Integrity Tech: the arsenal behind Flax Typhoon

Ten agencies from seven countries document how Integrity Technology Group, a Chinese company sanctioned by the US Treasury since January 2025, supplies automated scanners, botnets, hijacked VPNs and exfiltration scripts to actors linked to Flax Typhoon. Eight old vulnerabilities, five of them just added to CISA’s KEV catalogue, remain successfully exploited.

TLP:CLEAR   PAP:CLEAR   Unlimited disclosure, no restriction on use.
Published
9 October 2026
Subject
AA26-281A, Integrity Tech, Flax Typhoon
Distribution
Public
Confidence
High
Sources
7

The facts

On 8 October 2026, the United States cybersecurity agency CISA (1) published, together with the FBI (2), the NSA (3), the United Kingdom’s NCSC-UK (4), Australia’s ASD (5) through its ACSC (6), the Canadian Centre for Cyber Security, Japan’s NPA (7) and NCO (8), New Zealand’s NCSC-NZ (9) and Spain’s CNI (10), a joint advisory referenced AA26-281A. Ten agencies from seven countries describe in it how a Chinese company, Integrity Technology Group (Integrity Tech), enables China-linked cyber actors to steal sensitive data from organisations worldwide, including United States critical infrastructure sectors.

The document draws on technical material gathered during several FBI investigations into Integrity Tech. It describes a coherent set of TTPs (11): vulnerability research using open source scanning tools, cross-site scripting (XSS) (12) attacks, password spraying against Microsoft Exchange accounts, persistence through a hijacked VPN (13), and exfiltration of mailboxes through custom scripts. The victims identified span the Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology sectors in the United States, as well as law enforcement agencies, educational institutions and religious organisations in Southeast Asia, Africa and North America.

The takeaway

The advisory does not describe a novel intrusion but an access and tooling provider, Integrity Tech, already sanctioned by the US Treasury in January 2025 for its infrastructure role on behalf of Flax Typhoon. Eight old CVEs (14), most of them dated between 2014 and 2023, remain the preferred entry point; five of them have just been added to CISA’s KEV (15) catalogue on the very day the advisory was published, with a remediation deadline of 11 October 2026.

Integrity Tech and the Flax Typhoon ecosystem

Integrity Tech is a for-profit Chinese company, based in Beijing and linked to the Chinese government. Its employees support malicious cyber activity in several ways: acquiring or developing tools, hosting infrastructure, and directly compromising networks at victims worldwide. The advisory refers to the whole of this activity, attributed to China, under the generic term actors; this article uses the same term to refer to the cyber actors that Integrity Tech supports.

On 3 January 2025, OFAC (16), the US Treasury office responsible for economic sanctions, had already targeted Integrity Tech for its infrastructure role in several computer intrusions publicly attributed to Flax Typhoon between summer 2022 and autumn 2023. The Treasury noted that Integrity Tech hosted infrastructure used by Flax Typhoon for its CNE (17) activity, with regular exchanges of information between the two. Integrity Tech’s US assets were blocked and any transaction with the company by a US person was prohibited.

The AA26-281A advisory states that the actors supported by Integrity Tech employ TTPs consistent with activity publicly known under the names Flax Typhoon, Ethereal Panda and Red Juliett, among others. The signing authorities note that cybersecurity companies track and attribute actors using different methods, which do not necessarily map one to one onto the US government’s methodology for this activity as a whole.

Point of caution

The advisory explicitly states that the actors supported by Integrity Tech may also carry out activity unconnected to the company. The link established is that of an infrastructure and tooling provider observed across several FBI investigations, not that of a single, exclusive operator behind all activity carrying the Flax Typhoon label.

Reconnaissance: the open source scanning arsenal

The actors rely on a wide range of open source scanning tools to identify vulnerabilities in networks and web applications: BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe and wpscan. Several of these tools can fingerprint a remote application, test authentication protocols or enumerate a site’s pages. According to the authorities, the use of open source tools widely available on GitHub points to a search for the most vulnerable targets rather than bespoke targeting.

Scanning focuses on ports 21 (FTP (18)), 22 (SSH (19)), 53 (DNS (20)), 80 (HTTP (21)), 443 (HTTPS (22)) and 1080 (SOCKS (23)). When using dirsearch against a website, the actors specifically look to enumerate PHP (24) and ASP (.NET) pages.

MicroScan, a penetration testing platform since 2017

Since at least 2017, the actors have also used an application called MicroScan. This Python web application bundles more than 1,300 penetration testing scripts written to search for specific vulnerabilities on websites. The scripts target OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins and Apache Struts, among others. The CVEs successfully exploited and found in these penetration testing scripts are covered in the next section.

  • Associated ATT&CK technique: Active Scanning: Vulnerability Scanning, T1595.002
  • First documented use of MicroScan: as early as 2017
  • Contents of MicroScan: more than 1,300 penetration testing scripts

Eight old vulnerabilities, still effective

Appendix B of the advisory lists eight CVEs successfully exploited by MicroScan’s penetration testing scripts. Five of them, marked with an asterisk by the authorities, have just been added to CISA’s KEV catalogue: checking the catalogue’s JSON feed confirms an addition dated 8 October 2026, the day the advisory was published, with a remediation deadline set at 11 October 2026. The other three had already been on the catalogue for longer: two since 3 November 2021 (Pulse Connect Secure and GitLab, both flagged with a history of ransomware exploitation) and one since 2 October 2025 (Bash).

CVEVendor / ProductAffected versionsNatureKEV
CVE-2014-6278
CWE (25)-78
GNU BashUp to 4.3, including patch level bash43-026Remote code executionYes, since 2 October 2025
CVE-2015-3306*
CWE-284
ProFTPD1.3.5Unauthenticated arbitrary file read and writeYes, added 8 October 2026
CVE-2015-5477*
CWE-19
ISC BIND 9.xBefore 9.9.7-P2 and 9.10.x before 9.10.2-P3Denial of serviceYes, added 8 October 2026
CVE-2016-3081*
CWE-77
Apache Struts2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28Remote code execution (dynamic method invocation)Yes, added 8 October 2026
CVE-2019-11510
CWE-22
Pulse Connect Secure8.2 before 8.2R12.1, 8.3 before 8.3R7.1, 9.0 before 9.0R3.4Unauthenticated arbitrary file readYes, since 3 November 2021
CVE-2021-22205
CWE-94
GitLab CE/EEAll versions from 11.9 onwardUnauthenticated remote code executionYes, since 3 November 2021
CVE-2021-3199*
CWE-22
ONLYOFFICE DocumentServer5.1.5 to 5.6.2Unauthenticated arbitrary file writeYes, added 8 October 2026
CVE-2023-22894*
CWE-312
StrapiUp to 4.5.5Information disclosure from the admin panelYes, added 8 October 2026

Fig. 1. The eight CVEs successfully exploited (Appendix B of the advisory). The asterisk marks the five CVEs added to the KEV catalogue on 8 October 2026; KEV status and dates were verified against the catalogue’s JSON feed, independently of the advisory’s text.

Point of caution

For CVE-2023-22894, the CVSS (26) score published by the NVD (0.49, i.e. 4.9, based on a high privilege requirement) diverges noticeably from a secondary score of 7.2 for the same vector without the privilege metric: both assess access to the Strapi admin panel, not a flaw exploitable without authentication. Nothing in the AA26-281A advisory indicates that the actors already held administrator access before exploiting this CVE; the full exploitation chain is not detailed.

Initial access: the XSS trap and the fake Windows process

Since at least mid-January 2021, the actors have accessed their victims’ networks and cloud services mainly through command-line utilities built on exploit code written in Python and Go. They also use JavaScript and HTML code to carry out XSS attacks, which hijack an unwitting third-party application vulnerable to XSS to modify a web page’s content and reach further victims.

The FBI recovered an XSS payload used by the actors. Executed on a vulnerable website running JavaScript, it modifies the page’s content to display username and password fields, with the aim of harvesting the credentials the victim enters. Once any username and password are entered, the page generated by the XSS payload offers a download link to a password-protected .zip archive. The contents of that archive come from bytes encoded directly in the XSS payload and contain the executable live700_v1.exe.

Analysis of live700_v1.exe shows that it starts a process named DiagTrack.exe, which reuses the name of a legitimate Windows utility. DiagTrack.exe then establishes encrypted HTTP communications with the domain dns.studiocloud[.]xyz, which the FBI attributes to Integrity Tech. As the executable contains functions that query mailbox data, the FBI assesses that this malware probably aims at mailbox data exfiltration.

Observed chain

Website vulnerable to XSS → XSS payload displaying fake username and password fields → password-protected .zip archive containing live700_v1.exe → process renamed DiagTrack.exe → encrypted HTTP channel to dns.studiocloud[.]xyz.

EBurst and password spraying against Exchange

The actors use EBurst, an open source Python tool, to target accounts in the Microsoft Office 365 Cloud environment. The tool compromises mailbox accounts on Microsoft Exchange servers by combining several interfaces to carry out password spraying and password guessing against each supplied email address. According to the ReadMe file of the open source EBurst project, these interfaces include:

  • ECP (27), the Exchange control panel
  • EWS (28), Exchange Web Services
  • OAB (29), the offline address book
  • OWA (30), Outlook Web Access
  • RPC (31), remote procedure call
  • API (32)
  • MAPI (33), the messaging application programming interface
  • PowerShell
  • Autodiscover
  • Microsoft-Server-ActiveSync

Network defenders are encouraged to cover all of these interfaces, not just OWA or EWS, in their monitoring and detection rules against EBurst.

Persistence: a hijacked legitimate VPN

To establish lasting persistence, the actors deploy VPN clients on victims’ equipment to conceal command-and-control (C2 (34)) communications and the rest of their actions, which complicates attribution of the malicious network activity. For this they use SoftEther, a legitimate, open source VPN product.

On Windows, the actors download the SoftEther installers from infrastructure they control, using PowerShell or LOTL (35) binaries. On Linux and Unix, they download them using curl or wget. In both cases, the SoftEther client is configured to reconnect automatically on startup. The actors frequently name these installers conhost.exe or dllhost.exe, so that they resemble common Windows executables. Because SoftEther is a legitimate VPN product, endpoint detection tools flag it less readily than a dedicated tool.

In several observed cases, the actors installed the SoftEther program directly on the server. Analysis of these servers revealed victim domains and subdomains hosting the SoftEther connections: 98aiblog[.]com, hmbcloud[.]com, hmbcloud[.]net, hmbiplc-01[.]com, iepl.node[.]cm, javacheck.ooguy[.]com, javaupdate.giize[.]com, sexytube0[.]com and twimg.co[.]uk.

The FBI has observed the actors installing the client on the end-user workstation, which then connects to the command-and-control server through one of these domains, subdomains, or directly through the server’s IP (36) address. From these same waypoints, the actors have also accessed other targets, including the websites of cybersecurity companies.

Collection and exfiltration of mailbox data

The FBI has observed the actors downloading databases or manually extracting data from victims’ mailboxes, then staging it for exfiltration under inconspicuous file names intended to minimise detection of a MySQL mailbox export: 001.gif, All_scanner_vXX.pl.gz (where XX represents a one- or two-digit number), css.js, include.png, m2k.js, m2k_list.js and m2k_ui_adm.js.

Curlc4.txt, a PHP bot for the EWS API

The FBI has observed the actors building a bot using the PHP script Curlc4.txt to obtain victims’ messages. The script is designed to interface with Microsoft’s EWS API, which provides access to messages and other content such as calendars and contacts. The script appears to run standalone rather than being permanently installed on a compromised system; it uploads messages to a remote server, hides some of the directories and files it creates, and renames its child process crypto.

The script downloads the original file from https://upl.natcloudservice[.]com at IP address 149.28.132[.]137. The bot’s main C2 domain is natcloudservice[.]com, which communicates with https://natcloudservice[.]com/ews and upl.natcloudservice[.]com/ews. Before exfiltration, the bot compresses the messages; in some cases, the actors also encrypt the messages with a password, using RC4 (37) or AES (38)-128-CBC.

The PHP script accepts up to two command-line arguments. The first appears to designate the root directory for script execution; if it is not supplied, the script searches for a writable directory following the order in Table 1, and stores the second argument there in a variable saved on the targeted system.

Directory searchedSubdirectories skipped
//bin, /boot, /dev, /etc, /run, /proc, /sys, /var, /tmp, /usr
/homeNone
/var/wwwNone
/usrNone
/var/tmpNone

Fig. 2. Directories searched by Curlc4 looking for a writable location (Table 1 of the advisory).

Unique strings found in the script: $dir/storage/fm/.run ; $dir/.run ; public $password='jh4jnryw76ikmh' ; public $file='/var/tmp/.sess.zip' ; https://upl.natcloudservice[.]com/ews ; public $key='rhnr5m54pk65wertc' ; the RC4 setting ($this->enc="r";$this->cipher="rc4";$this->iv="") ; the AES-128-CBC setting ($this->enc="a";$this->cipher="aes-128-cbc";$this->iv="1111111111111111") ; https://natcloudservice[.]com/ews ; and the custom HTTP header curl_setopt($this->ch, CURLOPT_HTTPHEADER,array("X-Id: $clientid")). Other directories and files indicate that the script has run on a system: RUNNING_DIRECTORY/storage/fm, RUNNING_DIRECTORY/storage/fm.run (file), RUNNING_DIRECTORY/.run, RUNNING_DIRECTORY/clientid (file) and RUNNING_DIRECTORY/cp (file).

DC.exe and DCSync replication

The actors use DC.exe to carry out the DCSync replication technique, which copies sensitive Active Directory (AD (39)) information: account credentials, group membership details and trust relationships. DC.exe establishes an RPC connection to the victim’s domain controller, then uses the directory replication service to extract data from it. It notably retrieves a handle to the local security policy object, used to query the domain controller for the DNS domain name, the domain SID (40) and the domain’s replication epoch. The file also relies on nineteen object identifiers (LDAP OIDs) to retrieve Active Directory attributes and configurations, including 1.2.840.113556.1.2.48, 1.2.840.113556.1.4.1 and 1.2.840.113556.1.4.609; the full list of the nineteen OIDs appears in the original advisory.

Exfiltrated data and access restriction

The FBI recovered an archived mailbox database that the actors used to target victim organisations’ mailbox accounts. The actors collect account credentials and exfiltrate mailbox data from both on-premises systems and cloud services. Victims identified for mailbox data theft include government organisations, law enforcement services, healthcare systems and religious institutions in Southeast Asia. In some cases, the actors restricted access to the exfiltrated data to IP addresses located in Xiamen, China, only.

Office-cli, automating Microsoft 365 exfiltration

The actors use the office-cli command-line utility to target and maintain ongoing access to Microsoft Outlook 365 mailbox accounts, exfiltrating their content over various periods. They occasionally refresh these accounts and replace them with more recent ones. office-cli automates access to and exfiltration of mailbox content from configuration files such as client_id, tenant_id and secret.

The FBI has observed the actors running office-cli from the command line or from a Bash script. In both cases, they place the JSON (41) files needed to access the mailboxes in the configuration directory; office-cli then saves the collected data to a subdirectory of the dump directory. The actors evade detection using this tool because it relies on legitimate access methods. They also operate a custom web application that gives third parties access to the stolen mailbox content, in which a user can pass specific arguments in a URL (42) to view the content of a given account.

ATT&CK mapping

The advisory itself gives its own mapping to the ATT&CK (43) framework, stating that it uses version 19 of the framework. Each technique identifier has been verified here against the official STIX (44) data of ATT&CK Enterprise, version 19.2: all the identifiers cited are valid and match the label given by the authorities.

Tactic (as named by the advisory)TechniqueObserved use
ReconnaissanceT1595.002 Active Scanning: Vulnerability ScanningScanning tools used to identify network and application vulnerabilities
Initial AccessT1189 Drive-by CompromiseXSS attacks hijacking a third-party application to modify a page’s content
ExecutionT1059.001 Command and Scripting Interpreter: PowerShellDownloading the SoftEther installers
ExecutionT1059.004 Command and Scripting Interpreter: Unix Shelloffice-cli run from a Bash script
ExecutionT1059.006 Command and Scripting Interpreter: PythonCommand-line utilities built on Python exploit code
ExecutionT1059.007 Command and Scripting Interpreter: JavaScriptExecution of the XSS attacks
PersistenceT1133 External Remote ServicesSoftEther VPN clients installed for persistence
Defense EvasionT1036.003 Masquerading: Rename Legitimate UtilitiesExecutables renamed conhost.exe, dllhost.exe, DiagTrack.exe
Credential AccessT1003.006 OS Credential Dumping: DCSyncDC.exe against Active Directory
Credential AccessT1110.001 Brute Force: Password GuessingEBurst against Exchange accounts
Credential AccessT1110.003 Brute Force: Password SprayingEBurst against Exchange accounts
CollectionT1114.002 Email Collection: Remote EmailPHP script interfacing with the EWS API
CollectionT1560.003 Archive Collection Data: Archive via Custom MethodCompression and RC4 or AES-128-CBC encryption of messages before exfiltration
CollectionT1074.001 Data Staged: Local Data StagingPHP script searching for a writable directory
ExfiltrationT1020 Automated ExfiltrationAutomatic upload of messages to a remote server

Fig. 3. ATT&CK Enterprise v19.2 mapping, taken from the AA26-281A advisory and verified against the official STIX data.

A partly updated tactic label

The advisory labels its defense-evasion table “Defense Evasion”. However, in the ATT&CK Enterprise v19.2 STIX data, which the advisory itself says it uses, the tactic with identifier TA0005 has been renamed “Stealth”. The technique T1036.003 cited by the advisory is indeed attached there to the Stealth tactic, no longer to Defense Evasion. The discrepancy concerns only the label the authorities used in their own table, not the validity of the technique identifier itself.

Detection and hardening

If a compromise is detected

The authorities recommend identifying compromised hosts and isolating them, launching a threat hunt to scope the intrusion, collecting the relevant artefacts and logs to establish the timeline and the TTPs used, following national incident reporting obligations, and then applying eviction countermeasures. CISA provides a dedicated tool, the Eviction Strategies Tool, which combines the Playbook-NG web application with the COUN7ER post-compromise countermeasure database, to build a systematic eviction plan together with the expected outcome, preparatory steps and risks of each action.

Recommended mitigations

MitigationPurpose
Disable unused services and ports (automatic configuration, remote access, file sharing)Reduce the surface directly scanned by reconnaissance tools
Sanitise user input in web applicationsPrevent the injection of XSS payloads
Put in place identity, credential and access management (ICAM (45)), and require MFA (46) for services, in particular webmail, VPNs and accounts with access to critical systemsNeutralise password spraying and password guessing against Exchange
Replace default passwords, limit and audit accounts with administrative privilegesReduce the scope of an account compromise
Enable download and domain reputation filtering, and protective DNS resolutionBlock downloads of known malware and connections to already-flagged infrastructure
Monitor for misuse of LOTL tools and unexpected Active Directory replicationDetect the use of DC.exe and the DCSync technique
Segment the network and apply the principle of least privilegeLimit the reach of a compromised device into the rest of the network
Monitor cloud accounts for connected applications able to access sensitive dataSpot office-cli-style misuse of access to Microsoft 365 mailboxes
Apply patches and updates, including firmwareClose the eight CVEs listed in section 4, most of them old and already fixed by the vendor
Monitor for abnormal volumes of outbound traffic or uploadsSpot exfiltration of compressed mailbox data to domains such as natcloudservice[.]com
Maintain a backup plan with offline, password-protected copiesEnsure restoration is possible in case of a breach of data integrity
Regularly raise user awareness and train users, and carry out regular penetration testsReduce the likelihood of successful initial access

Fig. 4. Summary of the mitigations recommended by the authorities, aligned with CISA and NIST’s (48) CPGs (47).

