FBI: Chinese hackers empty mailboxes with free tools and old flaws
Since 2021, intrusions attributed to the Chinese company Integrity Technology Group have targeted the email systems of government agencies and hospitals. In a joint advisory, ten agencies from seven countries — including the FBI and Spanish intelligence services — warn organizations about their techniques. The toolkit: free software, old vulnerabilities and large-scale email theft.
Integrity Technology Group: a Chinese company in the crosshairs
The agencies that signed the advisory describe Integrity Technology Group as a commercial company linked to the Chinese government. Its employees are said to develop intrusion tools for sale, while also carrying out attacks against networks around the world.
According to the U.S. Department of Justice, this Beijing-based firm ran a botnet of more than 200,000 routers and cameras, dismantled by the FBI in September 2024. Washington sanctioned the company in January 2025, while London froze its assets in December.
In 2024, Christopher Wray, then director of the FBI, said the company’s chairman had publicly acknowledged years of intelligence collection on behalf of Chinese security agencies. Integrity Technology Group denied the accusations in January 2025, in a statement sent to the Shanghai Stock Exchange and reported by the Associated Press.
Since 2021, government agencies and hospitals targeted
The FBI obtained an archive of emails stolen from government bodies, police services, healthcare organizations and religious groups in Southeast Asia. The intruders sometimes limited access to that data to IP addresses in Xiamen, in southeastern China.
To extract mailboxes, they run the PHP script Curlc4.txt. Messages are collected through Exchange Web Services, then compressed, sometimes encrypted, before being sent to a remote server. In parallel, the office-cli tool lets them reach Microsoft 365 accounts using legitimate application credentials. According to the agencies, these connections look like ordinary traffic to security teams.
Loot available to third parties
The stolen data then circulates outside the group. The attackers maintain a web application open to third parties: adding certain parameters to a URL is enough to read the emails of a given account. The agencies do not name those users.
Free tools and eight old flaws
To identify their targets, the attackers use open-source scanners available on GitHub, including Nmap and masscan. The agencies see this as a preference for the least protected targets. They also rely on MicroScan, part of their arsenal since at least 2017. This Python application brings together more than 1,300 intrusion-testing scripts, able to probe WordPress or Apache Struts.
The agencies list eight vulnerabilities exploited successfully. The oldest affects GNU Bash and dates from 2014. The most recent affects the Strapi CMS and dates from 2023. Five of these flaws have just been added to the CISA catalog of vulnerabilities exploited in real attacks. With the open-source tool EBurst, they also try a few common passwords against a large number of Exchange and Microsoft 365 accounts.
SoftEther VPN: effective camouflage
After breaking into the network, they deploy SoftEther VPN and often rename it conhost.exe or dllhost.exe so that it looks like a Windows component. Detection is difficult for security teams, because SoftEther is legitimate software.
The agencies recommend requiring multifactor authentication on webmail and VPNs, and patching the eight vulnerabilities listed.
39 pages of indicators of compromise
They also publish 39 pages of indicators of compromise, including IP addresses and domain names sometimes ten years old, which should be checked before any blocking. By cross-referencing the list, The Hacker News identified ten IP addresses linked in 2024 to the command servers of the dismantled botnet. The dates of last activity differ from one advisory to another.
What to remember
- Hackers linked to Integrity Technology Group have targeted government agencies and hospitals since 2021.
- Ten agencies from seven countries, including the FBI, are warning about their methods.
- They use open-source scanners, Python scripts and old flaws.
- Stolen emails are exfiltrated through Exchange Web Services and Microsoft 365.
- A web application lets third parties read the stolen messages.
- SoftEther VPN is used to hide inside compromised networks.
- The agencies recommend MFA and patching the eight listed flaws.
FAQ
Who is Integrity Technology Group?
Integrity Technology Group is a Chinese company based in Beijing. The signing agencies describe it as a commercial business linked to the Chinese government, involved in developing intrusion tools and in cyberattacks.
Who are the hackers targeting?
The intrusions mainly target government agencies, law enforcement, healthcare systems and religious institutions, especially in Southeast Asia.
Which flaws are being exploited?
Eight vulnerabilities are cited, including a 2014 GNU Bash flaw and a 2023 Strapi CMS flaw. Five of them have just been added to the CISA catalog.
How can organizations protect themselves?
The agencies recommend enabling multifactor authentication on webmail and VPNs, applying patches for the listed flaws and checking the indicators of compromise they provide.
Conclusion
The joint advisory from the FBI and its partners shows that free tools and old flaws are still enough to compromise sensitive mailboxes. Open-source scanners, intrusion scripts and a legitimate VPN turned to camouflage let the attackers stay quiet. Against this threat, system updates and multifactor authentication remain essential cybersecurity defenses.