CISA Advisory: Chinese Government-Linked Actors Use Automated and Hands-On Hacking to Steal Sensitive Data From US Critical Infrastructure
CISA, the FBI, NSA and partner agencies from the UK, Australia, Canada, Japan, New Zealand and Spain jointly published advisory AA26-281A on October 8, reporting that China-based
Defenders in the four named sectors face commodity tooling, so signature-based detection is unreliable: open-source scanners, EBurst spraying and SoftEther VPN clients renamed conhost.exe or dllhost.exe draw less endpoint scrutiny than custom malware. Exchange and Office365 mailboxes are the main collection target, as the Curlc4.txt EWS bot and the XSS payload's mailbox-query functions show. Because the exploit repository dates to at least 2017, organizations with exposed Exchange interfaces or unpatched 2014–2023 CVEs should hunt for the published indicators now. The October 8 DOJ seizure fixed legal attribution, while this advisory exposes operational depth. CISA is the sole primary source, though co-sealed by eight agencies, with no independent corroboration yet. Much of this toolset is shared across China-linked and criminal actors, so the Integrity Technology Group link may explain only part of the intrusions.