
Ten agencies from seven countries document how Integrity Technology Group, a Chinese company sanctioned by the US Treasury since January 2025, supplies automated scanners, botnets, hijacked VPNs and exfiltration scripts to actors linked to Flax Typhoon. Eight old vulnerabilities, five of them just added to CISA’s KEV catalogue, remain successfully exploited.
The facts
On 8 October 2026, the United States cybersecurity agency CISA (1) published, together with the FBI (2), the NSA (3), the United Kingdom’s NCSC-UK (4), Australia’s ASD (5) through its ACSC (6), the Canadian Centre for Cyber Security, Japan’s NPA (7) and NCO (8), New Zealand’s NCSC-NZ (9) and Spain’s CNI (10), a joint advisory referenced AA26-281A. Ten agencies from seven countries describe in it how a Chinese company, Integrity Technology Group (Integrity Tech), enables China-linked cyber actors to steal sensitive data from organisations worldwide, including United States critical infrastructure sectors.
The document draws on technical material gathered during several FBI investigations into Integrity Tech. It describes a coherent set of TTPs (11): vulnerability research using open source scanning tools, cross-site scripting (XSS) (12) attacks, password spraying against Microsoft Exchange accounts, persistence through a hijacked VPN (13), and exfiltration of mailboxes through custom scripts. The victims identified span the Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology sectors in the United States, as well as law enforcement agencies, educational institutions and religious organisations in Southeast Asia, Africa and North America.
The advisory does not describe a novel intrusion but an access and tooling provider, Integrity Tech, already sanctioned by the US Treasury in January 2025 for its infrastructure role on behalf of Flax Typhoon. Eight old CVEs (14), most of them dated between 2014 and 2023, remain the preferred entry point; five of them have just been added to CISA’s KEV (15) catalogue on the very day the advisory was published, with a remediation deadline of 11 October 2026.
Integrity Tech and the Flax Typhoon ecosystem
Integrity Tech is a for-profit Chinese company, based in Beijing and linked to the Chinese government. Its employees support malicious cyber activity in several ways: acquiring or developing tools, hosting infrastructure, and directly compromising networks at victims worldwide. The advisory refers to the whole of this activity, attributed to China, under the generic term actors; this article uses the same term to refer to the cyber actors that Integrity Tech supports.
On 3 January 2025, OFAC (16), the US Treasury office responsible for economic sanctions, had already targeted Integrity Tech for its infrastructure role in several computer intrusions publicly attributed to Flax Typhoon between summer 2022 and autumn 2023. The Treasury noted that Integrity Tech hosted infrastructure used by Flax Typhoon for its CNE (17) activity, with regular exchanges of information between the two. Integrity Tech’s US assets were blocked and any transaction with the company by a US person was prohibited.
The AA26-281A advisory states that the actors supported by Integrity Tech employ TTPs consistent with activity publicly known under the names Flax Typhoon, Ethereal Panda and Red Juliett, among others. The signing authorities note that cybersecurity companies track and attribute actors using different methods, which do not necessarily map one to one onto the US government’s methodology for this activity as a whole.
The advisory explicitly states that the actors supported by Integrity Tech may also carry out activity unconnected to the company. The link established is that of an infrastructure and tooling provider observed across several FBI investigations, not that of a single, exclusive operator behind all activity carrying the Flax Typhoon label.
Reconnaissance: the open source scanning arsenal
The actors rely on a wide range of open source scanning tools to identify vulnerabilities in networks and web applications: BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe and wpscan. Several of these tools can fingerprint a remote application, test authentication protocols or enumerate a site’s pages. According to the authorities, the use of open source tools widely available on GitHub points to a search for the most vulnerable targets rather than bespoke targeting.
Scanning focuses on ports 21 (FTP (18)), 22 (SSH (19)), 53 (DNS (20)), 80 (HTTP (21)), 443 (HTTPS (22)) and 1080 (SOCKS (23)). When using dirsearch against a website, the actors specifically look to enumerate PHP (24) and ASP (.NET) pages.
MicroScan, a penetration testing platform since 2017
Since at least 2017, the actors have also used an application called MicroScan. This Python web application bundles more than 1,300 penetration testing scripts written to search for specific vulnerabilities on websites. The scripts target OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins and Apache Struts, among others. The CVEs successfully exploited and found in these penetration testing scripts are covered in the next section.
