IC Technology & Cyber — 2026-10-11

CISA Advisory: Chinese Government-Linked Actors Use Automated and Hands-On Hacking to Steal Sensitive Data From US Critical Infrastructure

BLUFChina-linked actors exploiting commodity tools and renamed legitimate software to harvest Exchange mailboxes across U.S. critical infrastructure will evade signature-based defenses, demanding behavior-based hunting against published indicators.

CISA, the FBI, NSA and partner agencies from the UK, Australia, Canada, Japan, New Zealand and Spain jointly published advisory AA26-281A on October 8, reporting that China-based Integrity Technology Group enables threat actors who target US critical infrastructure 1. The advisory, drawing on multiple FBI investigations, names Government Services, Critical Manufacturing, Healthcare and Public Health, and Information Technology as affected sectors 1. It describes open-source scanning tools, the MicroScan exploit application, XSS credential-harvesting payloads, EBurst password spraying against Microsoft Exchange, and SoftEther VPN clients for persistence 1. The FBI also observed a PHP script, Curlc4.txt, pulling emails through the Exchange EWS API 1.

Analysis
Defenders in the four named sectors face commodity tooling, so signature-based detection is unreliable: open-source scanners, EBurst spraying and SoftEther VPN clients renamed conhost.exe or dllhost.exe draw less endpoint scrutiny than custom malware. Exchange and Office365 mailboxes are the main collection target, as the Curlc4.txt EWS bot and the XSS payload's mailbox-query functions show. Because the exploit repository dates to at least 2017, organizations with exposed Exchange interfaces or unpatched 2014–2023 CVEs should hunt for the published indicators now. The October 8 DOJ seizure fixed legal attribution, while this advisory exposes operational depth. CISA is the sole primary source, though co-sealed by eight agencies, with no independent corroboration yet. Much of this toolset is shared across China-linked and criminal actors, so the Integrity Technology Group link may explain only part of the intrusions.
1 sources
  1. Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data - CISA

View in full brief →

UNCLASSIFIED // OPEN SOURCE