US and Allies Detail TTPs of Sanctioned Chinese Hacking Firm

Allies Expose Chinese Hacking Contractor 'Integrity Technology Group'

HIGH
October 10, 2026
October 11, 2026
5m read
Threat ActorThreat IntelligenceSupply Chain Attack

Related Entities(initial)

Threat Actors

Integrity Technology Group (ITG)Flax Typhoon

Products & Tech

Other

FishHubMicroScanEBurstoffice-cli

Full Report(when first published)

Executive Summary

A coalition of cybersecurity agencies from the U.S., U.K., and other allied nations has published a detailed joint advisory on Integrity Technology Group (ITG), a China-based company sanctioned for its role in global cyber espionage. The advisory, released on October 8, 2026, dissects ITG's function as a for-profit hacking contractor, developing and deploying cyber capabilities on behalf of Chinese state-sponsored threat actors, including the group known as Flax Typhoon (aka Ethereal Panda). The U.S. Department of Justice also announced the seizure of domains and hacking tools used by ITG, providing a rare public look into the commercial supply chain supporting China's state hacking operations.

Threat Overview

The advisory provides a clear picture of the public-private partnership model used by China for its cyber operations. ITG acts as a 'hacker-for-hire' entity, providing the tools, infrastructure, and operational support for state-directed campaigns. Their targets are widespread and align with China's strategic interests, including critical infrastructure, government, healthcare, and manufacturing sectors across North America, Southeast Asia, and Africa.

The group's activities mimic those previously attributed to Flax Typhoon, a threat actor known for targeting entities in Taiwan and other regions. The U.S. government's seizure of ITG's tools, including FishHub and MicroScan, represents a direct disruption of their operations.

Technical Analysis

ITG employs a mix of open-source and custom-built tools to conduct its operations. Their methodology is systematic, beginning with broad scanning and progressing to targeted exploitation.

Tools and TTPs:

  • Scanning: ITG uses open-source tools and a custom utility called MicroScan, which contains over 1,300 penetration testing scripts, to scan networks for specific vulnerabilities.
  • Exploitation: The group has been observed exploiting cross-site scripting (XSS) vulnerabilities to gain initial access.
  • Credential Access: A tool named EBurst is used to conduct password spraying attacks against Microsoft 365 accounts.
  • Collection: After gaining access to email accounts, the attackers use a command-line utility called office-cli to target Outlook 365 and exfiltrate emails.

MITRE ATT&CK Techniques

Impact Assessment

The activities of ITG and Flax Typhoon pose a significant threat to global critical infrastructure and government entities. The targets listed—including a power company in South Carolina, a Polish airport, and Taiwanese gas and power companies—demonstrate a clear focus on sectors with strategic importance. A successful compromise of these entities could lead to operational disruptions, espionage, or pre-positioning for future disruptive attacks. The joint advisory and DOJ action represent a coordinated effort by Western governments to expose and disrupt this state-sponsored commercial hacking ecosystem.

IOCs — Directly from Articles

The articles mention the names of tools but do not provide specific file hashes, domains, or IPs.

  • Tools: FishHub, MicroScan, EBurst, office-cli

Cyber Observables — Hunting Hints

Security teams can hunt for TTPs associated with ITG and Flax Typhoon:

Type
command_line_pattern
Value
office-cli
Description
The presence or execution of the office-cli utility is a strong indicator of this actor's activity.
Context
EDR logs, file system analysis
Confidence
high
Type
log_source
Value
Microsoft 365 unified audit log
Description
Search for a high volume of failed login attempts from a single IP followed by a success, indicative of a password spray attack using EBurst.
Context
SIEM, M365 Security Center
Confidence
high
Type
network_traffic_pattern
Value
Anomalous PowerShell to graph.microsoft.com
Description
Attackers often use PowerShell to interact with the Microsoft Graph API for email exfiltration after compromising an account.
Context
EDR logs, proxy logs
Confidence
medium
Type
vulnerability_signature
Value
XSS patterns in web logs
Description
Monitor WAF and web server logs for common cross-site scripting payloads, which ITG is known to use for initial access.
Context
WAF logs, web server logs
Confidence
medium

Detection & Response

  • Monitor M365 Logs: Closely monitor Microsoft 365 audit logs for signs of password spraying, impossible travel alerts, and anomalous mailbox access rules being created. This aligns with D3FEND Domain Account Monitoring (D3-DAM).
  • Endpoint Detection: Use an EDR solution to detect the execution of suspicious command-line utilities or PowerShell scripts used for email collection, such as office-cli.
  • Web Application Firewall (WAF): Implement a WAF to detect and block attempts to exploit web vulnerabilities like XSS.

