SecurityNot yet confirmed elsewhere1 publisher2 min readPublished Updated
Allied advisory details hacking toolkit of sanctioned Chinese firm Integrity Tech
US, UK and allied governments on October 8 described sanctioned Integrity Technology Group as a tool and infrastructure supplier that enabled Flax Typhoon. Its technique list centers on email theft and names the files and clients operators left on victim systems.
The Watch · Security desk

Microsoft 365 accounts: EBurst password spraying. Outlook 365 accounts: office-cli steals email. Southeast Asian government, law enforcement, healthcare and religious bodies: email exfiltrated. Victim devices: SoftEther VPN clients keep access. Integrity Tech: US seized tool domains.
- exposure Microsoft 365 email accounts EBurst tool used for password spraying and guessing to compromise accounts, claim 9
- exposure Outlook 365 account holders office-cli utility used to continuously access Outlook 365 accounts and steal emails, claim 15
- exposure Southeast Asian institutions Email exfiltrated from government, law enforcement, healthcare and religious targets, on-premises and in the cloud, claim 14
- exposure Victim devices SoftEther and other VPN clients installed to hide command and control traffic and keep access, claim 10
- decision Integrity Tech US seized several domains tied to its MicroScan and FishHub hacking tools on October 8, claim 19
| Who | How | Kind | Claim |
|---|---|---|---|
| Microsoft 365 email accounts | EBurst tool used for password spraying and guessing to compromise accounts | exposure | 9 |
| Outlook 365 account holders | office-cli utility used to continuously access Outlook 365 accounts and steal emails | exposure | 15 |
| Southeast Asian institutions | Email exfiltrated from government, law enforcement, healthcare and religious targets, on-premises and in the cloud | exposure | 14 |
| Victim devices | SoftEther and other VPN clients installed to hide command and control traffic and keep access | exposure | 10 |
| Integrity Tech | US seized several domains tied to its MicroScan and FishHub hacking tools on October 8 | decision | 19 |
What happened
- The advisory says Integrity Tech staff also break into victim networks themselves, activity the authoring agencies track as China-based malicious cyber activity.
- Its listed tooling includes MicroScan, a hacking tool holding more than 1,300 pen-testing scripts built to scan websites for specific flaws.
- Operators used a tool called EBurst to password-spray and guess their way into Microsoft 365 email accounts.
- Email was stolen from on-premises and cloud systems, with targets in government, law enforcement, healthcare and religious institutions in Southeast Asia.
- The US announced the same day that it had seized several domains tied to the MicroScan and FishHub hacking tools.
Why it matters
- exposure Integrity Tech builds tools for sale as well as its own use, so the same kit can surface in intrusions credited to groups other than Flax Typhoon, and a hunt keyed only to that group's name would miss it.
- constraint Seizing domains can cut off how MicroScan and FishHub are reached, but SoftEther clients and office-cli access already inside victim environments stay until defenders find and remove them.
- decision Microsoft 365 tenants that still accept password-only sign-ins are the ones EBurst spraying works against, and the advisory's call for MFA is the control that answers it.
Scanning happens before any foothold. Open-source scanners and MicroScan probe networks and web applications from outside [5][6]. Initial access then came through command-line utilities built on exploit code written in Python and Go, and through cross-site scripting bugs in third-party applications, according to the advisory as summarized by Infosecurity Magazine [7][8].
After initial access, the techniques on the list leave things behind on systems a defender owns. Operators installed VPN clients such as SoftEther on victim devices to hide command-and-control traffic [10]. They kept access to Outlook 365 accounts with a command-line utility called office-cli [15]. A PHP script, Curlc4.txt, ran as a bot that collected victims' email [12]. DC.exe was used to trick a domain controller into handing over Active Directory data, including account credentials [13]. Exfiltration data was staged under different file names to make a MySQL email dump harder to spot [11].
Email is the objective. Five of the eleven techniques in the magazine's summary concern mail accounts or mail data [21]. The mitigation advice comes down to three items: disable unused services and ports, including automatic configuration, remote access and file-sharing protocols; sanitize web application input against XSS payloads; and adopt identity, credential and access management policies with MFA where possible [17]. The report also lists a large number of indicators of compromise, plus guidance for responders who think they are already compromised [16].
