
On 8 October 2026 the FBI, CISA, NSA and agencies from six other countries published a joint advisory on the hackers enabled by Integrity Technology Group, a Chinese company linked to Beijing. The same day the US Justice Department seized two of its tools, MicroScan and FishHub. The advisory lists eight exploited CVEs, some more than ten years old, and gives concrete traces to hunt for on Linux and Windows servers.
What happened
On 8 October 2026 the FBI, CISA and NSA, together with the cyber agencies of the United Kingdom, Australia, Canada, Japan, New Zealand and Spain, published advisory AA26-281A. It describes the methods of hackers supported by Integrity Technology Group, a for-profit Chinese company with links to the Chinese government, whose activity overlaps with groups known as Flax Typhoon, Ethereal Panda or Red Juliett. The same day the US Justice Department announced the court-authorised seizure of two of its tools, the MicroScan vulnerability scanner and the FishHub phishing platform, along with six domain names.
How the attackers get in
According to the advisory, they scan ports 21, 22, 53, 80, 443 and 1080 with common open source tools, and MicroScan holds more than 1,300 scripts aimed at WordPress, Jenkins, Oracle WebLogic, Apache Struts or OpenSSL. Eight successfully exploited CVEs are listed, five of them newly added to the CISA KEV catalogue: Bash (Shellshock), ProFTPD 1.3.5, BIND 9, Apache Struts 2.3, Pulse Connect Secure, GitLab, ONLYOFFICE DocumentServer and Strapi. Mailboxes are attacked by password spraying against every Exchange interface (OWA, EWS, ActiveSync, Autodiscover and others). For persistence they install the legitimate SoftEther VPN client, set to reconnect at startup; on Linux a PHP script pulls mail through the EWS API and stages it in /var/tmp/.sess.zip. Domain controllers are read with the DCSync technique.
What to do now
- Check the eight CVEs: unpatched Bash, ProFTPD 1.3.5, BIND, Struts 2.3, old Pulse Secure appliances, GitLab, ONLYOFFICE 5.x and Strapi up to 4.5.5 must be updated or retired.
- Enforce MFA on webmail, Exchange Online and the VPN, and disable the Exchange protocols you do not use.
- Hunt on Linux servers:
find / -xdev -name .sess.zip 2>/dev/null, look for an unexpected SoftEther client or a process namedcryptowithps -eo pid,user,args. - Block and search the domains
natcloudservice[.]comandstudiocloud[.]xyzin DNS and proxy logs, and import the published STIX indicators. - Alert on Active Directory replication requested by machines that are not domain controllers.
Our take
None of these flaws is new: a 2014 Bash bug still opens doors in 2026. The best defence remains a complete inventory of what faces the internet, closed unused ports and MFA on every mail access.
Sources
- FBI / CISA / NSA and partners — Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data (AA26-281A)
- CISA — Cybersecurity Advisory AA26-281A
- U.S. Department of Justice — Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers
- The Record — International coalition seizes tools used by cyber firm behind Flax Typhoon
How we choose, verify and write our analyses →
Is your own server exposed? Run a free check — public information only, no intrusion:
Worried your servers are exposed? Our team audits, patches and monitors Linux and cloud infrastructure 24/7.
Talk to an expert Our managed server services →