- Associated ATT&CK technique: Active Scanning: Vulnerability Scanning, T1595.002
- First documented use of MicroScan: as early as 2017
- Contents of MicroScan: more than 1,300 penetration testing scripts
Eight old vulnerabilities, still effective
Appendix B of the advisory lists eight CVEs successfully exploited by MicroScan’s penetration testing scripts. Five of them, marked with an asterisk by the authorities, have just been added to CISA’s KEV catalogue: checking the catalogue’s JSON feed confirms an addition dated 8 October 2026, the day the advisory was published, with a remediation deadline set at 11 October 2026. The other three had already been on the catalogue for longer: two since 3 November 2021 (Pulse Connect Secure and GitLab, both flagged with a history of ransomware exploitation) and one since 2 October 2025 (Bash).
| CVE | Vendor / Product | Affected versions | Nature | KEV |
|---|---|---|---|---|
CVE-2014-6278CWE (25)-78 | GNU Bash | Up to 4.3, including patch level bash43-026 | Remote code execution | Yes, since 2 October 2025 |
CVE-2015-3306*CWE-284 | ProFTPD | 1.3.5 | Unauthenticated arbitrary file read and write | Yes, added 8 October 2026 |
CVE-2015-5477*CWE-19 | ISC BIND 9.x | Before 9.9.7-P2 and 9.10.x before 9.10.2-P3 | Denial of service | Yes, added 8 October 2026 |
CVE-2016-3081*CWE-77 | Apache Struts | 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28 | Remote code execution (dynamic method invocation) | Yes, added 8 October 2026 |
CVE-2019-11510CWE-22 | Pulse Connect Secure | 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, 9.0 before 9.0R3.4 | Unauthenticated arbitrary file read | Yes, since 3 November 2021 |
CVE-2021-22205CWE-94 | GitLab CE/EE | All versions from 11.9 onward | Unauthenticated remote code execution | Yes, since 3 November 2021 |
CVE-2021-3199*CWE-22 | ONLYOFFICE DocumentServer | 5.1.5 to 5.6.2 | Unauthenticated arbitrary file write | Yes, added 8 October 2026 |
CVE-2023-22894*CWE-312 | Strapi | Up to 4.5.5 | Information disclosure from the admin panel | Yes, added 8 October 2026 |
Fig. 1. The eight CVEs successfully exploited (Appendix B of the advisory). The asterisk marks the five CVEs added to the KEV catalogue on 8 October 2026; KEV status and dates were verified against the catalogue’s JSON feed, independently of the advisory’s text.
For CVE-2023-22894, the CVSS (26) score published by the NVD (0.49, i.e. 4.9, based on a high privilege requirement) diverges noticeably from a secondary score of 7.2 for the same vector without the privilege metric: both assess access to the Strapi admin panel, not a flaw exploitable without authentication. Nothing in the AA26-281A advisory indicates that the actors already held administrator access before exploiting this CVE; the full exploitation chain is not detailed.
Initial access: the XSS trap and the fake Windows process
Since at least mid-January 2021, the actors have accessed their victims’ networks and cloud services mainly through command-line utilities built on exploit code written in Python and Go. They also use JavaScript and HTML code to carry out XSS attacks, which hijack an unwitting third-party application vulnerable to XSS to modify a web page’s content and reach further victims.
The FBI recovered an XSS payload used by the actors. Executed on a vulnerable website running JavaScript, it modifies the page’s content to display username and password fields, with the aim of harvesting the credentials the victim enters. Once any username and password are entered, the page generated by the XSS payload offers a download link to a password-protected .zip archive. The contents of that archive come from bytes encoded directly in the XSS payload and contain the executable live700_v1.exe.
Analysis of live700_v1.exe shows that it starts a process named DiagTrack.exe, which reuses the name of a legitimate Windows utility. DiagTrack.exe then establishes encrypted HTTP communications with the domain dns.studiocloud[.]xyz, which the FBI attributes to Integrity Tech. As the executable contains functions that query mailbox data, the FBI assesses that this malware probably aims at mailbox data exfiltration.
Website vulnerable to XSS → XSS payload displaying fake username and password fields → password-protected .zip archive containing live700_v1.exe → process renamed DiagTrack.exe → encrypted HTTP channel to dns.studiocloud[.]xyz.
EBurst and password spraying against Exchange
The actors use EBurst, an open source Python tool, to target accounts in the Microsoft Office 365 Cloud environment. The tool compromises mailbox accounts on Microsoft Exchange servers by combining several interfaces to carry out password spraying and password guessing against each supplied email address. According to the ReadMe file of the open source EBurst project, these interfaces include:
- ECP (27), the Exchange control panel
- EWS (28), Exchange Web Services
- OAB (29), the offline address book
- OWA (30), Outlook Web Access
- RPC (31), remote procedure call
- API (32)
- MAPI (33), the messaging application programming interface
- PowerShell
- Autodiscover
- Microsoft-Server-ActiveSync
Network defenders are encouraged to cover all of these interfaces, not just OWA or EWS, in their monitoring and detection rules against EBurst.
Persistence: a hijacked legitimate VPN
To establish lasting persistence, the actors deploy VPN clients on victims’ equipment to conceal command-and-control (C2 (34)) communications and the rest of their actions, which complicates attribution of the malicious network activity. For this they use SoftEther, a legitimate, open source VPN product.
