On October 8, the FBI, alongside agencies from six other countries, issued a warning regarding a group of hackers linked to a Chinese cybersecurity firm, Integrity Technology Group. This group has reportedly exploited vulnerabilities to access and steal emails from various sectors, including government organizations, law enforcement, healthcare systems, and religious institutions across Southeast Asia. The advisory highlights that these hackers have been active since at least January 2021, although specific details about the number of organizations affected remain undisclosed.
Integrity Technology Group has faced sanctions from both the U.S. and the UK due to its alleged involvement in cyber intrusions targeting U.S. entities. The hackers employed a range of tools, including a custom-built application that purportedly provides third-party access to the stolen email content, although the identities of these third parties have not been revealed.
Methods of Intrusion
The advisory outlines the techniques used by the hackers to infiltrate networks. They utilize open-source scanning tools such as Nmap and WPScan to identify vulnerabilities in web applications and networks. Their scanning efforts focus on common ports, including 21, 22, 53, 80, 443, and 1080. Additionally, they have been known to use a Python-based scanner called MicroScan, which contains over 1,300 scripts designed for penetration testing.
Among the vulnerabilities exploited by the hackers are several known flaws, including CVE-2014-6278 and CVE-2016-3081, which have been cataloged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as part of their Known Exploited Vulnerabilities (KEV) list. The advisory emphasizes that the hackers have also employed password spraying techniques, utilizing tools like EBurst to target Microsoft 365 and Exchange accounts.
Data Exfiltration Techniques
Once inside a network, the hackers deploy various methods to maintain access and exfiltrate data. They reportedly install SoftEther, a legitimate VPN software, disguised as a Windows file to evade detection. To harvest credentials, they utilize a tool named DC.exe, which employs the DCSync technique to extract data from domain controllers.
For email collection, the hackers have developed a bot that interfaces with Exchange Web Services (EWS) to gather emails, calendars, and contacts. This bot compresses and encrypts the collected data before uploading it to a remote server. Additionally, they have been observed manually downloading databases and email data from compromised accounts.
Defensive Recommendations
In light of these findings, the advisory provides several recommendations for organizations to bolster their defenses against such intrusions. Key measures include:
- Disabling unused services and ports to minimize attack surfaces.
- Implementing multifactor authentication (MFA) for critical accounts and services.
- Regularly reviewing web application logs for signs of attack attempts.
- Applying patches for known vulnerabilities, particularly those listed in the advisory.
- Monitoring for unexpected Active Directory replication, which may indicate DCSync activity.
Organizations are urged to remain vigilant and proactive in their cybersecurity measures, especially given the sophisticated methods employed by these threat actors. The advisory also includes a comprehensive list of indicators of compromise (IOCs) associated with the hackers, which can aid in identifying potential breaches.
For further details on the advisory and the specific vulnerabilities exploited, refer to the report from The Hacker News.


