{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/intelligence-disruption/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Flax Typhoon","Ethereal Panda"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Struts","ScreenOS","Jenkins","OpenSSL","WebLogic Server","WordPress","Exchange Server"],"_cs_severities":["high"],"_cs_tags":["state-sponsored","intelligence-disruption","critical-infrastructure","espionage"],"_cs_type":"threat","_cs_vendors":["Apache","Juniper","Jenkins","OpenSSL","Oracle","Rejetto","WordPress","Microsoft"],"content_html":"\u003cp\u003eThe United States government has announced the seizure of domains associated with Integrity Technology Group (Integrity Tech), an entity previously sanctioned for providing cyber tools to Chinese state-sponsored threat actors. The disruption targeted two primary tools: MicroScan, a Python-based vulnerability scanner containing over 1,300 penetration testing scripts, and FishHub, a platform enabling remote access and data exfiltration. These tools have been active since 2017, targeting a broad range of technologies including Apache Struts, Juniper ScreenOS, Jenkins, Oracle WebLogic, and WordPress. Flax Typhoon and other associated APTs leveraged these tools alongside IoT botnets to conduct large-scale reconnaissance and persistent intrusion operations against critical infrastructure in the US, Japan, Taiwan, and Europe. Defenders should note that these actors continue to utilize custom scripts for email exfiltration and Active Directory data theft.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial reconnaissance performed using MicroScan via an IoT botnet to identify vulnerable services (e.g., Apache Struts, WebLogic, WordPress).\u003c/li\u003e\n\u003cli\u003eInitial access achieved through spear-phishing campaigns or exploitation of discovered vulnerabilities in internet-facing services.\u003c/li\u003e\n\u003cli\u003eDeployment of SoftEther VPN tools on compromised assets to establish persistent, remote access to internal networks.\u003c/li\u003e\n\u003cli\u003eCredential harvesting conducted using tools like EBurst against Microsoft Exchange servers.\u003c/li\u003e\n\u003cli\u003eInternal reconnaissance and lateral movement facilitated by tools such as Fscan and Nmap.\u003c/li\u003e\n\u003cli\u003eData collection and sensitive information extraction from Active Directory using the utility DC.ex.\u003c/li\u003e\n\u003cli\u003eFinal exfiltration of email databases and proprietary files using custom utilities like office-cli and PHP script Curlc4.txt.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign targeted critical infrastructure entities including power companies, government organizations, law enforcement agencies, healthcare systems, and universities across Southeast Asia, Japan, and Poland. Documented impacts include mass email data exfiltration, theft of sensitive Active Directory data, and unauthorized persistence within the networks of critical NGOs and government institutions. The use of IP-restricted access mechanisms for exfiltrated data highlights the long-term impact on victim privacy and operational security.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize hunting for the specific tools and infrastructure associated with Integrity Tech in your environment.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eBlock the seized C2 domains listed in the IOC table at the network perimeter.\u003c/li\u003e\n\u003cli\u003eReview network logs for outbound connections to these identified domains.\u003c/li\u003e\n\u003cli\u003eHunt for the presence of the specific exfiltration utilities mentioned (office-cli, Curlc4.txt) and the DC.ex utility on high-value targets.\u003c/li\u003e\n\u003cli\u003eAudit internet-facing services (Apache Struts, Jenkins, Oracle WebLogic, WordPress) for signs of unauthorized scanning or reconnaissance patterns described in the advisory.\u003c/li\u003e\n\u003cli\u003eMonitor for the deployment of SoftEther VPN software, as it is a favored tool for persistence in this campaign.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T08:39:25Z","date_published":"2026-10-09T08:39:25Z","id":"https://feed.craftedsignal.io/briefs/2026-10-chinese-hacking-tools-disruption/","summary":"The US government disrupted infrastructure supporting Integrity Technology Group tools MicroScan and FishHub, which Chinese state-sponsored actors, including Flax Typhoon, used to compromise critical infrastructure.","title":"Disruption of Integrity Technology Group Hacking Tools","url":"https://feed.craftedsignal.io/briefs/2026-10-chinese-hacking-tools-disruption/"}],"language":"en","title":"CraftedSignal Threat Feed - Intelligence-Disruption","version":"https://jsonfeed.org/version/1.1"}