attacks using tools like EBurst.
- Audit cloud permissions: Review Microsoft 365 and other cloud accounts for unauthorized applications or service principals that have read access to email and files.
- Monitor Active Directory: Set up alerts for unexpected replication events, which may indicate the use of DCSync techniques to harvest credentials.
- Disable unused services: Turn off unnecessary ports and services, such as remote access and file sharing, to reduce the attack surface for scanners like MicroScan.
- Sanitize web inputs: Ensure all web applications properly sanitize user input to prevent cross-site scripting attacks that could deliver malware like the fake DiagTrack.exe.