On Windows, the actors download the SoftEther installers from infrastructure they control, using PowerShell or LOTL (35) binaries. On Linux and Unix, they download them using curl or wget. In both cases, the SoftEther client is configured to reconnect automatically on startup. The actors frequently name these installers conhost.exe or dllhost.exe, so that they resemble common Windows executables. Because SoftEther is a legitimate VPN product, endpoint detection tools flag it less readily than a dedicated tool.
In several observed cases, the actors installed the SoftEther program directly on the server. Analysis of these servers revealed victim domains and subdomains hosting the SoftEther connections: 98aiblog[.]com, hmbcloud[.]com, hmbcloud[.]net, hmbiplc-01[.]com, iepl.node[.]cm, javacheck.ooguy[.]com, javaupdate.giize[.]com, sexytube0[.]com and twimg.co[.]uk.
The FBI has observed the actors installing the client on the end-user workstation, which then connects to the command-and-control server through one of these domains, subdomains, or directly through the server’s IP (36) address. From these same waypoints, the actors have also accessed other targets, including the websites of cybersecurity companies.
Collection and exfiltration of mailbox data
The FBI has observed the actors downloading databases or manually extracting data from victims’ mailboxes, then staging it for exfiltration under inconspicuous file names intended to minimise detection of a MySQL mailbox export: 001.gif, All_scanner_vXX.pl.gz (where XX represents a one- or two-digit number), css.js, include.png, m2k.js, m2k_list.js and m2k_ui_adm.js.
Curlc4.txt, a PHP bot for the EWS API
The FBI has observed the actors building a bot using the PHP script Curlc4.txt to obtain victims’ messages. The script is designed to interface with Microsoft’s EWS API, which provides access to messages and other content such as calendars and contacts. The script appears to run standalone rather than being permanently installed on a compromised system; it uploads messages to a remote server, hides some of the directories and files it creates, and renames its child process crypto.
The script downloads the original file from https://upl.natcloudservice[.]com at IP address 149.28.132[.]137. The bot’s main C2 domain is natcloudservice[.]com, which communicates with https://natcloudservice[.]com/ews and upl.natcloudservice[.]com/ews. Before exfiltration, the bot compresses the messages; in some cases, the actors also encrypt the messages with a password, using RC4 (37) or AES (38)-128-CBC.
The PHP script accepts up to two command-line arguments. The first appears to designate the root directory for script execution; if it is not supplied, the script searches for a writable directory following the order in Table 1, and stores the second argument there in a variable saved on the targeted system.
| Directory searched | Subdirectories skipped |
|---|---|
/ | /bin, /boot, /dev, /etc, /run, /proc, /sys, /var, /tmp, /usr |
/home | None |
/var/www | None |
/usr | None |
/var/tmp | None |
Fig. 2. Directories searched by Curlc4 looking for a writable location (Table 1 of the advisory).
Unique strings found in the script: $dir/storage/fm/.run ; $dir/.run ; public $password='jh4jnryw76ikmh' ; public $file='/var/tmp/.sess.zip' ; https://upl.natcloudservice[.]com/ews ; public $key='rhnr5m54pk65wertc' ; the RC4 setting ($this->enc="r";$this->cipher="rc4";$this->iv="") ; the AES-128-CBC setting ($this->enc="a";$this->cipher="aes-128-cbc";$this->iv="1111111111111111") ; https://natcloudservice[.]com/ews ; and the custom HTTP header curl_setopt($this->ch, CURLOPT_HTTPHEADER,array("X-Id: $clientid")). Other directories and files indicate that the script has run on a system: RUNNING_DIRECTORY/storage/fm, RUNNING_DIRECTORY/storage/fm.run (file), RUNNING_DIRECTORY/.run, RUNNING_DIRECTORY/clientid (file) and RUNNING_DIRECTORY/cp (file).
DC.exe and DCSync replication
The actors use DC.exe to carry out the DCSync replication technique, which copies sensitive Active Directory (AD (39)) information: account credentials, group membership details and trust relationships. DC.exe establishes an RPC connection to the victim’s domain controller, then uses the directory replication service to extract data from it. It notably retrieves a handle to the local security policy object, used to query the domain controller for the DNS domain name, the domain SID (40) and the domain’s replication epoch. The file also relies on nineteen object identifiers (LDAP OIDs) to retrieve Active Directory attributes and configurations, including 1.2.840.113556.1.2.48, 1.2.840.113556.1.4.1 and 1.2.840.113556.1.4.609; the full list of the nineteen OIDs appears in the original advisory.
Exfiltrated data and access restriction
The FBI recovered an archived mailbox database that the actors used to target victim organisations’ mailbox accounts. The actors collect account credentials and exfiltrate mailbox data from both on-premises systems and cloud services. Victims identified for mailbox data theft include government organisations, law enforcement services, healthcare systems and religious institutions in Southeast Asia. In some cases, the actors restricted access to the exfiltrated data to IP addresses located in Xiamen, China, only.
