The images in this article were generated with artificial intelligence. How we publish
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose main purpose was to exfiltrate emails Government organizations, security forces, health centres and religious institutions, especially in South-East Asia. The communication of the agencies combines technical evidence recovered by the investigations with evaluations of the infrastructure and practices of the group; the US Treasury Department. The United States had already sanctioned the company in January 2025 and the United Kingdom sanctioned it in December 2025. Integrity Technology Group has denied the charges.
Confirmed facts: the agencies describe concrete vectors and tools that the actors used: massive scans of exposed services (ports 21, 22, 53, 80, 443, 1080) with open-source utilities such as Nmap and mascan; use of a scanner called MicroScan (a Python application with more than 1,300 scripts to exploit known vulnerabilities); force / brute techniques (password printing) against Microsoft 365 and Exchange accounts by means of the EBurst tool; extraction of credentials and metadata from Active Directory Dync (ECP); and a web-based tool to collect the user-identified software for the 4.ct. In addition, the FBI links domains that the attackers used, such as natcloud service [.] com and dns.studiocloud [.] xyz, and states that there is a web application that allows third parties to access stolen mail content.

Limitations and uncertain elements: the alert does not quantify how many organizations were exfiltered or set specific dates of when the robberies occurred - only documents observable activity since at least January 2021. Nor does it assign intrusion to specific individuals within the sanctioned company; it speaks in collective terms ("the threat actors") and indicates that the same set of tactics coincides with groups traced by private firms with names like Flax Typhoon or Ethereal Panda, without establishing a full identity equivalence. On the other hand, the warning includes lists of indicators (domains, IP, hashes) covering years - several IOCs date from 2016 - and advises to check them before blocking them, because the dates of "last observation" are not always the most recent in the public record.
Technically, the operating pattern is classic but efficient: first, Automated scanning to locate vulnerable services (web, mail services and administrative panels); then, operation or falsification of pages to capture credentials (a XSS payload that shows user / password fields and delivers a ZIP with a malicious executable that simulates a legitimate process); side movements by robbing domain credentials and using valid credentials to access mail APIs; and exfiltration by scripts that compress and upload complete mailboxes to servers controlled by the attackers. A notable component is the preference for tools that use legitimate methods (EWS, Microsoft Graphh APIs, legitimate VPN installers) to make detection difficult.
What this means in practice: for the institutions concerned, the exposure of mailboxes not only implies loss of confidentiality - documents, medical records, police investigations - but also the possibility of prolonged follow-up(reusable credentials, remaining account delegations, or authorized applications). For individuals, the leaking of post may result in identity theft, extortion or operational security commitments. At the strategic level, the use of a company with commercial activities that, according to the agencies, provides capacity to state services, poses risks of espionage with access to internal communications from public and private actors.
Operational and technical recommendations - concrete and prioritized actions -: for safety managers and security officials, measures must be immediate and specific.
1) Review and harden access to mail and API: activate mandatory MFA for all access to webmail, Exchange, management panels and VPN; audit and revoke application permissions registered in Azure / Office 365 (rotate client secrets and remove unevaluated applications); monitor EWS access and unusual query patterns by account or IP addresses.
2) Plot and surface reduction: apply updates to the products identified by the warning and by the manufacturers (who publish patches and mitigations). Consult the catalogue of exploited vulnerabilities known to CISA to prioritize patches: https: / / www.cisa.gov / knowledge-exploited-vulnerabilities-catalog. Disable unnecessary services and ports (e.g. remote management interfaces and file services) and restrict access to critical services by reliable corporate access control lists or VPN.
3) Search for specific commitment signals: review web logs for XSS payloads or readdresses that show false forms; audit events and replication privileges of Active Directory (DCSync behaviors); detect executable facilities with system names (conhost.exe / dllhost.exe) outside expected locations; and check outgoing connections to domains and PIs listed in public indicators provided by agencies. For general references on MFA and controls, see the CISA guide: https: / / www.cisa.gov / mfa.
4) Response to suspicion of intrusion: to isolate committed hosts, preserve records and evidence, run forensic searches to determine scope (stolen credentials, recently granted permission accounts, applications with delegated access) and, only after proper scanning and mediation, remove backdoors and rotate passwords and secrets. If there is evidence of DCSync or certificate theft / Kerberos, consider the controlled rotation of critical service accounts (including krbtgt in AD) and the recombination of domain controllers according to severity.
(5) Coordinate and report: notify the competent national authorities and, where appropriate, sectoral information exchange partners. Agencies offer additional resources and can share IoC; in addition, joint action and reporting help contain the abuse of credentials and stop the distribution of stolen content by third parties.

For end-users: avoid reusing passwords, active MFA where available, distrust pages that ask for credentials unexpectedly and communicate any suspicious mail or request to the IT team. Organizations should train their staff in recognition of false login pages and in the quick report.
In short, the joint alert describes a well-tested chain of attack that combines public tools and known exploits with concealment techniques using legitimate services. The essential to defend yourself is to reduce the attack surface, force MFA, audit cloud and AD replication delegates, and have response procedures that preserve evidence before cleaning systems. For more regulatory and technical context, see the pages of agencies such as the FBI and CISA on tactics and patches.
Official sources and useful resources: FBI institutional pages on cyberresearch https: / / www.fbi.gov / investigate / cyber and the catalogue of exploited vulnerabilities of CISA cited above.
Related
More news on the same subject.

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...

Denmark confirms unauthorized access to the RCP that affected 8.8 million records
The Danish government confirmed that for about ten days in September there were unauthorized access to the Central Peru Register (CPR) the national population database. Accordin...