Disruption of Integrity Technology Group Hacking Tools
The US government disrupted infrastructure supporting Integrity Technology Group tools MicroScan and FishHub, which Chinese state-sponsored actors, including Flax Typhoon, used to compromise critical infrastructure.
The United States government has announced the seizure of domains associated with Integrity Technology Group (Integrity Tech), an entity previously sanctioned for providing cyber tools to Chinese state-sponsored threat actors. The disruption targeted two primary tools: MicroScan, a Python-based vulnerability scanner containing over 1,300 penetration testing scripts, and FishHub, a platform enabling remote access and data exfiltration. These tools have been active since 2017, targeting a broad range of technologies including Apache Struts, Juniper ScreenOS, Jenkins, Oracle WebLogic, and WordPress. Flax Typhoon and other associated APTs leveraged these tools alongside IoT botnets to conduct large-scale reconnaissance and persistent intrusion operations against critical infrastructure in the US, Japan, Taiwan, and Europe. Defenders should note that these actors continue to utilize custom scripts for email exfiltration and Active Directory data theft.
Attack Chain
- Initial reconnaissance performed using MicroScan via an IoT botnet to identify vulnerable services (e.g., Apache Struts, WebLogic, WordPress).
- Initial access achieved through spear-phishing campaigns or exploitation of discovered vulnerabilities in internet-facing services.
- Deployment of SoftEther VPN tools on compromised assets to establish persistent, remote access to internal networks.
- Credential harvesting conducted using tools like EBurst against Microsoft Exchange servers.
- Internal reconnaissance and lateral movement facilitated by tools such as Fscan and Nmap.
- Data collection and sensitive information extraction from Active Directory using the utility DC.ex.
- Final exfiltration of email databases and proprietary files using custom utilities like office-cli and PHP script Curlc4.txt.
Impact
The campaign targeted critical infrastructure entities including power companies, government organizations, law enforcement agencies, healthcare systems, and universities across Southeast Asia, Japan, and Poland. Documented impacts include mass email data exfiltration, theft of sensitive Active Directory data, and unauthorized persistence within the networks of critical NGOs and government institutions. The use of IP-restricted access mechanisms for exfiltrated data highlights the long-term impact on victim privacy and operational security.
Recommendation
Prioritize hunting for the specific tools and infrastructure associated with Integrity Tech in your environment.
- Block the seized C2 domains listed in the IOC table at the network perimeter.
- Review network logs for outbound connections to these identified domains.
- Hunt for the presence of the specific exfiltration utilities mentioned (office-cli, Curlc4.txt) and the DC.ex utility on high-value targets.
- Audit internet-facing services (Apache Struts, Jenkins, Oracle WebLogic, WordPress) for signs of unauthorized scanning or reconnaissance patterns described in the advisory.
- Monitor for the deployment of SoftEther VPN software, as it is a favored tool for persistence in this campaign.
Immediate actions
Block listed C2 domains on DNS and web proxy.
Mitigations
Patch internet-facing services including Apache Struts, WebLogic, and WordPress.
Known vulnerability scanning targets of MicroScan tool.
Indicators of compromise
6
domain
| Type | Value |
|---|---|
| domain | c0cc.cc |
| domain | 98aicai.com |
| domain | 98aicode.com |
| domain | outlook3650.com |
| domain | youtubecard.com |
| domain | linkedinns.net |