FBI Details China-Linked Operations for Email Theft and Third-Party Access

The FBI and partner agencies from six other countries have issued a joint advisory on hackers linked to Integrity Technology Group, a China-based cybersecurity company sanctioned by the United States and the United Kingdom. The agencies say the actors stole email from organizations including government bodies, law enforcement agencies, healthcare systems and religious institutions, and operated a web application that gave unidentified third parties access to stolen email content.
The activity has been ongoing since at least mid-January 2021, the advisory says. It describes targets in Southeast Asia as well as U.S. government services, critical manufacturing, healthcare, IT, law enforcement, education and religious groups. Organizations in Africa and North America were also targeted. The advisory does not state how many organizations were breached or date the individual thefts.
Intrusion routes and targeted services
Investigators describe a combination of broad scanning, exploitation and identity attacks. The actors used open-source tools including Nmap, masscan and WPScan, focusing on ports 21, 22, 53, 80, 443 and 1080. They also used MicroScan, a Python web application containing more than 1,300 penetration-testing scripts, to search for specific web vulnerabilities.
The advisory identifies eight vulnerabilities successfully exploited in products including GNU Bash, ProFTPD, ISC BIND, Apache Struts, Pulse Connect Secure, GitLab, ONLYOFFICE Document Server and Strapi. Five were described as newly added to CISA's Known Exploited Vulnerabilities catalog, although the catalog data checked on October 8 did not yet show them. The affected versions and remediation guidance should therefore be checked against vendors' own advisories.
Password spraying was another route into victim environments. The actors used EBurst, an open-source Python tool aimed at Microsoft 365 and Exchange accounts. Its login attempts can use Exchange interfaces including ECP, EWS, OAB, OWA, RPC, API, MAPI, PowerShell, Autodiscover and Microsoft-Server-ActiveSync. The FBI also recovered an XSS payload that presented visitors with false username and password fields before offering a password-protected ZIP file containing a program named live700_v1.exe.
Persistence, credential theft and mailbox collection
To retain access, the actors installed the legitimate SoftEther VPN software, sometimes renaming its installer conhost.exe or dllhost.exe to resemble Windows files. The client was configured to reconnect when a machine started. For credential collection, they used a tool named DC.exe to perform DCSync, copying account credentials, group membership information and trust relationships through Active Directory replication.
For email collection, a PHP script called Curlc4.txt created a bot that retrieved messages through Exchange Web Services, which can also access calendars and contacts. The bot compressed the mail, sometimes encrypted it, and uploaded it to a remote server. A separate tool, office-cli, repeatedly accessed Microsoft 365 accounts to obtain mail from different time periods using configuration files containing a client ID, tenant ID and secret.
The agencies say the actors also downloaded databases and manually extracted data from victim email. In some cases, access to stolen information was limited to IP addresses in Xiamen, China. Users of the reported web application could view a specified account's mail by adding arguments to a URL, although the advisory does not name the third parties using the service.
Defensive priorities
The joint guidance calls for organizations to disable unused services and ports, sanitize web input to mitigate XSS, and require multifactor authentication for webmail, VPNs and accounts that reach critical systems. Teams should review web application logs, investigate unexpected Active Directory replication, and inspect cloud accounts for connected applications able to read email or files.
Businesses should also patch the listed vulnerabilities, replace products no longer supported, and review the advisory's indicators before blocking them because some records date back to 2016. If compromise is suspected, the agencies advise isolating affected hosts, establishing the scope through hunting, then removing the actors and hardening the environment. The practical implication is clear: exposed web services, identity controls and delegated cloud access need to be assessed together rather than as separate security tasks.