Office-cli, automating Microsoft 365 exfiltration
The actors use the office-cli command-line utility to target and maintain ongoing access to Microsoft Outlook 365 mailbox accounts, exfiltrating their content over various periods. They occasionally refresh these accounts and replace them with more recent ones. office-cli automates access to and exfiltration of mailbox content from configuration files such as client_id, tenant_id and secret.
The FBI has observed the actors running office-cli from the command line or from a Bash script. In both cases, they place the JSON (41) files needed to access the mailboxes in the configuration directory; office-cli then saves the collected data to a subdirectory of the dump directory. The actors evade detection using this tool because it relies on legitimate access methods. They also operate a custom web application that gives third parties access to the stolen mailbox content, in which a user can pass specific arguments in a URL (42) to view the content of a given account.
ATT&CK mapping
The advisory itself gives its own mapping to the ATT&CK (43) framework, stating that it uses version 19 of the framework. Each technique identifier has been verified here against the official STIX (44) data of ATT&CK Enterprise, version 19.2: all the identifiers cited are valid and match the label given by the authorities.
| Tactic (as named by the advisory) | Technique | Observed use |
|---|---|---|
| Reconnaissance | T1595.002 Active Scanning: Vulnerability Scanning | Scanning tools used to identify network and application vulnerabilities |
| Initial Access | T1189 Drive-by Compromise | XSS attacks hijacking a third-party application to modify a page’s content |
| Execution | T1059.001 Command and Scripting Interpreter: PowerShell | Downloading the SoftEther installers |
| Execution | T1059.004 Command and Scripting Interpreter: Unix Shell | office-cli run from a Bash script |
| Execution | T1059.006 Command and Scripting Interpreter: Python | Command-line utilities built on Python exploit code |
| Execution | T1059.007 Command and Scripting Interpreter: JavaScript | Execution of the XSS attacks |
| Persistence | T1133 External Remote Services | SoftEther VPN clients installed for persistence |
| Defense Evasion | T1036.003 Masquerading: Rename Legitimate Utilities | Executables renamed conhost.exe, dllhost.exe, DiagTrack.exe |
| Credential Access | T1003.006 OS Credential Dumping: DCSync | DC.exe against Active Directory |
| Credential Access | T1110.001 Brute Force: Password Guessing | EBurst against Exchange accounts |
| Credential Access | T1110.003 Brute Force: Password Spraying | EBurst against Exchange accounts |
| Collection | T1114.002 Email Collection: Remote Email | PHP script interfacing with the EWS API |
| Collection | T1560.003 Archive Collection Data: Archive via Custom Method | Compression and RC4 or AES-128-CBC encryption of messages before exfiltration |
| Collection | T1074.001 Data Staged: Local Data Staging | PHP script searching for a writable directory |
| Exfiltration | T1020 Automated Exfiltration | Automatic upload of messages to a remote server |
Fig. 3. ATT&CK Enterprise v19.2 mapping, taken from the AA26-281A advisory and verified against the official STIX data.
The advisory labels its defense-evasion table “Defense Evasion”. However, in the ATT&CK Enterprise v19.2 STIX data, which the advisory itself says it uses, the tactic with identifier TA0005 has been renamed “Stealth”. The technique T1036.003 cited by the advisory is indeed attached there to the Stealth tactic, no longer to Defense Evasion. The discrepancy concerns only the label the authorities used in their own table, not the validity of the technique identifier itself.
Detection and hardening
If a compromise is detected
The authorities recommend identifying compromised hosts and isolating them, launching a threat hunt to scope the intrusion, collecting the relevant artefacts and logs to establish the timeline and the TTPs used, following national incident reporting obligations, and then applying eviction countermeasures. CISA provides a dedicated tool, the Eviction Strategies Tool, which combines the Playbook-NG web application with the COUN7ER post-compromise countermeasure database, to build a systematic eviction plan together with the expected outcome, preparatory steps and risks of each action.
Recommended mitigations
| Mitigation | Purpose |
|---|---|
| Disable unused services and ports (automatic configuration, remote access, file sharing) | Reduce the surface directly scanned by reconnaissance tools |
| Sanitise user input in web applications | Prevent the injection of XSS payloads |
| Put in place identity, credential and access management (ICAM (45)), and require MFA (46) for services, in particular webmail, VPNs and accounts with access to critical systems | Neutralise password spraying and password guessing against Exchange |
| Replace default passwords, limit and audit accounts with administrative privileges | Reduce the scope of an account compromise |
| Enable download and domain reputation filtering, and protective DNS resolution | Block downloads of known malware and connections to already-flagged infrastructure |
| Monitor for misuse of LOTL tools and unexpected Active Directory replication | Detect the use of DC.exe and the DCSync technique |
| Segment the network and apply the principle of least privilege | Limit the reach of a compromised device into the rest of the network |
| Monitor cloud accounts for connected applications able to access sensitive data | Spot office-cli-style misuse of access to Microsoft 365 mailboxes |
| Apply patches and updates, including firmware | Close the eight CVEs listed in section 4, most of them old and already fixed by the vendor |
| Monitor for abnormal volumes of outbound traffic or uploads | Spot exfiltration of compressed mailbox data to domains such as natcloudservice[.]com |
| Maintain a backup plan with offline, password-protected copies | Ensure restoration is possible in case of a breach of data integrity |
| Regularly raise user awareness and train users, and carry out regular penetration tests | Reduce the likelihood of successful initial access |
Fig. 4. Summary of the mitigations recommended by the authorities, aligned with CISA and NIST’s (48) CPGs (47).
