{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/screenos/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Flax Typhoon","Ethereal Panda"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Struts","ScreenOS","Jenkins","OpenSSL","WebLogic Server","WordPress","Exchange Server"],"_cs_severities":["high"],"_cs_tags":["state-sponsored","intelligence-disruption","critical-infrastructure","espionage"],"_cs_type":"threat","_cs_vendors":["Apache","Juniper","Jenkins","OpenSSL","Oracle","Rejetto","WordPress","Microsoft"],"content_html":"\u003cp\u003eThe United States government has announced the seizure of domains associated with Integrity Technology Group (Integrity Tech), an entity previously sanctioned for providing cyber tools to Chinese state-sponsored threat actors. The disruption targeted two primary tools: MicroScan, a Python-based vulnerability scanner containing over 1,300 penetration testing scripts, and FishHub, a platform enabling remote access and data exfiltration. These tools have been active since 2017, targeting a broad range of technologies including Apache Struts, Juniper ScreenOS, Jenkins, Oracle WebLogic, and WordPress. Flax Typhoon and other associated APTs leveraged these tools alongside IoT botnets to conduct large-scale reconnaissance and persistent intrusion operations against critical infrastructure in the US, Japan, Taiwan, and Europe. Defenders should note that these actors continue to utilize custom scripts for email exfiltration and Active Directory data theft.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial reconnaissance performed using MicroScan via an IoT botnet to identify vulnerable services (e.g., Apache Struts, WebLogic, WordPress).\u003c/li\u003e\n\u003cli\u003eInitial access achieved through spear-phishing campaigns or exploitation of discovered vulnerabilities in internet-facing services.\u003c/li\u003e\n\u003cli\u003eDeployment of SoftEther VPN tools on compromised assets to establish persistent, remote access to internal networks.\u003c/li\u003e\n\u003cli\u003eCredential harvesting conducted using tools like EBurst against Microsoft Exchange servers.\u003c/li\u003e\n\u003cli\u003eInternal reconnaissance and lateral movement facilitated by tools such as Fscan and Nmap.\u003c/li\u003e\n\u003cli\u003eData collection and sensitive information extraction from Active Directory using the utility DC.ex.\u003c/li\u003e\n\u003cli\u003eFinal exfiltration of email databases and proprietary files using custom utilities like office-cli and PHP script Curlc4.txt.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign targeted critical infrastructure entities including power companies, government organizations, law enforcement agencies, healthcare systems, and universities across Southeast Asia, Japan, and Poland. Documented impacts include mass email data exfiltration, theft of sensitive Active Directory data, and unauthorized persistence within the networks of critical NGOs and government institutions. The use of IP-restricted access mechanisms for exfiltrated data highlights the long-term impact on victim privacy and operational security.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize hunting for the specific tools and infrastructure associated with Integrity Tech in your environment.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlock the seized C2 domains listed in the IOC table at the network perimeter.\u003c/li\u003e\n\u003cli\u003eReview network logs for outbound connections to these identified domains.\u003c/li\u003e\n\u003cli\u003eHunt for the presence of the specific exfiltration utilities mentioned (office-cli, Curlc4.txt) and the DC.ex utility on high-value targets.\u003c/li\u003e\n\u003cli\u003eAudit internet-facing services (Apache Struts, Jenkins, Oracle WebLogic, WordPress) for signs of unauthorized scanning or reconnaissance patterns described in the advisory.\u003c/li\u003e\n\u003cli\u003eMonitor for the deployment of SoftEther VPN software, as it is a favored tool for persistence in this campaign.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T08:39:25Z","date_published":"2026-10-09T08:39:25Z","id":"https://feed.craftedsignal.io/briefs/2026-10-chinese-hacking-tools-disruption/","summary":"The US government disrupted infrastructure supporting Integrity Technology Group tools MicroScan and FishHub, which Chinese state-sponsored actors, including Flax Typhoon, used to compromise critical infrastructure.","title":"Disruption of Integrity Technology Group Hacking Tools","url":"https://feed.craftedsignal.io/briefs/2026-10-chinese-hacking-tools-disruption/"},{"_cs_actors":["Integrity Technology Group"],"_cs_cpes":["cpe:2.3:a:proftpd:proftpd:1.3.5:*:*:*:*:*:*:*","cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*","cpe:2.3:a:ivanti:connect_secure:8.2:*:*:*:*:*:*:*","cpe:2.3:a:ivanti:connect_secure:8.3:*:*:*:*:*:*:*","cpe:2.3:a:ivanti:connect_secure:9.0:*:*:*:*:*:*:*","cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","cpe:2.3:a:onlyoffice:document_server:*:*:*:*:*:*:*:*","cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2015-3306"},{"id":"CVE-2015-5477"},{"cvss":10,"id":"CVE-2019-11510"},{"cvss":10,"id":"CVE-2021-22205"},{"cvss":9.8,"id":"CVE-2021-3199"},{"cvss":4.9,"id":"CVE-2023-22894"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bash","ProFTPD (\u003c 9.9.7-P2)","BIND (\u003c 9.9.7-P2)","Struts","Connect Secure","GitLab","Document Server","Strapi","Exchange Server","Microsoft 