Mitigation

  • Multi-Factor Authentication (MFA): Enforce phishing-resistant MFA on all user accounts, especially for cloud services like Microsoft 365. This is the most effective defense against password spraying attacks.
  • Patch Management: Aggressively patch public-facing applications to prevent exploitation of known vulnerabilities. This is a fundamental aspect of D3FEND Software Update (D3-SU).
  • Block Legacy Authentication: Disable legacy authentication protocols (e.g., POP, IMAP, SMTP AUTH) in Microsoft 365, as these protocols do not support MFA and are frequently abused in password spraying campaigns.
  • Threat Intelligence Integration: Integrate threat intelligence feeds from government advisories (like this one) into security tools to automatically block known malicious indicators and detect TTPs associated with actors like Flax Typhoon.

Timeline of Events

1
October 8, 2026
An international coalition of cybersecurity agencies releases a joint advisory on Integrity Technology Group (ITG).
2
October 8, 2026
The U.S. Department of Justice announces the seizure of domains and tools used by ITG.
3
October 10, 2026
This article was published

Article Updates

October 11, 2026

US seizes 7 domains for Flax Typhoon's Microscan/FishHub tools; new details reveal Mirai botnet use, SoftEther VPN for persistence, and 5 CVEs added to CISA KEV.

MITRE ATT&CK Mitigations

The most effective countermeasure against the password spraying attacks conducted with the EBurst tool.

Patching web application vulnerabilities mitigates the initial access vector of exploiting flaws like XSS.

Enforcing strong password policies and blocking commonly used passwords makes password spraying less effective.

Disabling legacy authentication protocols in Microsoft 365 that do not support MFA is a critical hardening step.

D3FEND Defensive Countermeasures

The use of the 'EBurst' tool for password spraying against Microsoft 365 is a primary TTP of ITG. The single most effective defense against this technique is enforcing Multi-factor Authentication (MFA) across all accounts. Specifically, organizations should prioritize phishing-resistant MFA, such as FIDO2 hardware keys, for administrators and high-value users. Additionally, a critical complementary step is to explicitly block legacy authentication protocols (like POP, IMAP, SMTP AUTH) in the Microsoft 365 tenant. Attackers favor these older protocols for password spraying because they often bypass MFA, providing a direct path to compromise. By enabling modern authentication and enforcing MFA, organizations can neutralize this entire attack vector.

To detect password spraying and subsequent account abuse, continuous monitoring of cloud identity logs is essential. Security teams should configure alerts in their SIEM or Microsoft 365 Defender for high rates of failed logins from a single IP address across many accounts. This is the classic signature of a password spray. Following a successful compromise, further alerts should be configured for anomalous behavior, such as 'impossible travel' (logins from geographically distant locations in a short time), the creation of new inbox rules for email forwarding, or unusual API access, such as that from the 'office-cli' tool. This provides layered detection for both the initial access attempt and post-compromise activity.

ITG's use of 'MicroScan' for vulnerability scanning and exploitation of flaws like XSS highlights the need for strong perimeter defenses. A properly configured Web Application Firewall (WAF) can detect and block many of the 1,300 penetration testing scripts contained in MicroScan. The WAF should be deployed in blocking mode and have rulesets enabled to protect against common web attacks like cross-site scripting, SQL injection, and command injection. Integrating the WAF with a threat intelligence platform that includes indicators from government advisories can further enhance its effectiveness by blocking traffic from known malicious infrastructure used by ITG and Flax Typhoon.

Timeline of Events

1
October 8, 2026

An international coalition of cybersecurity agencies releases a joint advisory on Integrity Technology Group (ITG).

2
October 8, 2026

The U.S. Department of Justice announces the seizure of domains and tools used by ITG.

Sources & References(when first published)

UK and Allies Warn of Cyber Threat from China's Integrity Technology Group
Infosecurity Magazine (infosecurity-magazine.com) •October 9, 2026
DOJ seizes hacking tools used in China-backed critical infrastructure attacks
Cybersecurity Dive (cybersecuritydive.com) •October 9, 2026
Cyber / Brief — 9 Oct 2026
Cyberverso (cyberverso.net) •October 9, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Threat ActorFlax TyphoonState-SponsoredChinaCritical InfrastructureEspionage

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.