Enterprise Cybersecurity IntelligenceFriday

An enterprise cybersecurity intelligence company.For security and technology leaders.

Security.io Intelligence

What changed, why it matters,
and how it evolved.

Threat Intelligence · Executive briefing

Allied agencies turn Integrity Tech reporting into a hunt mandate

A 58-page joint advisory supplies campaign infrastructure, filenames, tools and exploited vulnerabilities tied to Chinese government-linked actors enabled by Integrity Technology Group, creating an immediate compromise-assessment requirement.

Threat IntelligenceIdentityIncident Response
Why it is in today’s brief

The fresh joint advisory materially advances earlier Integrity Tech reporting by publishing a unified, investigation-derived chain with exact infrastructure, filenames, exploited CVEs and response guidance. It warrants inclusion above less actionable threat reporting because enterprises can run a concrete compromise assessment today and must determine whether years-old exposure produced persistence or credential loss that patch records cannot resolve.

Read first

US and allied agencies attribute a global data-theft ecosystem to Chinese government-linked actors enabled by Integrity Technology Group.

Act now

Hunt DNS and proxy telemetry for dns.studiocloud.xyz and the listed SoftEther domains.

Accountable owner

CISO, with threat detection, vulnerability management, identity security and incident response jointly accountable for the assessment.

Decision horizon

Begin hunting today; complete exposure and telemetry validation within 72 hours; escalate immediately on any matched compromise evidence.

AssessmentHigh confidence
Emerging riskWatch for victim confirmations, additional infrastructure, revised STIX data, new mappings between government and industry actor labels, or evidence that the published infrastructure remains active.

What happened

On October 8, 2026, US and allied agencies published AA26-281A using evidence recovered from multiple FBI investigations related to Integrity Technology Group. Since at least mid-January 2021, the actors have gained access to victim networks and cloud services primarily through command-line utilities built on exploit code. The advisory lists eight observed CVEs: CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199 and CVE-2023-22894.

The actors scanned ports 21, 22, 53, 80, 443 and 1080 while using open-source reconnaissance tools including BBScan, dirsearch, Fscan, masscan, Nmap and WPScan. The advisory also describes MicroScan, a Python web application containing more than 1,300 penetration-testing scripts, and EBurst, an open-source Python tool used for password spraying and guessing across Microsoft Exchange and Office 365 interfaces.

The recovered XSS chain delivered live700_v1.exe, started a process named DiagTrack.exe and established encrypted communications over HTTP with dns.studiocloud.xyz. SoftEther installers were often named conhost.exe or dllhost.exe, and observed connection domains included 98aiblog.com, hmbcloud.com, hmbcloud.net, hmbiplc-01.com, iepl.node.cm and javacheck.ooguy.com. The agencies said SoftEther was configured to reconnect automatically at startup and was used to obscure command-and-control activity.

Why this matters now

The advisory consolidates technical evidence recovered during multiple FBI investigations into a decision-grade hunt package. It connects broad scanning, exploitation, credential attacks, legitimate VPN software and email-data collection into one operational sequence. Enterprises no longer need to rely only on high-level actor descriptions: defenders can search exact domains, filenames, ports, persistence mechanisms and vulnerable products.

The activity matters beyond organisations traditionally considered espionage targets. The agencies identified government services, critical manufacturing, healthcare, public health and information technology among affected sectors, with additional targeting in education and other organisations across North America, Southeast Asia and Africa. The use of common internet-facing technologies and open-source tooling widens the relevant exposure set.

Patch completion alone cannot close this risk. The advisory describes activity dating back years, so systems patched today may still contain persistence, stolen credentials or evidence of earlier exploitation. Security leaders should require a compromise assessment proportionate to exposure, telemetry retention and the sensitivity of data reachable from affected systems.

The decision for security leaders

Assign the hunt as a time-bounded compromise assessment, not a threat-intelligence reading exercise. Detection engineering should load exact indicators and behavioural searches; vulnerability management should identify historical and current exposure; identity teams should examine Exchange authentication; incident response should define the evidence threshold for containment.

Prioritise internet-facing systems, organisations holding sensitive government, health, manufacturing or technology data, and environments with weak telemetry retention. Where historical logs are unavailable, document that assurance limitation and use compensating evidence from endpoint state, account activity, network flows, VPN installations and persistence configuration.

Do not equate a negative indicator search with absence of compromise. Domains and filenames can change, while the documented sequence of vulnerable web applications, credential harvesting, Exchange password spraying, legitimate VPN persistence and email collection remains reusable. Closure should combine indicator results with behavioural and exposure evidence.

Evidence of closure

  • Indicator searches cover retained DNS, proxy, endpoint and authentication telemetry.
  • Exposure records resolve every observed CVE to an owner and disposition.
  • Exchange authentication review identifies no unexplained spraying or successful access.
  • Incident response approves documented limitations where historical telemetry is unavailable.

The Security.io assessment

The publication’s value is the integration of technical evidence across reconnaissance, exploitation, identity abuse, persistence and exfiltration. It gives enterprises enough specificity to test whether existing controls would detect the sequence, rather than asking teams to search only for a threat-actor label whose industry mappings vary.

The campaign also demonstrates why old CVEs can remain operationally current. A vulnerability’s publication year does not indicate whether an exposed enterprise system was exploited, whether credentials were captured or whether SoftEther persistence survived later patching. Organisations with any historical exposure should separate remediation status from compromise status.

Attribution posture: the authoring agencies link the activity to Chinese government-linked actors enabled by Integrity Technology Group, while cautioning that industry actor names do not map one-to-one to the government’s understanding.

Questions for the morning meeting

  • Have the published domains, filenames and ports been checked across retained telemetry?
  • Which internet-facing systems remain exposed to the eight observed CVEs?
  • Can Exchange password spraying be detected across every listed interface?
  • Who owns incident escalation when a campaign indicator is found?

Related intelligence

Shared decision context