<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:ivanti:connect_secure:9.0:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aivanticonnect_secure9.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 19:12:19 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aivanticonnect_secure9.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>China-Linked Espionage Campaign Targeting Global Infrastructure via Integrity Technology Group</title><link>https://feed.craftedsignal.io/briefs/2026-10-integrity-technology-espionage/</link><pubDate>Thu, 08 Oct 2026 19:12:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-integrity-technology-espionage/</guid><description>Integrity Technology Group, a Chinese for-profit entity, is conducting multi-year cyber espionage targeting government, healthcare, and religious institutions using automated vulnerability scanning, credential harvesting, and specialized data exfiltration tools.</description><content:encoded><![CDATA[<p>Integrity Technology Group, a China-based for-profit company linked to state security agencies, has conducted widespread espionage against government, law enforcement, healthcare, and religious institutions across Southeast Asia, Africa, and North America since at least 2021. The group leverages a diverse set of penetration testing scripts and automated scanning tools to identify and exploit vulnerabilities in legacy services and web applications. Beyond exploitation, they utilize password spraying against Microsoft 365 and Exchange environments, coupled with XSS-based phishing to harvest credentials.</p>
<p>The group maintains persistence through disguised legitimate software and exfiltrates sensitive email content via custom bots and tools that interface directly with Exchange Web Services. Notably, the group facilitates third-party access to stolen data via a specialized web portal, indicating a high-level operational model that prioritizes data monetization or dissemination. US and UK authorities have sanctioned the group for its role in targeting critical infrastructure. Defenders should prioritize auditing Active Directory replication, monitoring Exchange interface access, and patching the documented vulnerabilities exploited by the group.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial Reconnaissance: Attackers scan for exposed services (ports 21, 22, 53, 80, 443, 1080) using tools like Nmap, masscan, and MicroScan (containing 1,300+ penetration scripts).</li>
<li>Initial Access: Attackers exploit known vulnerabilities (CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894) or perform password spraying against Microsoft 365/Exchange interfaces.</li>
<li>Credential Harvesting: Actors deploy XSS payloads on legitimate web pages to redirect users to fake login portals to steal usernames and passwords, or use EBurst to brute-force authentication.</li>
<li>Persistence: Attackers install SoftEther VPN, renaming the binary to 'conhost.exe' or 'dllhost.exe' to mimic Windows system processes and establishing persistence upon system reboot.</li>
<li>Credential Access: Attackers execute 'DC.exe' to leverage the DCSync technique, extracting account credentials and trust relationships from domain controllers.</li>
<li>Collection: Attackers deploy the PHP script 'Curlc4.txt' or the 'office-cli' utility to interface with Exchange Web Services (EWS) and copy sensitive mailboxes.</li>
<li>Exfiltration: Stolen email content is compressed and uploaded to attacker-controlled C2 infrastructure, such as 'natcloudservice.com'.</li>
<li>Impact: Stolen information is ingested into a web-based portal to provide third-party access to the intelligence, affecting diverse sectors including law enforcement and healthcare.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>This campaign has resulted in the theft of high-value communications from government agencies, law enforcement, healthcare systems, and religious organizations globally. By enabling third-party access to stolen emails through a web portal, the threat actor significantly increases the potential for downstream exploitation and geopolitical intelligence leverage. The duration of the campaign, active since 2021, suggests large-scale, long-term exposure of sensitive data across multiple continents.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Block known malicious C2 domains including 'dns.studiocloud.xyz' and 'natcloudservice.com' at the DNS resolver level.</li>
<li>Patch the 8 identified vulnerabilities (CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894) across all perimeter and internal services.</li>
<li>Enforce MFA across all Microsoft 365, VPN, and critical email infrastructure.</li>
<li>Audit Active Directory for anomalous replication events associated with the DCSync technique (e.g., unexpected 'GetNCChanges' calls).</li>
<li>Review web server logs for suspicious MicroScan patterns or XSS injection attempts.</li>
<li>Monitor process creation for 'conhost.exe' or 'dllhost.exe' originating from non-system paths, specifically those associated with VPN binary signatures.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>espionage</category><category>china</category><category>cyber-espionage</category><category>microsoft-365</category><category>dcsync</category></item></channel></rss>