Infosecurity Magazine, summarizing the advisory, wrote that Integrity Tech's work has in the past enabled groups such as Flax Typhoon, also tracked as Ethereal Panda and Red Juliett [3]. The advisory itself places the company inside a wider system: "The services provided by Integrity Tech also contribute to the larger Chinese cyber ecosystem, which aims to exfiltrate sensitive data from victims around the world." [20]
NCSC director of operations Paul Chichester said: "The breadth of sectors that have been targeted across the globe demonstrate the extent of the threat and all organizations should take note of this warning and engage with NCSC advice and guidance." [18] The magazine's report does not name the allied countries that joined the US and UK on the advisory [1].
What to watch
- Whether MicroScan or FishHub resurface on new domains after the October 8 seizures.
- Whether the published indicators turn up SoftEther or office-cli activity outside the Southeast Asian sectors the advisory names.
- Whether the authoring agencies tie Integrity Tech tooling to named groups beyond Flax Typhoon.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The US, UK and several allied countries issued a joint alert detailing the tactics, techniques and procedures associated with a sanctioned Chinese organization, Integrity Technology Group.
- [3]
According to the advisory, the work of Integrity Technology Group has in the past enabled prolific Beijing-backed groups such as Flax Typhoon (aka Ethereal Panda, Red Juliett).
- [4]
"Integrity Tech employs individuals who support malicious cyber activity in different ways, including acquiring or building cyber tools for use and sale, acquiring and hosting infrastructure and compromising networks across global victims, which the authoring organizations track as China-based malicious cyber activity."
- [5]
Integrity Tech TTPs include the use of open source scanning tools to find vulnerabilities in networks and web-based applications.
- [6]
Integrity Tech TTPs include use of the MicroScan hacking tool, which contains over 1,300 pen-testing scripts designed to scan sites for specific flaws.
- [7]
Initial access to networks and cloud services was gained via command line utilities built on exploit codes written in Python and Go.
- [8]
Integrity Tech TTPs include exploitation of cross-site scripting (XSS) bugs to compromise third-party apps.
- [9]
The EBurst tool was used for password spraying and guessing to compromise Microsoft 365 email accounts.
- [10]
Persistence was achieved by installing VPN clients, such as SoftEther, on victim devices to obfuscate command and control communications.
- [11]
Exfiltration data was staged with different file names to minimize detection of the MySQL email dump.
- [12]
A bot was created using the PHP script Curlc4.txt to obtain emails from victims.
- [13]
DC.exe was used to trick a domain controller into handing over sensitive Active Directory information, including account credentials.
- [14]
Email data was exfiltrated from on-premises systems and cloud-based services, with targeted verticals including government, law enforcement, healthcare and religious institutions located in Southeast Asia.
- [15]
The command-line utility office-cli was used to continuously access Microsoft Outlook 365 accounts and steal emails.
- [16]
The report lists a large number of indicators of compromise, additional resources and mitigations, and advice for incident responders who think they may already have been compromised.
- [17]
The main mitigation advice: disable unused services and ports, including automatic configuration, remote access and file sharing protocols; sanitize user input in web applications to prevent XSS payload injection; implement identity, credential and access management (ICAM) policies and require multifactor authentication where possible.
- [18]
"The breadth of sectors that have been targeted across the globe demonstrate the extent of the threat and all organizations should take note of this warning and engage with NCSC advice and guidance."
- [19]
Also on October 8, the US announced the seizure of several domains associated with hacking tools Microscan and FishHub, in a bid to disrupt the operations of Integrity Tech and associated threat groups.
- [20]
"The services provided by Integrity Tech also contribute to the larger Chinese cyber ecosystem, which aims to exfiltrate sensitive data from victims around the world."
- [21]
Five of the eleven techniques in Infosecurity Magazine's summary of the advisory concern email accounts or email data (EBurst against Microsoft 365, the MySQL email dump staging, the Curlc4.txt email bot, email exfiltration, and office-cli against Outlook 365).
Sources
1 independent publisher whose own reporting we read for this story.
- infosecurity-magazine.comUK and Allies Warn of Cyber Threat from China’s Integrity Technology Group
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Joint Government Cyber AdvisoriesFollow
- Email Account CompromiseFollow
- State-Sponsored Cyber EspionageFollow
Entities
- Integrity Technology GroupFollow
- Flax TyphoonFollow
- UK NCSCFollow
- Paul ChichesterFollow
- MicroScanFollow
- FishHubFollow
- EBurstFollow
- SoftEtherFollow
- Microsoft 365Follow