A coalition of cybersecurity agencies from the U.S., U.K., and other allied nations has published a detailed joint advisory on Integrity Technology Group (ITG), a China-based company sanctioned for its role in global cyber espionage. The advisory, released on October 8, 2026, dissects ITG's function as a for-profit hacking contractor, developing and deploying cyber capabilities on behalf of Chinese state-sponsored threat actors, including the group known as Flax Typhoon (aka Ethereal Panda). The U.S. Department of Justice also announced the seizure of domains and hacking tools used by ITG, providing a rare public look into the commercial supply chain supporting China's state hacking operations.
The advisory provides a clear picture of the public-private partnership model used by China for its cyber operations. ITG acts as a 'hacker-for-hire' entity, providing the tools, infrastructure, and operational support for state-directed campaigns. Their targets are widespread and align with China's strategic interests, including critical infrastructure, government, healthcare, and manufacturing sectors across North America, Southeast Asia, and Africa.
The group's activities mimic those previously attributed to Flax Typhoon, a threat actor known for targeting entities in Taiwan and other regions. The U.S. government's seizure of ITG's tools, including FishHub and MicroScan, represents a direct disruption of their operations.
ITG employs a mix of open-source and custom-built tools to conduct its operations. Their methodology is systematic, beginning with broad scanning and progressing to targeted exploitation.
MicroScan, which contains over 1,300 penetration testing scripts, to scan networks for specific vulnerabilities.EBurst is used to conduct password spraying attacks against Microsoft 365 accounts.office-cli to target Outlook 365 and exfiltrate emails.T1595.002 - Vulnerability Scanning: The use of MicroScan and other tools to actively scan for weaknesses is a key part of their reconnaissance phase.T1190 - Exploit Public-Facing Application: The advisory mentions the exploitation of vulnerabilities like XSS in web applications.T1110.003 - Password Spraying: The tool EBurst is explicitly used for password spraying against Microsoft 365, a common technique to compromise accounts with weak passwords.T1114.002 - Remote Email Collection: The use of the office-cli tool to steal emails from compromised Outlook 365 accounts falls under this technique.T1588.002 - Tool: As a contractor, ITG's entire purpose is to 'Obtain Capabilities' by developing and acquiring tools like FishHub and MicroScan for use in attacks.The activities of ITG and Flax Typhoon pose a significant threat to global critical infrastructure and government entities. The targets listed—including a power company in South Carolina, a Polish airport, and Taiwanese gas and power companies—demonstrate a clear focus on sectors with strategic importance. A successful compromise of these entities could lead to operational disruptions, espionage, or pre-positioning for future disruptive attacks. The joint advisory and DOJ action represent a coordinated effort by Western governments to expose and disrupt this state-sponsored commercial hacking ecosystem.
The articles mention the names of tools but do not provide specific file hashes, domains, or IPs.
FishHub, MicroScan, EBurst, office-cliSecurity teams can hunt for TTPs associated with ITG and Flax Typhoon:
command_line_patternoffice-clioffice-cli utility is a strong indicator of this actor's activity.log_sourceMicrosoft 365 unified audit logEBurst.network_traffic_patternAnomalous PowerShell to graph.microsoft.comvulnerability_signatureXSS patterns in web logsoffice-cli.US seizes 7 domains for Flax Typhoon's Microscan/FishHub tools; new details reveal Mirai botnet use, SoftEther VPN for persistence, and 5 CVEs added to CISA KEV.
The most effective countermeasure against the password spraying attacks conducted with the EBurst tool.
Patching web application vulnerabilities mitigates the initial access vector of exploiting flaws like XSS.
Enforcing strong password policies and blocking commonly used passwords makes password spraying less effective.
Disabling legacy authentication protocols in Microsoft 365 that do not support MFA is a critical hardening step.
The use of the 'EBurst' tool for password spraying against Microsoft 365 is a primary TTP of ITG. The single most effective defense against this technique is enforcing Multi-factor Authentication (MFA) across all accounts. Specifically, organizations should prioritize phishing-resistant MFA, such as FIDO2 hardware keys, for administrators and high-value users. Additionally, a critical complementary step is to explicitly block legacy authentication protocols (like POP, IMAP, SMTP AUTH) in the Microsoft 365 tenant. Attackers favor these older protocols for password spraying because they often bypass MFA, providing a direct path to compromise. By enabling modern authentication and enforcing MFA, organizations can neutralize this entire attack vector.
To detect password spraying and subsequent account abuse, continuous monitoring of cloud identity logs is essential. Security teams should configure alerts in their SIEM or Microsoft 365 Defender for high rates of failed logins from a single IP address across many accounts. This is the classic signature of a password spray. Following a successful compromise, further alerts should be configured for anomalous behavior, such as 'impossible travel' (logins from geographically distant locations in a short time), the creation of new inbox rules for email forwarding, or unusual API access, such as that from the 'office-cli' tool. This provides layered detection for both the initial access attempt and post-compromise activity.
ITG's use of 'MicroScan' for vulnerability scanning and exploitation of flaws like XSS highlights the need for strong perimeter defenses. A properly configured Web Application Firewall (WAF) can detect and block many of the 1,300 penetration testing scripts contained in MicroScan. The WAF should be deployed in blocking mode and have rulesets enabled to protect against common web attacks like cross-site scripting, SQL injection, and command injection. Integrating the WAF with a threat intelligence platform that includes indicators from government advisories can further enhance its effectiveness by blocking traffic from known malicious infrastructure used by ITG and Flax Typhoon.
An international coalition of cybersecurity agencies releases a joint advisory on Integrity Technology Group (ITG).
The U.S. Department of Justice announces the seizure of domains and tools used by ITG.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.