Back
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
SiTech AI Team3 min read

FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

The FBI and agencies in six other countries said hackers tied to China-based Integrity Technology Group have stolen email from organizations in Southeast Asia since at least January 2021 and run a web portal for third parties to access it.

Who Is Behind the Campaign

The FBI and agencies in six other countries said on October 8 that hackers tied to Integrity Technology Group, a China-based for-profit company with links to the Chinese government, have been breaking into networks since at least mid-January 2021. The hackers stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, and also targeted U.S. government services, critical manufacturing, healthcare, IT, law enforcement, education, and religious groups, along with organizations in Southeast Asia, Africa, and North America.

The U.S. Treasury sanctioned the company in January 2025 and the UK in December 2025. The agencies describe its methods as consistent with activity tracked as Flax Typhoon, Ethereal Panda, and RedJuliett. Integrity Technology Group rejected the accusations in January 2025.

How the Hackers Get In

The hackers scan networks and web applications with open-source tools such as Nmap, masscan, and WPScan, focusing on ports 21, 22, 53, 80, 443, and 1080. They have also used MicroScan, a Python web application with more than 1,300 penetration testing scripts, since as early as 2017. The advisory lists eight known flaws that were successfully exploited, including CVE-2019-11510 in Pulse Connect Secure, CVE-2021-22205 in GitLab, and CVE-2023-22894 in Strapi.

Another entry point is a fake login page. The FBI recovered a cross-site scripting payload that shows username and password fields and then offers a password-protected ZIP file containing a program named live700_v1.exe, which starts a process named DiagTrack.exe and sends encrypted traffic to dns.studiocloud[.]xyz. The hackers also use password spraying with the open-source Python tool EBurst against Microsoft 365 and Exchange accounts.

How They Stay and What They Take

To keep access, the hackers install SoftEther, a legitimate VPN program, often renaming the installer conhost.exe or dllhost.exe so it looks like a Windows file. To steal credentials, they ran a tool named DC.exe that uses DCSync to copy account credentials, group membership details, and trust relationships from domain controllers.

For email, the hackers built a bot from a PHP script named Curlc4.txt that collects mail through Exchange Web Services, compresses and sometimes encrypts it, and uploads it to a remote server. A second tool, office-cli, repeatedly returns to Microsoft 365 accounts to take mail from different time periods. The hackers also run a web application that provides third-party access to stolen email content, and in some cases limited access to that data to IP addresses in Xiamen, China.

What Defenders Should Do

The agencies urge defenders to hunt for signs of this activity. Recommended steps include turning off unused services and ports, sanitizing user input to block cross-site scripting, requiring multifactor authentication, watching for unexpected Active Directory replication, checking cloud accounts for connected applications that can read files and email, reviewing web application logs, applying patches, and replacing products that no longer get updates. For a suspected compromise, the advisory recommends isolating affected hosts, hunting to learn the scope, and reporting under national rules. The advisory includes 39 pages of indicators of compromise, some dating back to 2016.

Sources: The Hacker News

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.