Executive Summary
In October 2026, the FBI and international agencies disclosed that Chinese state-sponsored hackers linked to Integrity Technology Group conducted a multi-year espionage campaign targeting government organizations, law enforcement agencies, healthcare systems, and religious institutions across Southeast Asia, North America, and Africa. The threat actors, tracked as Flax Typhoon and Ethereal Panda, exploited web vulnerabilities using automated scanners with over 1,300 penetration testing scripts, conducted password spraying attacks against Microsoft 365 accounts, and deployed custom email harvesting tools. Most significantly, the hackers operated a web portal that provided third-party access to stolen email content, indicating a potential intelligence-as-a-service operation.
This incident underscores the evolving nature of state-sponsored cyber espionage, where threat actors are increasingly commercializing stolen data through accessible platforms. The campaign's focus on unencrypted email communications and lateral movement through compromised networks highlights critical gaps in zero-trust architecture implementation across targeted organizations.
Why This Matters Now
State-sponsored groups are increasingly operating intelligence-as-a-service platforms, democratizing access to stolen data and amplifying the impact of individual breaches across multiple threat actors and criminal organizations.
Attack Path Analysis
China-linked Integrity Technology Group hackers conducted a multi-year campaign starting in 2021, using automated scanning tools with over 1,300 scripts to identify vulnerable web applications and services. They exploited known CVEs and performed password spraying against Microsoft 365/Exchange accounts to gain initial access. After compromising credentials, attackers escalated privileges using DCSync techniques to harvest domain controller data and establish persistence with legitimate VPN tools like SoftEther. They moved laterally across networks and cloud environments to access email systems and databases. Command and control was maintained through encrypted channels to domains like dns.studiocloud[.]xyz and natcloudservice[.]com. Email data was systematically exfiltrated using custom PHP bots (Curlc4.txt) and office-cli tools, with stolen content made available through a web portal to third parties. The campaign resulted in widespread data theft from government, healthcare, law enforcement, and religious organizations across multiple regions.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers used MicroScan tool with 1,300+ penetration testing scripts to scan for vulnerabilities in web applications, targeting ports 21, 22, 53, 80, 443, and 1080. They exploited 8 known CVEs including CVE-2021-22205 (GitLab) and CVE-2019-11510 (Pulse Connect Secure), and deployed XSS payloads delivering live700_v1.exe malware disguised as DiagTrack.exe. Password spraying attacks using EBurst tool targeted Microsoft 365 and Exchange accounts across multiple interfaces.
Related CVEs
CVE-2014-6278
CVSS 8.8GNU Bash through 4.3 bash43-026 allows remote attackers to execute arbitrary code via specially crafted environment variables.
Affected Products:
GNU Bash – through 4.3 bash43-026
Exploit Status:
exploited in the wildCVE-2015-3306
CVSS 10The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
Affected Products:
ProFTPD ProFTPD – 1.3.5
Exploit Status:
exploited in the wildCVE-2016-3081
CVSS 8.1The Struts 1 plugin in Apache Struts 2 before 2.3.20.3, 2.3.24.3, and 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted Struts 1 action.
Affected Products:
Apache Struts – 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, 2.3.25 to 2.3.28
Exploit Status:
exploited in the wildCVE-2019-11510
CVSS 10In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability.
Affected Products:
Pulse Secure Pulse Connect Secure – 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, 9.0 before 9.0R3.4
Exploit Status:
exploited in the wildCVE-2021-22205
CVSS 10An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
Affected Products:
GitLab GitLab CE/EE – All versions starting from 11.9
Exploit Status:
exploited in the wildCVE-2021-3199
CVSS 9.8ONLYOFFICE Document Server 5.1.5 through 5.6.2 allows remote code execution via the convertservice functionality.
Affected Products:
ONLYOFFICE Document Server – 5.1.5 through 5.6.2
Exploit Status:
exploited in the wildCVE-2023-22894
CVSS 4.9Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication.
