Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished Updated

Allied advisory details hacking toolkit of sanctioned Chinese firm Integrity Tech

US, UK and allied governments on October 8 described sanctioned Integrity Technology Group as a tool and infrastructure supplier that enabled Flax Typhoon. Its technique list centers on email theft and names the files and clients operators left on victim systems.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Allied advisory details hacking toolkit of sanctioned Chinese firm Integrity Tech
Generated illustration
Integrity Tech's kit hits Microsoft 365 mail and SE Asia Who the Integrity Tech techniques in the joint advisory reach, and how, plus the US domain seizure announced the same day.

Microsoft 365 accounts: EBurst password spraying. Outlook 365 accounts: office-cli steals email. Southeast Asian government, law enforcement, healthcare and religious bodies: email exfiltrated. Victim devices: SoftEther VPN clients keep access. Integrity Tech: US seized tool domains.

Integrity Tech's kit hits Microsoft 365 mail and SE Asia
WhoHowKindClaim
Microsoft 365 email accountsEBurst tool used for password spraying and guessing to compromise accountsexposure9
Outlook 365 account holdersoffice-cli utility used to continuously access Outlook 365 accounts and steal emailsexposure15
Southeast Asian institutionsEmail exfiltrated from government, law enforcement, healthcare and religious targets, on-premises and in the cloudexposure14
Victim devicesSoftEther and other VPN clients installed to hide command and control traffic and keep accessexposure10
Integrity TechUS seized several domains tied to its MicroScan and FishHub hacking tools on October 8decision19

What happened

  • The advisory says Integrity Tech staff also break into victim networks themselves, activity the authoring agencies track as China-based malicious cyber activity.
  • Its listed tooling includes MicroScan, a hacking tool holding more than 1,300 pen-testing scripts built to scan websites for specific flaws.
  • Operators used a tool called EBurst to password-spray and guess their way into Microsoft 365 email accounts.
  • Email was stolen from on-premises and cloud systems, with targets in government, law enforcement, healthcare and religious institutions in Southeast Asia.
  • The US announced the same day that it had seized several domains tied to the MicroScan and FishHub hacking tools.

Why it matters

  • exposure Integrity Tech builds tools for sale as well as its own use, so the same kit can surface in intrusions credited to groups other than Flax Typhoon, and a hunt keyed only to that group's name would miss it.
  • constraint Seizing domains can cut off how MicroScan and FishHub are reached, but SoftEther clients and office-cli access already inside victim environments stay until defenders find and remove them.
  • decision Microsoft 365 tenants that still accept password-only sign-ins are the ones EBurst spraying works against, and the advisory's call for MFA is the control that answers it.

Scanning happens before any foothold. Open-source scanners and MicroScan probe networks and web applications from outside [5][6]. Initial access then came through command-line utilities built on exploit code written in Python and Go, and through cross-site scripting bugs in third-party applications, according to the advisory as summarized by Infosecurity Magazine [7][8].

After initial access, the techniques on the list leave things behind on systems a defender owns. Operators installed VPN clients such as SoftEther on victim devices to hide command-and-control traffic [10]. They kept access to Outlook 365 accounts with a command-line utility called office-cli [15]. A PHP script, Curlc4.txt, ran as a bot that collected victims' email [12]. DC.exe was used to trick a domain controller into handing over Active Directory data, including account credentials [13]. Exfiltration data was staged under different file names to make a MySQL email dump harder to spot [11].

Email is the objective. Five of the eleven techniques in the magazine's summary concern mail accounts or mail data [21]. The mitigation advice comes down to three items: disable unused services and ports, including automatic configuration, remote access and file-sharing protocols; sanitize web application input against XSS payloads; and adopt identity, credential and access management policies with MFA where possible [17]. The report also lists a large number of indicators of compromise, plus guidance for responders who think they are already compromised [16].

Infosecurity Magazine, summarizing the advisory, wrote that Integrity Tech's work has in the past enabled groups such as Flax Typhoon, also tracked as Ethereal Panda and Red Juliett [3]. The advisory itself places the company inside a wider system: "The services provided by Integrity Tech also contribute to the larger Chinese cyber ecosystem, which aims to exfiltrate sensitive data from victims around the world." [20]

NCSC director of operations Paul Chichester said: "The breadth of sectors that have been targeted across the globe demonstrate the extent of the threat and all organizations should take note of this warning and engage with NCSC advice and guidance." [18] The magazine's report does not name the allied countries that joined the US and UK on the advisory [1].

What to watch

  • Whether MicroScan or FishHub resurface on new domains after the October 8 seizures.
  • Whether the published indicators turn up SoftEther or office-cli activity outside the Southeast Asian sectors the advisory names.
  • Whether the authoring agencies tie Integrity Tech tooling to named groups beyond Flax Typhoon.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The US, UK and several allied countries issued a joint alert detailing the tactics, techniques and procedures associated with a sanctioned Chinese organization, Integrity Technology Group.

    ReportedSupportedView cited source
  2. [2]

    The advisory was published on October 8.

    ReportedSupportedView cited source
  3. [3]

    According to the advisory, the work of Integrity Technology Group has in the past enabled prolific Beijing-backed groups such as Flax Typhoon (aka Ethereal Panda, Red Juliett).

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. infosecurity-magazine.com

    1 article · October 9, 2026

    UK and Allies Warn of Cyber Threat from China’s Integrity Technology Group

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories