Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
Joint advisory details tactics, techniques, and procedures used by threat actors enabled by Integrity Technology Group

Key Takeaways
- Chinese government-linked threat actors, enabled by Integrity Technology Group, are combining automated tools and hands-on techniques to steal sensitive data globally.
- Activity targets US critical infrastructure sectors and extends to victims in Southeast Asia, Africa, and North America.
- Exploitation methods include scanning tools, cross-site scripting, password spraying on Microsoft Exchange, and VPN-based persistence.
Related Security News

FBI Disrupts Flax Typhoon Hacking Tools MicroScan and FishHub
The FBI, in coordination with international partners, seized seven domains operated by the Chinese state-sponsored threat actor Flax Typhoon. The domains were used to control two hacking tools, MicroScan and FishHub, which were deployed in attacks breaching critical infrastructure and other organizations worldwide. The operation disrupted the threat actor's command-and-control capabilities.