The authorities also recommend continuously testing existing security controls against each of the ATT&CK techniques listed in section 9, using CISA Decider or an equivalent mapping tool, to objectively measure the actual performance of detections in place rather than assuming their coverage.

Indicators of compromise

The advisory publishes sixteen tables of indicators and mappings, with an explicit warning from the authorities: several indicators date back as far as 2016, and verification is recommended before any blocking action. The tables below reproduce in full the named indicators and the hash sets (webshells, binaries, dropped files), directly usable for detection. The two tables of raw domain names and IP addresses are very large (218 domain names and 516 IP addresses, with first-observed dates ranging from 2012 to 2024) and are not reproduced line by line here; they are available in full, in STIX format, directly from the original advisory (see Sources).

Domains and hosts directly attributed to the activity

Unlike the two raw tables, this table qualifies each entry by its role (infrastructure or SoftEther host) and overlaps with the domains already cited in section 7.

NameRoleFirst observedLast observed
96cee[.]comInfrastructure29 Jun 20209 May 2024
dns.studiocloud[.]xyzInfrastructure10 Dec 20219 May 2024
studiocloud[.]xyzInfrastructure10 Dec 20219 May 2024
asean.twimg.co[.]ukSoftEther host21 Sep 202415 Dec 2024
bj-hk.hmbcloud[.]netSoftEther host29 Mar 202129 Mar 2021
bj-jp.hmbcloud[.]netSoftEther host10 Apr 20217 May 2021
blog.98aiblog[.]comSoftEther host12 Jul 202414 Aug 2024
bsnl.twimg.co[.]ukSoftEther host17 Jun 20247 Jul 2024
eg.twimg.co[.]ukSoftEther host22 Sep 202414 Dec 2024
etechhosting.twimg.co[.]ukSoftEther host21 Sep 202416 Dec 2024
fcchk.twimg.co[.]ukSoftEther host21 Sep 202414 Dec 2024
gz-hk.hmbcloud[.]netSoftEther host28 Dec 202022 Jan 2021
iplc-hk.hmbcloud[.]comSoftEther host30 Nov 20208 Dec 2020
javacheck.ooguy[.]comSoftEther host22 Dec 202325 Jun 2024
javaupdate.giize[.]comSoftEther host22 Dec 202315 Jun 2024
ls.twimg.co[.]ukSoftEther host21 Sep 202414 Dec 2024
np.twimg.co[.]ukSoftEther host21 Sep 202425 Nov 2024
one.hmbiplc-01[.]comSoftEther host2 Apr 20222 Apr 2022
pw.sexytube0[.]comSoftEther host6 Aug 202118 Apr 2024
senate.twimg.co[.]ukSoftEther host21 Sep 202414 Dec 2024
sh-jp.hmbcloud[.]netSoftEther host10 Apr 202125 Apr 2021
szxcm-hkg01.iepl.node[.]cmSoftEther host7 Dec 20208 Jan 2021
tj.twimg.co[.]ukSoftEther host21 Sep 202414 Dec 2024
ximmd.sexytube0[.]comSoftEther host14 Jul 202031 Oct 2020

Fig. 5. The 24 domains and hosts directly attributed to the activity (Table 12 of the advisory).

Webshells

FileMD5 (49)SHA-256 (50)
b374.php48ca18a25424a0f52276290b619a7a8372c6af6a4be99e31c4a7a0aa4f01750792788e7f6f9749243a9f2c47c14a708f
back.pl38f5ff8169423e2c756848c02e8cac3b456586ababa08f70216c4459f4d6375676166ebfddd98a33b447ceb5099e8dc5
error.jspd61326c4e6d24aa9b67e2b7a3ef7cedf2f5c406eb64ad8902c8e30610d43fd3efc05a14cdb8fb158818953eaf3dc6a81
file_back.aspxf8de2e99dc7523d2c83d1a48e844c5ff5782ff2c835c88cc1ee521d2e8c523cfad73db3f9a29c93b40c4223f0338ade9
gf.phtml5b5a2c7fa705d8b1eb04da5db900b0d70e6fecb2d369b0eae63731616a3daada52036634885ab1b85b115af6bc5bcb86
yaml-payload.jar655cd134976d3e80c521708aa8be418b36f3b7645609ef40444dbc68f01d26c543d67689eda4937272ea5cfa4df1b522

Fig. 6. Six webshells from the actors’ CNE tooling repository (Table 13 of the advisory).