The authorities also recommend continuously testing existing security controls against each of the ATT&CK techniques listed in section 9, using CISA Decider or an equivalent mapping tool, to objectively measure the actual performance of detections in place rather than assuming their coverage.
Indicators of compromise
The advisory publishes sixteen tables of indicators and mappings, with an explicit warning from the authorities: several indicators date back as far as 2016, and verification is recommended before any blocking action. The tables below reproduce in full the named indicators and the hash sets (webshells, binaries, dropped files), directly usable for detection. The two tables of raw domain names and IP addresses are very large (218 domain names and 516 IP addresses, with first-observed dates ranging from 2012 to 2024) and are not reproduced line by line here; they are available in full, in STIX format, directly from the original advisory (see Sources).
Domains and hosts directly attributed to the activity
Unlike the two raw tables, this table qualifies each entry by its role (infrastructure or SoftEther host) and overlaps with the domains already cited in section 7.
| Name | Role | First observed | Last observed |
|---|---|---|---|
96cee[.]com | Infrastructure | 29 Jun 2020 | 9 May 2024 |
dns.studiocloud[.]xyz | Infrastructure | 10 Dec 2021 | 9 May 2024 |
studiocloud[.]xyz | Infrastructure | 10 Dec 2021 | 9 May 2024 |
asean.twimg.co[.]uk | SoftEther host | 21 Sep 2024 | 15 Dec 2024 |
bj-hk.hmbcloud[.]net | SoftEther host | 29 Mar 2021 | 29 Mar 2021 |
bj-jp.hmbcloud[.]net | SoftEther host | 10 Apr 2021 | 7 May 2021 |
blog.98aiblog[.]com | SoftEther host | 12 Jul 2024 | 14 Aug 2024 |
bsnl.twimg.co[.]uk | SoftEther host | 17 Jun 2024 | 7 Jul 2024 |
eg.twimg.co[.]uk | SoftEther host | 22 Sep 2024 | 14 Dec 2024 |
etechhosting.twimg.co[.]uk | SoftEther host | 21 Sep 2024 | 16 Dec 2024 |
fcchk.twimg.co[.]uk | SoftEther host | 21 Sep 2024 | 14 Dec 2024 |
gz-hk.hmbcloud[.]net | SoftEther host | 28 Dec 2020 | 22 Jan 2021 |
iplc-hk.hmbcloud[.]com | SoftEther host | 30 Nov 2020 | 8 Dec 2020 |
javacheck.ooguy[.]com | SoftEther host | 22 Dec 2023 | 25 Jun 2024 |
javaupdate.giize[.]com | SoftEther host | 22 Dec 2023 | 15 Jun 2024 |
ls.twimg.co[.]uk | SoftEther host | 21 Sep 2024 | 14 Dec 2024 |
np.twimg.co[.]uk | SoftEther host | 21 Sep 2024 | 25 Nov 2024 |
one.hmbiplc-01[.]com | SoftEther host | 2 Apr 2022 | 2 Apr 2022 |
pw.sexytube0[.]com | SoftEther host | 6 Aug 2021 | 18 Apr 2024 |
senate.twimg.co[.]uk | SoftEther host | 21 Sep 2024 | 14 Dec 2024 |
sh-jp.hmbcloud[.]net | SoftEther host | 10 Apr 2021 | 25 Apr 2021 |
szxcm-hkg01.iepl.node[.]cm | SoftEther host | 7 Dec 2020 | 8 Jan 2021 |
tj.twimg.co[.]uk | SoftEther host | 21 Sep 2024 | 14 Dec 2024 |
ximmd.sexytube0[.]com | SoftEther host | 14 Jul 2020 | 31 Oct 2020 |
Fig. 5. The 24 domains and hosts directly attributed to the activity (Table 12 of the advisory).