Affected Products:
Strapi Strapi – Up to 4.5.5
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Password Spraying
Spearphishing Link
DCSync
Remote Email Collection
External Remote Services
Exfiltration Over C2 Channel
Domain Account Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software vulnerabilities are addressed
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – Identification and classification of critical ICT systems
Control ID: Article 8
CISA ZTMM 2.0 – Identity verification and access controls
Control ID: Identity Pillar
NIS2 Directive – Risk analysis and information system security policies
Control ID: Article 21(2)(a)
ISO 27001:2022 – Management of technical vulnerabilities
Control ID: A.8.8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Primary target of China-linked APT campaign exploiting email systems, requiring enhanced zero trust segmentation and encrypted traffic protection for sensitive communications.
Law Enforcement
Specifically targeted by Salt Typhoon operators for email exfiltration, necessitating improved egress security and multicloud visibility to prevent intelligence compromise.
Health Care / Life Sciences
Healthcare systems breached via Exchange vulnerabilities and password spraying attacks, requiring HIPAA-compliant threat detection and east-west traffic security implementation.
Telecommunications
Critical infrastructure exposed through botnet operations and lateral movement techniques, demanding Kubernetes security and inline IPS deployment for network protection.
Sources
- FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emailshttps://thehackernews.com/2026/10/fbi-says-china-linked-hackers-ran.htmlVerified
- FBI and International Partners Disrupt China-Linked Cyber Operationshttps://www.ic3.gov/CSA/2026/261008.pdfVerified
- UK Clamps Down on China-Based Companies for Reckless and Irresponsible Activity in Cyberspacehttps://www.gov.uk/government/news/uk-clamps-down-on-china-based-companies-for-reckless-and-irresponsible-activity-in-cyberspaceVerified
- US Treasury Sanctions Beijing-Based Company for Role in Computer Break-inshttps://thehackernews.com/2025/01/us-treasury-sanctions-beijing.htmlVerified
- China-Linked Flax Typhoon Cyber Espionage Group Targets Taiwan Organizationshttps://thehackernews.com/2023/08/china-linked-flax-typhoon-cyber.htmlVerified
- New Raptor Train IoT Botnet Compromises Over 200,000 Devices Worldwidehttps://thehackernews.com/2024/09/new-raptor-train-iot-botnet-compromises.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained this China-linked campaign by limiting lateral movement across networks and cloud environments, reducing the blast radius of credential harvesting and email exfiltration activities.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: CNSF policies would likely have restricted attackers' ability to scan across multiple cloud workloads and network segments, reducing their reconnaissance reach and limiting access to vulnerable services through workload isolation controls.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have limited the attackers' ability to reach domain controllers from compromised workloads, constraining their capacity to perform DCSync operations and reducing the scope of credential harvesting activities.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have constrained attackers' lateral movement between network segments and cloud workloads, limiting their ability to reach email systems and databases through granular inter-workload policy enforcement.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely have detected and constrained unauthorized VPN client installations and suspicious outbound connections to malicious domains, reducing the reliability of command and control channels across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have constrained large-scale email data exfiltration by limiting outbound data transfers to unauthorized destinations and reducing the volume of sensitive information that could be systematically extracted from Exchange and Microsoft 365 environments.
While sensitive data from compromised organizations would likely still face exposure risks, the overall impact scope would likely be reduced through constrained lateral movement and limited data exfiltration capabilities across segmented cloud environments.
Impact at a Glance
Affected Business Functions
- Email Communications
- Government Services
- Healthcare Information Systems
- Critical Manufacturing Operations
Estimated downtime: N/A
Estimated loss: N/A
Stolen email content from government organizations, law enforcement agencies, healthcare systems, and religious institutions across Southeast Asia, Africa, and North America. Email data accessible through web application providing third-party access to stolen content.
Recommended Actions
Key Takeaways & Next Steps
- •
Implement Zero Trust Segmentation to prevent lateral movement from compromised endpoints to critical email and database systems, using identity-based policies and microsegmentation
- •
Deploy Egress Security & Policy Enforcement to block unauthorized data exfiltration attempts and monitor outbound connections to suspicious domains like those used for C2 communication
- •
Enable Multicloud Visibility & Control to detect anomalous interactions with Microsoft 365 and Exchange services, including repeated API calls and bulk email access patterns
- •
Utilize Encrypted Traffic (HPE) protection to secure email data in transit and prevent interception during lateral movement across hybrid cloud environments
- •
Implement Inline IPS (Suricata) capabilities to detect and block exploitation attempts targeting the 8 known CVEs and similar vulnerability scanning activities