365","ScreenOS","Jenkins","WebLogic Server"],"_cs_severities":["high"],"_cs_tags":["espionage","china","cyber-espionage","microsoft-365","dcsync"],"_cs_type":"threat","_cs_vendors":["GNU","ProFTPD","ISC","Apache","Pulse Secure","GitLab","ONLYOFFICE","Strapi","Microsoft","Juniper Networks","Jenkins","Oracle"],"content_html":"\u003cp\u003eIntegrity Technology Group, a China-based for-profit company linked to state security agencies, has conducted widespread espionage against government, law enforcement, healthcare, and religious institutions across Southeast Asia, Africa, and North America since at least 2021. The group leverages a diverse set of penetration testing scripts and automated scanning tools to identify and exploit vulnerabilities in legacy services and web applications. Beyond exploitation, they utilize password spraying against Microsoft 365 and Exchange environments, coupled with XSS-based phishing to harvest credentials.\u003c/p\u003e\n\u003cp\u003eThe group maintains persistence through disguised legitimate software and exfiltrates sensitive email content via custom bots and tools that interface directly with Exchange Web Services. Notably, the group facilitates third-party access to stolen data via a specialized web portal, indicating a high-level operational model that prioritizes data monetization or dissemination. US and UK authorities have sanctioned the group for its role in targeting critical infrastructure. Defenders should prioritize auditing Active Directory replication, monitoring Exchange interface access, and patching the documented vulnerabilities exploited by the group.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial Reconnaissance: Attackers scan for exposed services (ports 21, 22, 53, 80, 443, 1080) using tools like Nmap, masscan, and MicroScan (containing 1,300+ penetration scripts).\u003c/li\u003e\n\u003cli\u003eInitial Access: Attackers exploit known vulnerabilities (CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894) or perform password spraying against Microsoft 365/Exchange interfaces.\u003c/li\u003e\n\u003cli\u003eCredential Harvesting: Actors deploy XSS payloads on legitimate web pages to redirect users to fake login portals to steal usernames and passwords, or use EBurst to brute-force authentication.\u003c/li\u003e\n\u003cli\u003ePersistence: Attackers install SoftEther VPN, renaming the binary to 'conhost.exe' or 'dllhost.exe' to mimic Windows system processes and establishing persistence upon system reboot.\u003c/li\u003e\n\u003cli\u003eCredential Access: Attackers execute 'DC.exe' to leverage the DCSync technique, extracting account credentials and trust relationships from domain controllers.\u003c/li\u003e\n\u003cli\u003eCollection: Attackers deploy the PHP script 'Curlc4.txt' or the 'office-cli' utility to interface with Exchange Web Services (EWS) and copy sensitive mailboxes.\u003c/li\u003e\n\u003cli\u003eExfiltration: Stolen email content is compressed and uploaded to attacker-controlled C2 infrastructure, such as 'natcloudservice.com'.\u003c/li\u003e\n\u003cli\u003eImpact: Stolen information is ingested into a web-based portal to provide third-party access to the intelligence, affecting diverse sectors including law enforcement and healthcare.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis campaign has resulted in the theft of high-value communications from government agencies, law enforcement, healthcare systems, and religious organizations globally. By enabling third-party access to stolen emails through a web portal, the threat actor significantly increases the potential for downstream exploitation and geopolitical intelligence leverage. The duration of the campaign, active since 2021, suggests large-scale, long-term exposure of sensitive data across multiple continents.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBlock known malicious C2 domains including 'dns.studiocloud.xyz' and 'natcloudservice.com' at the DNS resolver level.\u003c/li\u003e\n\u003cli\u003ePatch the 8 identified vulnerabilities (CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894) across all perimeter and internal services.\u003c/li\u003e\n\u003cli\u003eEnforce MFA across all Microsoft 365, VPN, and critical email infrastructure.\u003c/li\u003e\n\u003cli\u003eAudit Active Directory for anomalous replication events associated with the DCSync technique (e.g., unexpected 'GetNCChanges' calls).\u003c/li\u003e\n\u003cli\u003eReview web server logs for suspicious MicroScan patterns or XSS injection attempts.\u003c/li\u003e\n\u003cli\u003eMonitor process creation for 'conhost.exe' or 'dllhost.exe' originating from non-system paths, specifically those associated with VPN binary signatures.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:12:19Z","date_published":"2026-10-08T19:12:19Z","id":"https://feed.craftedsignal.io/briefs/2026-10-integrity-technology-espionage/","summary":"Integrity Technology Group, a Chinese for-profit entity, is conducting multi-year cyber espionage targeting government, healthcare, and religious institutions using automated vulnerability scanning, credential harvesting, and specialized data exfiltration tools.","title":"China-Linked Espionage Campaign Targeting Global Infrastructure via Integrity Technology Group","url":"https://feed.craftedsignal.io/briefs/2026-10-integrity-technology-espionage/"}],"language":"en","title":"CraftedSignal Threat Feed - ScreenOS","version":"https://jsonfeed.org/version/1.1"}