Webshells
| File | MD5 (49) | SHA-256 (50) |
|---|---|---|
b374.php | 48ca18a25424a0f52276290b619a7a83 | 72c6af6a4be99e31c4a7a0aa4f01750792788e7f6f9749243a9f2c47c14a708f |
back.pl | 38f5ff8169423e2c756848c02e8cac3b | 456586ababa08f70216c4459f4d6375676166ebfddd98a33b447ceb5099e8dc5 |
error.jsp | d61326c4e6d24aa9b67e2b7a3ef7cedf | 2f5c406eb64ad8902c8e30610d43fd3efc05a14cdb8fb158818953eaf3dc6a81 |
file_back.aspx | f8de2e99dc7523d2c83d1a48e844c5ff | 5782ff2c835c88cc1ee521d2e8c523cfad73db3f9a29c93b40c4223f0338ade9 |
gf.phtml | 5b5a2c7fa705d8b1eb04da5db900b0d7 | 0e6fecb2d369b0eae63731616a3daada52036634885ab1b85b115af6bc5bcb86 |
yaml-payload.jar | 655cd134976d3e80c521708aa8be418b | 36f3b7645609ef40444dbc68f01d26c543d67689eda4937272ea5cfa4df1b522 |
Fig. 6. Six webshells from the actors’ CNE tooling repository (Table 13 of the advisory).
Tooling binaries and scripts
| File | Category | MD5 | SHA-256 |
|---|---|---|---|
ksubdomain | Enumeration | dae8f50ea44225fae3ba1f160b42bfdc | 670fa10a2ddde21fd594c4fef86b554d864089ed2de7153b472e921c623403ae |
ksubdomain_linux | Enumeration | fdece34bc084f1e252aeae274650eb8d | 645f6f2667af01a94d04a9d7a71916a13d9426835d636b4ceee2e25ccb34e525 |
oneforall.py | Enumeration | 596b990b0b389d906a8f4384837c1878 | 4d488f21269b18e37aaca93ac2a61707c9b611e506cdb3b287277746e94636b5 |
subDomainsBrute.py | Enumeration | a73eca669fe80628dbbd2c7d9bb14c8f | a14844e982f172d0f23910558c3f390a9d4c45dc32db825c2af7cf0ed8631db2 |
office-cli | Information extraction | be121e707f817aa9392c55af1e7ec2aa | add7dd142e4f7e2873bc8f7b7fb6308063608e0b49a773dea93abad4047f1489 |
JuicyPotato.exe | Privilege escalation | 7ce68f0dd85355ba2897a68521167e56 | e7e727458f573dded05537baddac2867d2801db1c3c74410398d063dfd6f6575 |
BBScan.py | Scanning | f82694de2f19e1bff333c27bb7eb7a56 | 8e1b56ef51ba70aa4c4cfd4430820f20875b354588d5d723ba4d3940ea6c924b |
dirmap.py | Scanning | 1933c314041415939331fce183939547 | 46e59172c40c95d83c3a6f24f801fc2265653c8b575b66a726463e2a4eebd7f2 |
dirsearch.py | Scanning | 8829f6f1cc5fc0aab2f6e71bfd7dc53d | 752b14c6e6936991d51fcd5ebf40d303e657c2372893604f96044848ad9a5f24 |
fscan.exe | Scanning | cf903e4a1629aa0582fd0363b5786676 | 7b9efc7ef8957411cdd22582ce4bfb3a5f76d9c91cdb7e36bf85c9785a2480e9 |
nbtscan.exe | Scanning | f01a9a2d1e31332ed36c1a4d2839f412 | c9d5dc956841e000bfd8762e2f0b48b66c79b79500e894b4efa7fb9ba17e4e9e |
nbtscan_linux | Scanning | ef713447f18f5b7ee16af4ac37ec4133 | 2fbcb1995c458e5affd5fb8f1f979a08ddce21714a2e413aa3d5dc44f9f245fe |
PackerFuzzer.py | Scanning | 8dcc4f9ccc6b6adf7eeeb3f51c95afad | 33790218d5871af646feef5be29e0596d4703a45ce675c1eb2ca00140b3a1bde |
ShuiZe.py | Scanning | b04375cca637f0702bf27feaff22a92d | c7f86a4623db5c90273cea041d43207849c5c6b0060c370b2095f13871b1366d |
sqlmap.py | Scanning | bcacc7ca999980d26c186ef791242fb5 | 2ecb51d7fa3bc3fa7ad7df64c6d0cd1f4ff2b37ed6839d3cff529fb08af49fb0 |
wpscan | Scanning | 1b8e29b6b7972fb124425aaa257f8f6d | efb0437e6a6a0f07169952f1a8b734299ec9a8b1faadbed811fe017f2cf54976 |
Fig. 7. Sixteen binaries and scripts from the CNE tooling repository (Table 14 of the advisory). Note that masscan and NMAP, cited in section 3, do not appear in this hash table: only their presence in the advisory’s text links them to the actors.
