Close Menu
NCIJ Network NCIJ Network
    What's Hot

    American Ignorance Risks Fueling Deadly Middle East Sectarianism

    October 8, 2026

    Did Chuck Schumer say ‘our ultimate goal’ is to give citizenship to immigrants already in US?

    October 8, 2026

    Adidas sues Australian label White Fox over four stripes design

    October 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • American Ignorance Risks Fueling Deadly Middle East Sectarianism
    • Did Chuck Schumer say ‘our ultimate goal’ is to give citizenship to immigrants already in US?
    • Adidas sues Australian label White Fox over four stripes design
    • Russian strike on buses kills at least 30, say officials, as deadly attacks on Ukraine surge
    • Campaigners led by Chris Packham urge prime minister to rethink Send overhaul | Special educational needs
    • White House blocks Microsoft from foreign worker hiring program
    • JetBrains Releases Mellum2.1: A 12B MoE Open Model for Coding Agents
    • FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 8, 2026 Cybersecurity No Comments9 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8.

    The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more than 1,300 scripts, guessed passwords for Microsoft 365 and Exchange accounts, and copied mailboxes using tools designed to collect mail.

    The hackers have been breaking into networks since at least mid-January 2021, according to the agencies’ joint advisory. It describes the hacking in the present tense but provides no date for any theft and does not specify how many organizations were breached.

    The same hackers targeted U.S. government services, critical manufacturing, healthcare, and IT organizations, along with U.S. law enforcement, education, and religious groups. Organizations in Southeast Asia, Africa, and North America were also targeted.

    The hackers also run a web application that “provides third-party access to stolen email content,” the advisory said. It does not identify those third parties.

    In September 2024, the FBI disrupted a botnet, a network of hijacked devices, that the U.S. Justice Department said Integrity Technology Group controlled. It held more than 200,000 routers, cameras, and other consumer devices, and Lumen researchers had named it Raptor Train.

    Cybersecurity

    The 2024 action dealt with the botnet. The new advisory covers how the hackers get into networks and what they take. It is based on evidence the FBI recovered and observed during several investigations related to the company.

    Who Is Behind It

    The agencies describe Integrity Technology Group as “a China-based for-profit company with links to the Chinese government” whose employees build or get cyber tools “for use and sale,” host infrastructure, and break into networks.

    The advisory uses a single label, “the threat actors,” for the company and the hackers it enables. It does not say which of them carried out each break-in.

    The U.S. Treasury sanctioned the company in January 2025 for its role in several computer break-ins against U.S. victims. The UK sanctioned it in December 2025.

    Christopher Wray, then the FBI director, said in 2024 that the company’s “chairman has publicly admitted that for years his company has collected intelligence and performed reconnaissance for Chinese government security agencies.”

    The hackers’ methods are “consistent with” activity that security companies track as Flax Typhoon, Ethereal Panda, and RedJuliett, among others, the advisory said. Those names may not match the U.S. government’s own tracking one-to-one, and the same hackers may also carry out work unrelated to Integrity Technology Group.

    Flax Typhoon is Microsoft’s name for a China-based group that it described in 2023 as targeting organizations in Taiwan.

    Integrity Technology Group rejected the U.S. accusations in January 2025. It told the Shanghai Stock Exchange that the U.S. move had no factual basis, the Associated Press reported. A Chinese Foreign Ministry spokesperson, asked about the sanctions, said China firmly opposed the U.S. action, according to the same report.

    How the Hackers Get In

    The hackers look for flaws in networks and web applications with open-source scanners such as Nmap, masscan, and WPScan, the advisory said. Their scans focus on ports 21, 22, 53, 80, 443, and 1080.

    “The use of open source tools typically found on GitHub suggests the threat actors tend to look for more vulnerable targets,” the agencies said.

    The hackers have also used a scanner called MicroScan since as early as 2017. It is a Python web application containing more than 1,300 penetration testing scripts designed to scan websites for specific flaws. The hackers have used the scripts against services including OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts.

    The UK’s National Cyber Security Centre, one of the agencies behind the advisory, said in its news release that the hackers are “uniquely using AI tools, such as automated scanning.” The advisory itself does not mention AI.

    The hackers mostly get in with command-line tools built on exploit code written in languages such as Python and Go. The advisory lists 8 known flaws that it says were successfully exploited. The flaws were found in the hackers’ penetration testing scripts.

    The table shows the affected versions as the advisory gives them and, where one could be confirmed, the release that fixes the flaw.

    Flaw Product Affected Versions in the Advisory Fixed In
    CVE-2014-6278 GNU Bash Through 4.3 bash43-026 Not confirmed
    CVE-2015-3306* ProFTPD 1.3.5 1.3.5a
    CVE-2015-5477* ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 9.9.7-P2 or 9.10.2-P3
    CVE-2016-3081* Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28 2.3.20.3, 2.3.24.3, or 2.3.28.1
    CVE-2019-11510 Pulse Connect Secure 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 8.2R12.1, 8.3R7.1, or 9.0R3.4, from the advisory’s ranges
    CVE-2021-22205 GitLab All versions starting from 11.9 13.8.8, 13.9.6, or 13.10.3, per its NVD record
    CVE-2021-3199* ONLYOFFICE Document Server 5.1.5 through 5.6.2 5.6.3
    CVE-2023-22894* Strapi Up to 4.5.5 4.8.0

    The advisory marks 5 of the 8 with an asterisk and describes them as newly added to the Known Exploited Vulnerabilities (KEV) catalog, the list of flaws that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) says have been used in attacks. They were not in the catalog data that CISA publishes on GitHub (version 2026.10.04) when The Hacker News checked at 18:05 UTC on October 8.