Tooling binaries and scripts

FileCategoryMD5SHA-256
ksubdomainEnumerationdae8f50ea44225fae3ba1f160b42bfdc670fa10a2ddde21fd594c4fef86b554d864089ed2de7153b472e921c623403ae
ksubdomain_linuxEnumerationfdece34bc084f1e252aeae274650eb8d645f6f2667af01a94d04a9d7a71916a13d9426835d636b4ceee2e25ccb34e525
oneforall.pyEnumeration596b990b0b389d906a8f4384837c18784d488f21269b18e37aaca93ac2a61707c9b611e506cdb3b287277746e94636b5
subDomainsBrute.pyEnumerationa73eca669fe80628dbbd2c7d9bb14c8fa14844e982f172d0f23910558c3f390a9d4c45dc32db825c2af7cf0ed8631db2
office-cliInformation extractionbe121e707f817aa9392c55af1e7ec2aaadd7dd142e4f7e2873bc8f7b7fb6308063608e0b49a773dea93abad4047f1489
JuicyPotato.exePrivilege escalation7ce68f0dd85355ba2897a68521167e56e7e727458f573dded05537baddac2867d2801db1c3c74410398d063dfd6f6575
BBScan.pyScanningf82694de2f19e1bff333c27bb7eb7a568e1b56ef51ba70aa4c4cfd4430820f20875b354588d5d723ba4d3940ea6c924b
dirmap.pyScanning1933c314041415939331fce18393954746e59172c40c95d83c3a6f24f801fc2265653c8b575b66a726463e2a4eebd7f2
dirsearch.pyScanning8829f6f1cc5fc0aab2f6e71bfd7dc53d752b14c6e6936991d51fcd5ebf40d303e657c2372893604f96044848ad9a5f24
fscan.exeScanningcf903e4a1629aa0582fd0363b57866767b9efc7ef8957411cdd22582ce4bfb3a5f76d9c91cdb7e36bf85c9785a2480e9
nbtscan.exeScanningf01a9a2d1e31332ed36c1a4d2839f412c9d5dc956841e000bfd8762e2f0b48b66c79b79500e894b4efa7fb9ba17e4e9e
nbtscan_linuxScanningef713447f18f5b7ee16af4ac37ec41332fbcb1995c458e5affd5fb8f1f979a08ddce21714a2e413aa3d5dc44f9f245fe
PackerFuzzer.pyScanning8dcc4f9ccc6b6adf7eeeb3f51c95afad33790218d5871af646feef5be29e0596d4703a45ce675c1eb2ca00140b3a1bde
ShuiZe.pyScanningb04375cca637f0702bf27feaff22a92dc7f86a4623db5c90273cea041d43207849c5c6b0060c370b2095f13871b1366d
sqlmap.pyScanningbcacc7ca999980d26c186ef791242fb52ecb51d7fa3bc3fa7ad7df64c6d0cd1f4ff2b37ed6839d3cff529fb08af49fb0
wpscanScanning1b8e29b6b7972fb124425aaa257f8f6defb0437e6a6a0f07169952f1a8b734299ec9a8b1faadbed811fe017f2cf54976

Fig. 7. Sixteen binaries and scripts from the CNE tooling repository (Table 14 of the advisory). Note that masscan and NMAP, cited in section 3, do not appear in this hash table: only their presence in the advisory’s text links them to the actors.

Files dropped on victims

FileCategoryMD5SHA-256
curlc4.txtMalware4f61b9ab907f351bb40b37b10f4974d08b869a5edaff74ff18bca3658a519a19771e66d00ff7849af7a142dd6fc8da85
DiagTrack.exeMalware6d57c42dee8bd7789969e2dd28671162804a53be802378a8ec4c94602fd3d6584e0d472d83148e8a42c731950fec415d
live700_v1.exeMalware776807750280daad05348f931a33e4efc4503db6ece93eddf4511e787607cb14606a1df9f526f1e39992497119437cec
conhost.exeSoftEthera973c0ab904c1b74655a906b99b76850b1552703ff0035f197c22cdb3a514bb6aa45ec98de3ef5409faab0978f18c35e
dllhost.exeSoftEtherf62cbbbdf35c7790909c26c7c5fbce058a592e22c51311d482272ec5aba0103c9cd0cfd78e5b5ba75dfa8f1c56926672
dllhost.exeSoftEthera05cdf6afcbb107961307f59cbab5e4f86f1cfa6a2e0a8cb6fc1fbee28472308e6467932f8658a6a4885e29ed8c34a67
b.exeInformation extraction7d5a182f70bed0e4fa2f8615aba070dee93244080a749b521f63476343ce3c81cc8c1b672fa0d9e67359aee37544c784
dc.exeInformation extraction1bcaef76b2063f1b80b0fa0d277ec9c59dc85f9569a15eaf51c7d34254767ea30dd67b2178cec4cc7125288b9544fe00
secretsdump.exeInformation extraction4d33bfb75e27fefaa72526899604d557644decbc6ce8c52382f4755fa6fc2cb4d89a0e7ec0e574c11b398a6f2eed04b1
secretsdump.pyInformation extractionfc6e8ca41cf4f6100177352660e520b467db57a1f957031b78f29aa91e2e87780eae3835290259eff846d8f14afb794b

