Executive Summary
Threat actors use automated tools to steal sensitive information. Additionally, they establish persistent access through legitimate VPN software. Therefore, organizations must act quickly to secure their systems. These Chinese state hackers target high-value data for long-term intelligence gathering.
Intrusion Methods and Tools
Hackers execute scanning tools like MicroScan to find network vulnerabilities. Next, they deploy cross-site scripting attacks to harvest user credentials. Furthermore, attackers target Microsoft Exchange servers using password guessing techniques. They exploit common weaknesses in older software versions. As a result, unpatched systems fall victim to these automated sweeps.

Persistent Access Techniques
The actors then establish connections via SoftEther VPN to hide their tracks. They frequently rename installer files to mimic common Windows programs. Consequently, endpoint detection software fails to flag these connections as malicious. Attackers also host these connections on compromised subdomains.
Data Extraction Bots
Finally, they extract huge volumes of email data using custom bots. A specialized PHP script connects to Microsoft interfaces to copy mailboxes. Moreover, this script automatically uploads stolen emails to remote servers. Hackers often compress and encrypt this data before transferring it.
Integrity Technology Group Operations
International authorities link this activity directly to the Chinese government. Specifically, a company named Integrity Technology Group enables these malicious actions. This firm allegedly builds cyber tools and hosts infrastructure for state-sponsored operations. Law enforcement maintains high confidence in this attribution based on technical evidence. The FBI recovered multiple payloads during their ongoing investigations. Indeed, these services power a much larger cyberespionage ecosystem.
Massive Global Fallout
Victims include government services, healthcare providers, and manufacturing plants. Meanwhile, hackers successfully steal vast amounts of proprietary data and account credentials. They specifically target Active Directory environments to copy trust relationships. By using the DCSync technique, attackers pull sensitive configuration details.
Worldwide Reach
A joint advisory notes that these actors “target and steal sensitive data from organizations worldwide, including US critical infrastructure sectors”. They also compromise religious institutions and educational facilities. Consequently, experts suspect the total financial damage caused by these Chinese state hackers is massive. Investigators observe victims across North America, Africa, and Southeast Asia.
Defending Against Future Threats
Network defenders should implement strong identity management policies immediately. Authorities advise requiring multifactor authentication for all essential services. Additionally, organizations must replace default passwords and audit administrative privileges. Administrators must sanitize user input in web applications to block injection attacks.
Additional Security Measures
Finally, system administrators should monitor for abnormal traffic and unexpected Active Directory replication. Teams must apply software patches automatically from trusted network locations. Ultimately, rapid detection and patching remain the best defenses against these scanning bots.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!