    Strapi’s own advisory gives a wider range than the joint advisory. It says versions from 3.2.1 through 4.7.9, but not including 4.8.0, are affected.

    Two flaws depend on a setting. The Struts flaw works only when Dynamic Method Invocation is turned on, and Apache says turning it off is an alternative to upgrading. The ONLYOFFICE flaw applies when JWT is used, according to its NVD record.

    The BIND flaw is a denial-of-service bug that makes the DNS server exit.

    Another way in is a fake login. The FBI recovered a cross-site scripting (XSS) payload that changes a vulnerable web page to show username and password fields.

    After a visitor enters any username and password, the page offers a password-protected ZIP file that holds a program named live700_v1.exe. That program starts a process named DiagTrack.exe, the same name as a legitimate Windows program, which sends encrypted traffic to dns.studiocloud[.]xyz.

    The FBI attributes that domain to Integrity Technology Group and assesses that the malware likely targets email.

    The hackers also use password spraying, which means trying a few common passwords against many accounts. For this, they use EBurst, an open-source Python tool that targets Microsoft 365 and Exchange accounts.

    EBurst tries logins through Exchange interfaces that include ECP, EWS, OAB, OWA, RPC, API, MAPI, PowerShell, Autodiscover, and Microsoft-Server-ActiveSync, according to its README file. Defenders should cover these interfaces, the agencies said.

    How They Stay and What They Take

    To keep access, the hackers install SoftEther, a legitimate VPN program that security software is less likely to flag, the advisory said. They often rename the installer conhost.exe or dllhost.exe so it looks like a Windows file, and they set the client to reconnect each time the machine starts.

    To take credentials, they ran a tool named DC.exe that uses DCSync, a technique that copies data from a domain controller through Active Directory’s replication service. It copied account credentials, group membership details, and trust relationships.

    For email, the hackers built a bot from a PHP script named Curlc4.txt. It collects mail through Exchange Web Services (EWS), an interface that also gives access to calendars and contacts.

    The bot compresses the mail, sometimes encrypts it, and uploads it to a remote server. The script appears to be stand-alone rather than installed on a hacked device, and its main command-and-control domain was natcloudservice[.]com.

    A second tool, office-cli, keeps going back to Microsoft 365 accounts to take mail from different time periods. It works from configuration files that hold a client ID, tenant ID, and secret, and it avoids detection by using legitimate access methods, the agencies said.

    The FBI also saw the hackers download databases or pull data from victims’ email by hand.

    Cybersecurity

    In some cases, the hackers limited access to the stolen data to IP addresses in Xiamen, China.

    Users of the web application for third parties can view the mail of a specific account by adding arguments to a URL.

    What Defenders Should Do

    The agencies urge defenders to hunt for signs of this activity in their own networks. The steps they recommend include:

    • Turn off unused services and ports, such as remote access and file sharing.
    • Sanitize user input in web applications to block XSS.
    • Require multifactor authentication (MFA), especially for webmail, VPNs, and accounts that reach critical systems.
    • Watch for unexpected Active Directory replication, a sign of DCSync.
    • Check cloud accounts for connected applications that can read files and email.
    • Review web application logs for attack attempts.
    • Apply patches, including for the 8 flaws listed above.
    • Replace products that no longer get updates.

    For a suspected compromise, the advisory’s steps are to isolate the affected hosts, hunt to learn how far the break-in went, and report it under national rules. The hackers should be removed after enough hunting data has been collected, and the network then hardened.

    The advisory has 39 pages of indicators of compromise (IOCs), the domains, IP addresses, and file hashes linked to the hackers. The agencies say several date back to as early as 2016 and recommend checking them before blocking.

    Some are not new. The Hacker News found that 10 IP addresses in the list also appeared in the September 2024 advisory on the botnet, where they were tied to its command-and-control servers.

    The dates do not match. The new list shows those 10 addresses as last seen on June 5, 2024. The 2024 advisory showed them as last seen between August 28 and September 4, 2024.

    So a “last seen” date in the new list is not always the latest one on record. Apart from dates that show when a domain’s registration expires, the most recent “last seen” dates in the tables are from 2025.

    access ChinaLinked Emails FBI giving hackers parties Portal Ran stolen
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Trump Administration Cuts Off Access to a Major Immigration Program for Workers at Microsoft and Adobe

    Russian Spies Give ‘MatchBoil’ Malware a Stealthy Facelift

    Cisco Patches a Dozen Critical Vulnerabilities

    AWS’s repeated problems with AI agent controls illustrates the autonomous agent dilemma

    Cisco warns of critical flaws allowing Nexus switch takeover

    Security Awareness Training Isn’t Dead, but It Needs a Rethink

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    American Ignorance Risks Fueling Deadly Middle East Sectarianism

    October 8, 2026

    Did Chuck Schumer say ‘our ultimate goal’ is to give citizenship to immigrants already in US?

    October 8, 2026

    Adidas sues Australian label White Fox over four stripes design

    October 8, 2026

    Russian strike on buses kills at least 30, say officials, as deadly attacks on Ukraine surge

    October 8, 2026
    Latest Posts

    Wisconsin’s partisan primary election is Tuesday. Learn more about who’s on your ballot.

    August 10, 2026

    Gabon ends fisheries partnership agreement with EU

    August 10, 2026

    Science backs calls for limiting screens in schools

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    American Ignorance Risks Fueling Deadly Middle East Sectarianism

    October 8, 2026

    Did Chuck Schumer say ‘our ultimate goal’ is to give citizenship to immigrants already in US?

    October 8, 2026

    Adidas sues Australian label White Fox over four stripes design

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.