Fig. 8. Ten files potentially dropped on victims (Table 15 of the advisory). Two distinct copies of dllhost.exe appear with different hashes.

On the two tables not reproduced

The 218 domain names (Table 10) and 516 IP addresses (Table 11) in the advisory span an observation window of more than ten years, with first-seen dates running back in some cases to 2012 or 2016. Many of these domains carry an old last-observed date (2020, 2021) and so no longer reflect active infrastructure. The STIX JSON and XML packages published by CISA (see Sources) carry the full, machine-readable contents of these two tables, suited for direct ingestion by a SIEM or an EDR.

Source qualification

The advisory is a joint primary source, co-signed by ten government bodies. The elements that can be verified independently have been cross-checked.

ItemStatusComment
OFAC sanction against Integrity Tech and its infrastructure link to Flax TyphooncorroboratedUS Treasury press release of 3 January 2025 and consistent reporting from several specialised outlets.
TTPs and tools specific to Integrity Tech (MicroScan, EBurst, Curlc4, DC.exe, office-cli)single sourceTechnical material drawn from FBI investigations, with no independent third-party publication found as of 9 October 2026.
CVSS scores, CWEs and affected versions of the eight CVEscorroboratedCompared against each CVE’s NVD record, accessed 9 October 2026.
Status and KEV catalogue addition date of the five CVEs marked with an asteriskcorroboratedVerified against the JSON feed of CISA’s KEV catalogue: addition dated 8 October 2026 for all five, confirming the advisory’s asterisk.
Identifiers and names of the fifteen ATT&CK techniques citedcorroboratedVerified against the official STIX data of ATT&CK Enterprise v19.2.
The “Defense Evasion” label in table 6 of the advisorydiscardedTactic renamed “Stealth” in the v19.2 STIX data that the advisory itself says it uses; see section 9.
Full list of the 218 domain names and 516 IP addressessingle sourceReproduced as published by the signing authorities, not independently cross-checked given the volume.

Assessment

Exposure of internet-facing services
Systematic scanning of FTP, SSH, DNS, HTTP, HTTPS and SOCKS ports; eight old CVEs, most of them fixed by the vendor long ago, remain effective vectors in the absence of patching.
High
Compromise of mailbox accounts
EBurst covers ten Exchange and Office 365 authentication interfaces; exfiltration through Curlc4 and office-cli relies on legitimate access methods, which offer little to go on for detection.
High
Stealth of the persistence mechanism
SoftEther is a legitimate VPN, renamed as common Windows executables; detection tools flag it less readily than a dedicated tool.
High
Freshness and direct usability of the published network indicators
A substantial share of the 218 domains and 516 IP addresses shows a last-observed date before 2022, in some cases 2016; the authorities themselves recommend verifying them before any blocking action.
Low
Confidence in the precise attribution to Integrity Tech
The link to Flax Typhoon, Ethereal Panda and Red Juliett is established by the authorities themselves, who nonetheless note that the actors supported by Integrity Tech may act without any connection to the company.
Moderate
Method note

This analysis is built on the full text of the AA26-281A advisory as published on 8 October 2026, without access to the full STIX files or to the samples themselves. The eight CVEs were compared against their respective NVD records, KEV status against the catalogue’s official JSON feed, and the fifteen ATT&CK identifiers against the Enterprise v19.2 STIX data. The two largest indicator tables (domains, IP addresses) were counted but not cross-checked line by line. The levels in the grid reflect judgement.

