
Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
A multinational cybersecurity advisory issued on October 8, 2026, warns that Chinese government-linked threat actors, enabled by the China-based Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide. Activity spans US critical infrastructure sectors, government networks, and victims across Southeast Asia, Africa, and North America. Exploitation methods include scanning tools, cross-site scripting attacks, password spraying on Microsoft Exchange servers, and persistence via VPN software. The advisory provides indicators of compromise and mitigation guidance for network defenders.