
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
The Cybersecurity and Infrastructure Security Agency and partners are warning of a Chinese-government linked organization that specializes in developing sophisticated hacking tools used to exfiltrate sensitive data from a wide-range of critical infrastructure organizations.
Summary
“Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide, including US critical infrastructure sectors,” according to an Oct. 8 cybersecurity advisory. CISA issued the advisory with the National Security Agency, the FBI and international cyber agencies from the United Kingdom, Australia, Canada, Japan, New Zealand and Spain.
According to the advisory, Integrity Tech threat actors have been tracked targeting U.S. government services and facilities, critical manufacturing, healthcare and public health and information technology critical infrastructure sectors. The group has also enabled attacks against U.S. law enforcement, education and religious organizations, according to CISA. The advisory describes the Integrity Technology Group as a “for-profit company with links to the Chinese government.” Integrity Tech specializes in acquiring and building malicious cyber tools, hosting infrastructure and compromising networks on behalf of clients, according to CISA.
“The services provided by Integrity Tech also contribute to the larger Chinese cyber ecosystem, which aims to exfiltrate sensitive data from victims around the world,” the advisory says. According to CISA, the China-linked actors are exploitation vulnerabilities by using “canning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while establishing persistence through VPN software and exfiltrating emails and credentials using scripts.” The CISA-led advisory provides tactics, techniques and procedures and indicators of compromise for organizations to use to detect malicious cyber activity affiliated with the Integrity Technology Group on their networks. CISA also urges organizations to disable unused services and ports, sanitize web application inputs to prevent injection attacks, implement multifactor authentication and apply patches to reduce risks of compromise.
Meanwhile, the Justice Department and the FBI announced on Oct. 8 the disruption of vulnerability scanning and spear phishing tools used by the Integrity Technology Group. According to court documents from the Western District of Pennsylvania, Integrity Technology Group produced a “Microscan” vulnerability scanning tool that used a botnet of Internet of Things devices infected with a malware variant.
The group used the “Microscan” capabilities against a South Carolina-based power company, a multi-national Non-Governmental Organization and international critical infrastructure organizations, the release says. The Justice Department and the FBI also announced the seizure of a “FishHub” spear phishing tool developed by Integrity Technology that was used to target approximately 20 Taiwanese universities. “Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure,” Brett Leatherman, assistant director of the FBI Cyber Division, said in the release.
Leatherman said, “The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity.
KazaSec's take
Phishing and credential-based attacks succeed because they target people, not just infrastructure, technical controls like SPF, DKIM, and DMARC only ever close part of that gap. The rest comes down to whether a team can actually spot the fake, and whether a compromised credential can still be reused anywhere else.
Coverage details
Related security advisories
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.