Files dropped on victims
| File | Category | MD5 | SHA-256 |
|---|---|---|---|
curlc4.txt | Malware | 4f61b9ab907f351bb40b37b10f4974d0 | 8b869a5edaff74ff18bca3658a519a19771e66d00ff7849af7a142dd6fc8da85 |
DiagTrack.exe | Malware | 6d57c42dee8bd7789969e2dd28671162 | 804a53be802378a8ec4c94602fd3d6584e0d472d83148e8a42c731950fec415d |
live700_v1.exe | Malware | 776807750280daad05348f931a33e4ef | c4503db6ece93eddf4511e787607cb14606a1df9f526f1e39992497119437cec |
conhost.exe | SoftEther | a973c0ab904c1b74655a906b99b76850 | b1552703ff0035f197c22cdb3a514bb6aa45ec98de3ef5409faab0978f18c35e |
dllhost.exe | SoftEther | f62cbbbdf35c7790909c26c7c5fbce05 | 8a592e22c51311d482272ec5aba0103c9cd0cfd78e5b5ba75dfa8f1c56926672 |
dllhost.exe | SoftEther | a05cdf6afcbb107961307f59cbab5e4f | 86f1cfa6a2e0a8cb6fc1fbee28472308e6467932f8658a6a4885e29ed8c34a67 |
b.exe | Information extraction | 7d5a182f70bed0e4fa2f8615aba070de | e93244080a749b521f63476343ce3c81cc8c1b672fa0d9e67359aee37544c784 |
dc.exe | Information extraction | 1bcaef76b2063f1b80b0fa0d277ec9c5 | 9dc85f9569a15eaf51c7d34254767ea30dd67b2178cec4cc7125288b9544fe00 |
secretsdump.exe | Information extraction | 4d33bfb75e27fefaa72526899604d557 | 644decbc6ce8c52382f4755fa6fc2cb4d89a0e7ec0e574c11b398a6f2eed04b1 |
secretsdump.py | Information extraction | fc6e8ca41cf4f6100177352660e520b4 | 67db57a1f957031b78f29aa91e2e87780eae3835290259eff846d8f14afb794b |
Fig. 8. Ten files potentially dropped on victims (Table 15 of the advisory). Two distinct copies of dllhost.exe appear with different hashes.
The 218 domain names (Table 10) and 516 IP addresses (Table 11) in the advisory span an observation window of more than ten years, with first-seen dates running back in some cases to 2012 or 2016. Many of these domains carry an old last-observed date (2020, 2021) and so no longer reflect active infrastructure. The STIX JSON and XML packages published by CISA (see Sources) carry the full, machine-readable contents of these two tables, suited for direct ingestion by a SIEM or an EDR.
Source qualification
The advisory is a joint primary source, co-signed by ten government bodies. The elements that can be verified independently have been cross-checked.
| Item | Status | Comment |
|---|---|---|
| OFAC sanction against Integrity Tech and its infrastructure link to Flax Typhoon | corroborated | US Treasury press release of 3 January 2025 and consistent reporting from several specialised outlets. |
| TTPs and tools specific to Integrity Tech (MicroScan, EBurst, Curlc4, DC.exe, office-cli) | single source | Technical material drawn from FBI investigations, with no independent third-party publication found as of 9 October 2026. |
| CVSS scores, CWEs and affected versions of the eight CVEs | corroborated | Compared against each CVE’s NVD record, accessed 9 October 2026. |
| Status and KEV catalogue addition date of the five CVEs marked with an asterisk | corroborated | Verified against the JSON feed of CISA’s KEV catalogue: addition dated 8 October 2026 for all five, confirming the advisory’s asterisk. |
| Identifiers and names of the fifteen ATT&CK techniques cited | corroborated | Verified against the official STIX data of ATT&CK Enterprise v19.2. |
| The “Defense Evasion” label in table 6 of the advisory | discarded | Tactic renamed “Stealth” in the v19.2 STIX data that the advisory itself says it uses; see section 9. |
| Full list of the 218 domain names and 516 IP addresses | single source | Reproduced as published by the signing authorities, not independently cross-checked given the volume. |
Assessment
This analysis is built on the full text of the AA26-281A advisory as published on 8 October 2026, without access to the full STIX files or to the samples themselves. The eight CVEs were compared against their respective NVD records, KEV status against the catalogue’s official JSON feed, and the fifteen ATT&CK identifiers against the Enterprise v19.2 STIX data. The two largest indicator tables (domains, IP addresses) were counted but not cross-checked line by line. The levels in the grid reflect judgement.
Glossary
- CISA (1): Cybersecurity and Infrastructure Security Agency, the United States cybersecurity and infrastructure security agency.
- FBI (2): Federal Bureau of Investigation, the United States federal police agency.
- NSA (3): National Security Agency, the United States signals intelligence agency.
- NCSC-UK (4): National Cyber Security Centre, the United Kingdom’s national cybersecurity centre.
- ASD (5): Australian Signals Directorate, Australia’s signals intelligence agency.
- ACSC (6): Australian Cyber Security Centre, the ASD’s cybersecurity centre.
- NPA (7): National Police Agency, Japan’s national police agency.