Glossary

  1. CISA (1): Cybersecurity and Infrastructure Security Agency, the United States cybersecurity and infrastructure security agency.
  2. FBI (2): Federal Bureau of Investigation, the United States federal police agency.
  3. NSA (3): National Security Agency, the United States signals intelligence agency.
  4. NCSC-UK (4): National Cyber Security Centre, the United Kingdom’s national cybersecurity centre.
  5. ASD (5): Australian Signals Directorate, Australia’s signals intelligence agency.
  6. ACSC (6): Australian Cyber Security Centre, the ASD’s cybersecurity centre.
  7. NPA (7): National Police Agency, Japan’s national police agency.
  8. NCO (8): National Cybersecurity Office, Japan’s national cybersecurity office.
  9. NCSC-NZ (9): National Cyber Security Centre, New Zealand’s national cybersecurity centre.
  10. CNI (10): Centro Nacional de Inteligencia, Spain’s national intelligence centre.
  11. TTP (11): Tactics, Techniques, and Procedures, the tactics, techniques and procedures used by an actor.
  12. XSS (12): Cross-Site Scripting, the injection of script executed client-side in a vulnerable web page.
  13. VPN (13): Virtual Private Network.
  14. CVE (14): Common Vulnerabilities and Exposures, the public identifier assigned to a vulnerability.
  15. KEV (15): Known Exploited Vulnerabilities, CISA’s catalogue of vulnerabilities whose exploitation has been observed.
  16. OFAC (16): Office of Foreign Assets Control, the US Treasury office responsible for economic sanctions.
  17. CNE (17): Computer Network Exploitation, the exploitation of a computer network for intelligence or intrusion purposes.
  18. FTP (18): File Transfer Protocol.
  19. SSH (19): Secure Shell, an encrypted remote access protocol.
  20. DNS (20): Domain Name System.
  21. HTTP (21): Hypertext Transfer Protocol, the web’s transfer protocol.
  22. HTTPS (22): HTTP Secure, HTTP encrypted using TLS.
  23. SOCKS (23): a protocol that relays network connections through a proxy server.
  24. PHP (24): a server-side scripting language widely used in web development.
  25. CWE (25): Common Weakness Enumeration, a classification of software weaknesses.
  26. CVSS (26): Common Vulnerability Scoring System, the system used to rate the severity of vulnerabilities.
  27. ECP (27): Exchange Control Panel, Microsoft Exchange’s control panel.
  28. EWS (28): Exchange Web Services.
  29. OAB (29): Offline Address Book, Exchange’s offline address book.
  30. OWA (30): Outlook Web Access, Outlook’s web interface.
  31. RPC (31): Remote Procedure Call.
  32. API (32): Application Programming Interface.
  33. MAPI (33): Messaging Application Programming Interface, Microsoft’s messaging programming interface.
  34. C2 (34): Command and Control, an actor’s command-and-control infrastructure.
  35. LOTL (35): Living Off the Land, the use of tools and binaries already present and legitimate on a system to carry out malicious actions.
  36. IP (36): Internet Protocol, the Internet’s addressing protocol.
  37. RC4 (37): Rivest Cipher 4, a stream cipher algorithm.
  38. AES (38): Advanced Encryption Standard, a block cipher algorithm.
  39. AD (39): Active Directory, Microsoft’s directory service.
  40. SID (40): Security Identifier, the unique security identifier of a Windows account or domain.
  41. JSON (41): JavaScript Object Notation, a text format for structured data.
  42. URL (42): Uniform Resource Locator, the address of a resource on the web.
  43. ATT&CK (43): Adversarial Tactics, Techniques, and Common Knowledge, the framework of attack tactics and techniques maintained by MITRE.
  44. STIX (44): Structured Threat Information Expression, a format for exchanging threat data, used to publish ATT&CK and this advisory’s indicators.
  45. ICAM (45): Identity, Credential, and Access Management.
  46. MFA (46): Multifactor Authentication.
  47. CPG (47): Cross-Sector Cybersecurity Performance Goal, a cross-sector cybersecurity performance goal defined by CISA and NIST.
  48. NIST (48): National Institute of Standards and Technology, the United States technical standards institute.
  49. MD5 (49): Message Digest 5, a hash function used here as a supplementary hash.
  50. SHA-256 (50): Secure Hash Algorithm 256-bit, the hash function used for file hashes.

Sources

  1. CISA, FBI, NSA, NCSC-UK, ASD’s ACSC, Canadian Centre for Cyber Security, NPA, NCO, NCSC-NZ, CNI, Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data, advisory AA26-281A, 8 October 2026. cisa.gov/aa26-281a
  2. CISA, indicator-of-compromise packages for advisory AA26-281A, STIX JSON (1,021.16 KB) and STIX XML (658.87 KB) formats, 8 October 2026. Links available from the advisory page above.
  3. U.S. Department of the Treasury, Office of Foreign Assets Control, Treasury Sanctions Technology Company for Support to Malicious Cyber Group, 3 January 2025. home.treasury.gov
  4. CISA, Known Exploited Vulnerabilities catalogue, JSON feed, accessed 9 October 2026. cisa.gov/known_exploited_vulnerabilities.json
  5. NIST, National Vulnerability Database, records for CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199 and CVE-2023-22894, accessed 9 October 2026. nvd.nist.gov
  6. MITRE, ATT&CK Enterprise v19.2, STIX data, accessed 9 October 2026. github.com/mitre-attack/attack-stix-data
  7. CISA, People’s Republic of China Threat Overview and Advisories, accessed 9 October 2026. cisa.gov/china

Marked TLP:CLEAR, PAP:CLEAR. Unlimited disclosure, no restriction on use.

The analysis presented here reflects the author’s own views and rests on the public sources listed above.