{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/document-server/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Integrity Technology Group"],"_cs_cpes":["cpe:2.3:a:proftpd:proftpd:1.3.5:*:*:*:*:*:*:*","cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*","cpe:2.3:a:ivanti:connect_secure:8.2:*:*:*:*:*:*:*","cpe:2.3:a:ivanti:connect_secure:8.3:*:*:*:*:*:*:*","cpe:2.3:a:ivanti:connect_secure:9.0:*:*:*:*:*:*:*","cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","cpe:2.3:a:onlyoffice:document_server:*:*:*:*:*:*:*:*","cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2015-3306"},{"id":"CVE-2015-5477"},{"cvss":10,"id":"CVE-2019-11510"},{"cvss":10,"id":"CVE-2021-22205"},{"cvss":9.8,"id":"CVE-2021-3199"},{"cvss":4.9,"id":"CVE-2023-22894"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bash","ProFTPD (\u003c 9.9.7-P2)","BIND (\u003c 9.9.7-P2)","Struts","Connect Secure","GitLab","Document Server","Strapi","Exchange Server","Microsoft 365","ScreenOS","Jenkins","WebLogic Server"],"_cs_severities":["high"],"_cs_tags":["espionage","china","cyber-espionage","microsoft-365","dcsync"],"_cs_type":"threat","_cs_vendors":["GNU","ProFTPD","ISC","Apache","Pulse Secure","GitLab","ONLYOFFICE","Strapi","Microsoft","Juniper Networks","Jenkins","Oracle"],"content_html":"\u003cp\u003eIntegrity Technology Group, a China-based for-profit company linked to state security agencies, has conducted widespread espionage against government, law enforcement, healthcare, and religious institutions across Southeast Asia, Africa, and North America since at least 2021. The group leverages a diverse set of penetration testing scripts and automated scanning tools to identify and exploit vulnerabilities in legacy services and web applications. Beyond exploitation, they utilize password spraying against Microsoft 365 and Exchange environments, coupled with XSS-based phishing to harvest credentials.\u003c/p\u003e\n\u003cp\u003eThe group maintains persistence through disguised legitimate software and exfiltrates sensitive email content via custom bots and tools that interface directly with Exchange Web Services. Notably, the group facilitates third-party access to stolen data via a specialized web portal, indicating a high-level operational model that prioritizes data monetization or dissemination. US and UK authorities have sanctioned the group for its role in targeting critical infrastructure. Defenders should prioritize auditing Active Directory replication, monitoring Exchange interface access, and patching the documented vulnerabilities exploited by the group.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial Reconnaissance: Attackers scan for exposed services (ports 21, 22, 53, 80, 443, 1080) using tools like Nmap, masscan, and MicroScan (containing 1,300+ penetration scripts).\u003c/li\u003e\n\u003cli\u003eInitial Access: Attackers exploit known vulnerabilities (CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894) or perform password spraying against Microsoft 365/Exchange interfaces.\u003c/li\u003e\n\u003cli\u003eCredential Harvesting: Actors deploy XSS payloads on legitimate web pages to redirect users to fake login portals to steal usernames and passwords, or use EBurst to brute-force authentication.\u003c/li\u003e\n\u003cli\u003ePersistence: Attackers install SoftEther VPN, renaming the binary to 'conhost.exe' or 'dllhost.exe' to mimic Windows system processes and establishing persistence upon system reboot.\u003c/li\u003e\n\u003cli\u003eCredential Access: Attackers execute 'DC.exe' to leverage the DCSync technique, extracting account credentials and trust relationships from domain controllers.\u003c/li\u003e\n\u003cli\u003eCollection: Attackers deploy the PHP script 'Curlc4.txt' or the 'office-cli' utility to interface with Exchange Web Services (EWS) and copy sensitive mailboxes.\u003c/li\u003e\n\u003cli\u003eExfiltration: Stolen email content is compressed and uploaded to attacker-controlled C2 infrastructure, such as 'natcloudservice.com'.\u003c/li\u003e\n\u003cli\u003eImpact: Stolen information is ingested into a web-based portal to provide third-party access to the intelligence, affecting diverse sectors including law enforcement and healthcare.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis campaign has resulted in the theft of high-value communications from government agencies, law enforcement, healthcare systems, and religious organizations globally. By enabling third-party access to stolen emails through a web portal, the threat actor significantly increases the potential for downstream exploitation and geopolitical intelligence leverage. The duration of the campaign, active since 2021, suggests large-scale, long-term exposure of sensitive data across multiple continents.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBlock known malicious C2 domains including 'dns.studiocloud.xyz' and 'natcloudservice.com' at the DNS resolver level.\u003c/li\u003e\n\u003cli\u003ePatch the 8 identified vulnerabilities (CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894) across all perimeter and internal services.\u003c/li\u003e\n\u003cli\u003eEnforce MFA across all Microsoft 365, VPN, and critical email infrastructure.\u003c/li\u003e\n\u003cli\u003eAudit Active Directory for anomalous replication events associated with the DCSync technique (e.g., unexpected 'GetNCChanges' calls).\u003c/li\u003e\n\u003cli\u003eReview web server logs for suspicious MicroScan patterns or XSS injection attempts.\u003c/li\u003e\n\u003cli\u003eMonitor process creation for 'conhost.exe' or 'dllhost.exe' originating from non-system paths, specifically those associated with VPN binary signatures.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:12:19Z","date_published":"2026-10-08T19:12:19Z","id":"https://feed.craftedsignal.io/briefs/2026-10-integrity-technology-espionage/","summary":"Integrity Technology Group, a Chinese for-profit entity, is conducting multi-year cyber espionage targeting government, healthcare, and religious institutions using automated vulnerability scanning, credential harvesting, and specialized data exfiltration tools.","title":"China-Linked Espionage Campaign Targeting Global Infrastructure via Integrity Technology Group","url":"https://feed.craftedsignal.io/briefs/2026-10-integrity-technology-espionage/"}],"language":"en","title":"CraftedSignal Threat Feed - Document Server","version":"https://jsonfeed.org/version/1.1"}