FBI and nine partner agencies expose the toolkit of China-linked Integrity Tech: old flaws, Exchange password spraying and SoftEther VPN backdoors

On 8 October 2026 the FBI, CISA, NSA and agencies from six other countries published a joint advisory on the hackers enabled by Integrity Technology Group, a Chinese company linked to Beijing. The same day the US Justice Department seized two of its tools, MicroScan and FishHub. The advisory lists eight exploited CVEs, some more than ten years old, and gives concrete traces to hunt for on Linux and Windows servers.

What happened

On 8 October 2026 the FBI, CISA and NSA, together with the cyber agencies of the United Kingdom, Australia, Canada, Japan, New Zealand and Spain, published advisory AA26-281A. It describes the methods of hackers supported by Integrity Technology Group, a for-profit Chinese company with links to the Chinese government, whose activity overlaps with groups known as Flax Typhoon, Ethereal Panda or Red Juliett. The same day the US Justice Department announced the court-authorised seizure of two of its tools, the MicroScan vulnerability scanner and the FishHub phishing platform, along with six domain names.

How the attackers get in

According to the advisory, they scan ports 21, 22, 53, 80, 443 and 1080 with common open source tools, and MicroScan holds more than 1,300 scripts aimed at WordPress, Jenkins, Oracle WebLogic, Apache Struts or OpenSSL. Eight successfully exploited CVEs are listed, five of them newly added to the CISA KEV catalogue: Bash (Shellshock), ProFTPD 1.3.5, BIND 9, Apache Struts 2.3, Pulse Connect Secure, GitLab, ONLYOFFICE DocumentServer and Strapi. Mailboxes are attacked by password spraying against every Exchange interface (OWA, EWS, ActiveSync, Autodiscover and others). For persistence they install the legitimate SoftEther VPN client, set to reconnect at startup; on Linux a PHP script pulls mail through the EWS API and stages it in /var/tmp/.sess.zip. Domain controllers are read with the DCSync technique.

What to do now

  1. Check the eight CVEs: unpatched Bash, ProFTPD 1.3.5, BIND, Struts 2.3, old Pulse Secure appliances, GitLab, ONLYOFFICE 5.x and Strapi up to 4.5.5 must be updated or retired.
  2. Enforce MFA on webmail, Exchange Online and the VPN, and disable the Exchange protocols you do not use.
  3. Hunt on Linux servers: find / -xdev -name .sess.zip 2>/dev/null, look for an unexpected SoftEther client or a process named crypto with ps -eo pid,user,args.
  4. Block and search the domains natcloudservice[.]com and studiocloud[.]xyz in DNS and proxy logs, and import the published STIX indicators.
  5. Alert on Active Directory replication requested by machines that are not domain controllers.

Our take

None of these flaws is new: a 2014 Bash bug still opens doors in 2026. The best defence remains a complete inventory of what faces the internet, closed unused ports and MFA on every mail access.

Sources

How we choose, verify and write our analyses →

Is your own server exposed? Run a free check — public information only, no intrusion:

Check a server Check a website

Worried your servers are exposed? Our team audits, patches and monitors Linux and cloud infrastructure 24/7.

Talk to an expert Our managed server services →