Skip to content
TrustList
News

Seven countries tie old exploited flaws to China's Integrity Tech

Editorial

By TrustList Editorial

Advisory AA26-281A names eight CVEs, SoftEther persistence and Exchange password spraying, while the FBI seized seven domains behind the MicroScan and FishHub tools.

About Seven countries tie old exploited flaws to China's Integrity Tech

Seven countries tie old exploited flaws to China's Integrity Tech

8 October 2026: Security agencies from seven countries have published joint advisory AA26-281A, which links eight exploited CVEs, a custom web scanner and a phishing kit to Integrity Technology Group, a China-based contractor with links to the Chinese government, behind the activity known as Flax Typhoon. On the same day the US Justice Department and FBI seized seven domains that gave the company and its clients access to two of those tools, MicroScan and FishHub.

The advisory explains the five old flaws CISA added to its Known Exploited Vulnerabilities catalogue on 8 October, in Strapi, ONLYOFFICE Docs, Apache Struts, ISC BIND and ProFTPD, which we reported in our 8 October item. They came from exploit scripts the FBI recovered during its investigations.

Who signed and what they found

The authors are the FBI, CISA and NSA in the United States, the UK's National Cyber Security Centre, the Australian Signals Directorate's ACSC, the Canadian Centre for Cyber Security, Japan's National Police Agency and National Cybersecurity Office, New Zealand's NCSC and Spain's Centro Nacional de Inteligencia. They describe Integrity Tech as a for-profit company that builds and sells tools, hosts infrastructure and breaks into networks for others, and they list targets in US government, manufacturing, healthcare and IT, as well as law enforcement, schools and religious groups in Southeast Asia, Africa and North America.

MicroScan, in use since at least 2017, is a Python web application holding more than 1,300 scripts written to probe for specific flaws in products such as Oracle WebLogic, Jenkins, Juniper ScreenOS, WordPress and Apache Struts. According to the Justice Department, its targets included a South Carolina power company, airports in Japan and Poland and Taiwanese gas and power firms. FishHub ran spear-phishing campaigns and then pulled in further malware; the department says about 20 Taiwanese universities were confirmed victims.

"The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity," said Brett Leatherman, assistant director of the FBI's Cyber Division.

The eight flaws in the exploit kit

The advisory's appendix lists the CVEs that the recovered scripts exploited successfully:

  • CVE-2014-6278, GNU Bash through 4.3 bash43-026, remote code execution
  • CVE-2015-3306, ProFTPD 1.3.5, unauthorised file read
  • CVE-2015-5477, ISC BIND 9 before 9.9.7-P2 and 9.10.2-P3, denial of service
  • CVE-2016-3081, Apache Struts 2.3.19 to 2.3.28 lines, remote code execution
  • CVE-2019-11510, Pulse Connect Secure 8.2, 8.3 and 9.0 before the fixed releases, unauthorised file read
  • CVE-2021-22205, GitLab from 11.9, remote code execution
  • CVE-2021-3199, ONLYOFFICE DocumentServer 5.1.5 to 5.6.2, unauthorised write
  • CVE-2023-22894, Strapi up to 4.5.5, information disclosure

Every one has had a fix for years. What the list shows is how long unpatched servers stay reachable, and that a scanner built in 2017 still finds them.

Signs to hunt for on your own network

The technical section is more useful than the CVE list for most teams. The actors install the SoftEther VPN client on compromised machines, often renamed conhost.exe or dllhost.exe and set to reconnect at startup, which endpoint tools tend to ignore because SoftEther is legitimate software. They spray passwords at Exchange and Microsoft 365 through the open source EBurst tool, across OWA, EWS, ActiveSync, Autodiscover, MAPI and the other interfaces the advisory names. They read mailboxes through a PHP bot called Curlc4 that talks to the EWS API, use an office-cli utility with stolen app credentials (client_id, tenant_id and secret) to keep pulling Outlook 365 mail, and run DC.exe to perform DCSync against Active Directory.

The agencies publish the indicators as STIX files alongside the advisory. Their mitigations include multifactor authentication for webmail, VPNs and accounts with access to critical systems, watching for unexpected Active Directory replication, reviewing which applications are connected to cloud accounts, and replacing end-of-life products.

Our email security software category lists 11 products, our SIEM software category lists 15 and our vulnerability management software category lists 16.

The second strike against the same company

This is the Justice Department's second public disruption of Integrity Tech. In September 2024 it took down the company's Mirai botnet of more than 200,000 consumer devices. The court papers for the new seizures were unsealed in the Western District of Pennsylvania, and the FBI's San Diego and Baltimore field offices are investigating, with help from Japan's National Police Agency.

Related on TrustList:

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy