Skip to content
Threat Feed
high advisory

Integrity Technology Group Enabling Global Cyber Espionage

The NCSC and international partners have exposed Integrity Technology Group for facilitating global cyber espionage campaigns through AI-powered scanning, large-scale botnets, and manual network exploitation.

The UK's National Cyber Security Centre (NCSC), in coordination with international partners from six countries, has publicly exposed Integrity Technology Group (Integrity Tech), a China-based company with ties to the Chinese government. Integrity Tech is identified as a key facilitator within the broader Chinese cyber ecosystem, providing technical infrastructure and tools that enable malicious cyber actors to conduct global espionage. The company employs personnel tasked with developing exploit tools, acquiring and hosting command-and-control infrastructure, and conducting manual network compromises.

Their operations are closely linked to high-profile threat campaigns previously tracked as Flax Typhoon, Ethereal Panda, and Red Juliett. The advisory highlights the entity's use of AI-enabled automated scanning tools and large-scale botnets to identify and infiltrate sensitive networks globally across critical infrastructure sectors. This disclosure emphasizes the role of private-sector intermediaries in scaling state-sponsored cyber operations, and organizations are advised to prioritize resilience against botnet-driven reconnaissance and credential-based exploitation.

Impact

Integrity Tech's activities enable persistent access to sensitive data for organizations across a broad range of global sectors, including critical infrastructure. The use of large-scale botnets and AI-driven automation significantly increases the threat surface for potential targets, allowing for rapid identification and exploitation of vulnerabilities. Previous activities attributed to groups utilizing this infrastructure have resulted in long-term network compromises and the exfiltration of confidential intelligence.

Recommendation

  • Consult the joint advisory published by the FBI and international partners at https://www.ic3.gov/CSA/2026/261008.pdf for specific mitigation guidance related to botnet infrastructure.
  • Enhance monitoring of egress traffic to identify potential communication with known botnet command-and-control infrastructure often utilized by groups such as Flax Typhoon.
  • Conduct thorough reviews of internet-facing assets for unauthorized scanning and exploitation patterns, specifically targeting web vulnerabilities and weak authentication.
  • Implement robust perimeter defense and segmentation to limit the reach of compromised accounts or botnet-controlled entry points.

Immediate actions

Review and implement mitigation guidance from the joint FBI advisory (IC3-2026-1008).

SOC 48h

Threat Hunt

Monitor for anomalous outbound traffic patterns consistent with botnet signaling.

T1071 high medium confidence hunt now

Data: Netflow, Proxy logs