- NCO (8): National Cybersecurity Office, Japan’s national cybersecurity office.
- NCSC-NZ (9): National Cyber Security Centre, New Zealand’s national cybersecurity centre.
- CNI (10): Centro Nacional de Inteligencia, Spain’s national intelligence centre.
- TTP (11): Tactics, Techniques, and Procedures, the tactics, techniques and procedures used by an actor.
- XSS (12): Cross-Site Scripting, the injection of script executed client-side in a vulnerable web page.
- VPN (13): Virtual Private Network.
- CVE (14): Common Vulnerabilities and Exposures, the public identifier assigned to a vulnerability.
- KEV (15): Known Exploited Vulnerabilities, CISA’s catalogue of vulnerabilities whose exploitation has been observed.
- OFAC (16): Office of Foreign Assets Control, the US Treasury office responsible for economic sanctions.
- CNE (17): Computer Network Exploitation, the exploitation of a computer network for intelligence or intrusion purposes.
- FTP (18): File Transfer Protocol.
- SSH (19): Secure Shell, an encrypted remote access protocol.
- DNS (20): Domain Name System.
- HTTP (21): Hypertext Transfer Protocol, the web’s transfer protocol.
- HTTPS (22): HTTP Secure, HTTP encrypted using TLS.
- SOCKS (23): a protocol that relays network connections through a proxy server.
- PHP (24): a server-side scripting language widely used in web development.
- CWE (25): Common Weakness Enumeration, a classification of software weaknesses.
- CVSS (26): Common Vulnerability Scoring System, the system used to rate the severity of vulnerabilities.
- ECP (27): Exchange Control Panel, Microsoft Exchange’s control panel.
- EWS (28): Exchange Web Services.
- OAB (29): Offline Address Book, Exchange’s offline address book.
- OWA (30): Outlook Web Access, Outlook’s web interface.
- RPC (31): Remote Procedure Call.
- API (32): Application Programming Interface.
- MAPI (33): Messaging Application Programming Interface, Microsoft’s messaging programming interface.
- C2 (34): Command and Control, an actor’s command-and-control infrastructure.
- LOTL (35): Living Off the Land, the use of tools and binaries already present and legitimate on a system to carry out malicious actions.
- IP (36): Internet Protocol, the Internet’s addressing protocol.
- RC4 (37): Rivest Cipher 4, a stream cipher algorithm.
- AES (38): Advanced Encryption Standard, a block cipher algorithm.
- AD (39): Active Directory, Microsoft’s directory service.
- SID (40): Security Identifier, the unique security identifier of a Windows account or domain.
- JSON (41): JavaScript Object Notation, a text format for structured data.
- URL (42): Uniform Resource Locator, the address of a resource on the web.
- ATT&CK (43): Adversarial Tactics, Techniques, and Common Knowledge, the framework of attack tactics and techniques maintained by MITRE.
- STIX (44): Structured Threat Information Expression, a format for exchanging threat data, used to publish ATT&CK and this advisory’s indicators.
- ICAM (45): Identity, Credential, and Access Management.
- MFA (46): Multifactor Authentication.
- CPG (47): Cross-Sector Cybersecurity Performance Goal, a cross-sector cybersecurity performance goal defined by CISA and NIST.
- NIST (48): National Institute of Standards and Technology, the United States technical standards institute.
- MD5 (49): Message Digest 5, a hash function used here as a supplementary hash.
- SHA-256 (50): Secure Hash Algorithm 256-bit, the hash function used for file hashes.
Sources
- CISA, FBI, NSA, NCSC-UK, ASD’s ACSC, Canadian Centre for Cyber Security, NPA, NCO, NCSC-NZ, CNI, Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data, advisory AA26-281A, 8 October 2026. cisa.gov/aa26-281a
- CISA, indicator-of-compromise packages for advisory AA26-281A, STIX JSON (1,021.16 KB) and STIX XML (658.87 KB) formats, 8 October 2026. Links available from the advisory page above.
- U.S. Department of the Treasury, Office of Foreign Assets Control, Treasury Sanctions Technology Company for Support to Malicious Cyber Group, 3 January 2025. home.treasury.gov
- CISA, Known Exploited Vulnerabilities catalogue, JSON feed, accessed 9 October 2026. cisa.gov/known_exploited_vulnerabilities.json
- NIST, National Vulnerability Database, records for CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199 and CVE-2023-22894, accessed 9 October 2026. nvd.nist.gov
- MITRE, ATT&CK Enterprise v19.2, STIX data, accessed 9 October 2026. github.com/mitre-attack/attack-stix-data
- CISA, People’s Republic of China Threat Overview and Advisories, accessed 9 October 2026. cisa.gov/china
Marked TLP:CLEAR, PAP:CLEAR. Unlimited disclosure, no restriction on use.
The analysis presented here reflects the author’s own views and rests on the public sources listed above.


