Seven countries tie old exploited flaws to China's Integrity Tech
EditorialBy TrustList Editorial
Advisory AA26-281A names eight CVEs, SoftEther persistence and Exchange password spraying, while the FBI seized seven domains behind the MicroScan and FishHub tools.
About Seven countries tie old exploited flaws to China's Integrity Tech
Seven countries tie old exploited flaws to China's Integrity Tech
8 October 2026: Security agencies from seven countries have published joint advisory AA26-281A, which links eight exploited CVEs, a custom web scanner and a phishing kit to Integrity Technology Group, a China-based contractor with links to the Chinese government, behind the activity known as Flax Typhoon. On the same day the US Justice Department and FBI seized seven domains that gave the company and its clients access to two of those tools, MicroScan and FishHub.
The advisory explains the five old flaws CISA added to its Known Exploited Vulnerabilities catalogue on 8 October, in Strapi, ONLYOFFICE Docs, Apache Struts, ISC BIND and ProFTPD, which we reported in our 8 October item. They came from exploit scripts the FBI recovered during its investigations.
Who signed and what they found
The authors are the FBI, CISA and NSA in the United States, the UK's National Cyber Security Centre, the Australian Signals Directorate's ACSC, the Canadian Centre for Cyber Security, Japan's National Police Agency and National Cybersecurity Office, New Zealand's NCSC and Spain's Centro Nacional de Inteligencia. They describe Integrity Tech as a for-profit company that builds and sells tools, hosts infrastructure and breaks into networks for others, and they list targets in US government, manufacturing, healthcare and IT, as well as law enforcement, schools and religious groups in Southeast Asia, Africa and North America.
MicroScan, in use since at least 2017, is a Python web application holding more than 1,300 scripts written to probe for specific flaws in products such as Oracle WebLogic, Jenkins, Juniper ScreenOS, WordPress and Apache Struts. According to the Justice Department, its targets included a South Carolina power company, airports in Japan and Poland and Taiwanese gas and power firms. FishHub ran spear-phishing campaigns and then pulled in further malware; the department says about 20 Taiwanese universities were confirmed victims.
"The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity," said Brett Leatherman, assistant director of the FBI's Cyber Division.
The eight flaws in the exploit kit
The advisory's appendix lists the CVEs that the recovered scripts exploited successfully:
- CVE-2014-6278, GNU Bash through 4.3 bash43-026, remote code execution
- CVE-2015-3306, ProFTPD 1.3.5, unauthorised file read
- CVE-2015-5477, ISC BIND 9 before 9.9.7-P2 and 9.10.2-P3, denial of service
- CVE-2016-3081, Apache Struts 2.3.19 to 2.3.28 lines, remote code execution
- CVE-2019-11510, Pulse Connect Secure 8.2, 8.3 and 9.0 before the fixed releases, unauthorised file read
- CVE-2021-22205, GitLab from 11.9, remote code execution
- CVE-2021-3199, ONLYOFFICE DocumentServer 5.1.5 to 5.6.2, unauthorised write
- CVE-2023-22894, Strapi up to 4.5.5, information disclosure
Every one has had a fix for years. What the list shows is how long unpatched servers stay reachable, and that a scanner built in 2017 still finds them.
Signs to hunt for on your own network
The technical section is more useful than the CVE list for most teams. The actors install the SoftEther VPN client on compromised machines, often renamed conhost.exe or dllhost.exe and set to reconnect at startup, which endpoint tools tend to ignore because SoftEther is legitimate software. They spray passwords at Exchange and Microsoft 365 through the open source EBurst tool, across OWA, EWS, ActiveSync, Autodiscover, MAPI and the other interfaces the advisory names. They read mailboxes through a PHP bot called Curlc4 that talks to the EWS API, use an office-cli utility with stolen app credentials (client_id, tenant_id and secret) to keep pulling Outlook 365 mail, and run DC.exe to perform DCSync against Active Directory.
The agencies publish the indicators as STIX files alongside the advisory. Their mitigations include multifactor authentication for webmail, VPNs and accounts with access to critical systems, watching for unexpected Active Directory replication, reviewing which applications are connected to cloud accounts, and replacing end-of-life products.
Our email security software category lists 11 products, our SIEM software category lists 15 and our vulnerability management software category lists 16.
The second strike against the same company
This is the Justice Department's second public disruption of Integrity Tech. In September 2024 it took down the company's Mirai botnet of more than 200,000 consumer devices. The court papers for the new seizures were unsealed in the Western District of Pennsylvania, and the FBI's San Diego and Baltimore field offices are investigating, with help from Japan's National Police Agency.
Related on TrustList:
- ChromeOS 16805.33.0 fixes 106 Chrome bugs, five of them Critical
- SonicWall SMA1000 CVSS 10 flaw now seeing exploitation attempts
Sources
- CISA and partners: Cybersecurity Advisory AA26-281A, Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data, 8 October 2026
- US Attorney's Office, Western District of Pennsylvania: Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers, 8 October 2026
- Australian Cyber Security Centre: advisory page for the same joint advisory, 8 October 2026
- iTnews: ASD joins seven-nation alert as US seizes Chinese hacking firm's tools, 11 October 2026
Categories & features
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.