Skip to content
Security & Trust

Agencies: China-linked hackers use free tools and a real VPN to steal email

A joint advisory describes an intrusion built from ordinary parts that blend into normal IT work.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Agencies: China-linked hackers use free tools and a real VPN to steal email
In brief
  • A joint advisory from CISA, the FBI and partner agencies says China-linked actors tied to Integrity Technology Group steal email and credentials using free scanners and legitimate VPN software.
  • Because the tools look like routine IT, detection depends on knowing what should be installed and running, not on spotting obviously malicious software.
  • Leaders should confirm multifactor authentication, close unused ports, inventory VPN clients and watch Exchange and Active Directory access, then check logs against the published indicators.

Security teams are trained to look for something strange. A new joint advisory describes an intrusion built to look routine. CISA published it on October 8. The FBI and NSA co-wrote it with agencies from the UK, Australia, Canada, Japan, New Zealand and Spain.

The attackers use free scanners, a real VPN program and file names borrowed from Windows. The lesson here is simple. The hardest intrusions to catch may be the ones that look like your own IT team's daily work.

Who the agencies are describing

The advisory centres on Integrity Technology Group. It is a for-profit company based in China. The agencies say it has links to the Chinese government.

They say its staff build or buy hacking tools. They also host attack infrastructure and break into networks.

The agencies say the methods resemble those of groups the industry calls Flax Typhoon, Ethereal Panda and Red Juliett. The list is not complete. Other names also fit.

The agencies add two caveats. Security vendors track groups in different ways, so labels may not match exactly. These actors may also do work that has nothing to do with Integrity Tech.

Victims came from several fields. In the US, they included government services, manufacturing, health care and IT. The agencies class these as critical infrastructure. Police, schools and religious groups were also hit. So were organisations in Southeast Asia, Africa and North America.

The evidence comes from several FBI investigations.

How the chain works

First, the actors look for weak targets. They use free, open source scanners such as NMAP, masscan, dirsearch and wpscan. They mostly probe six ports. These cover file transfer (21), remote login (22), name lookup (53), web traffic (80, 443) and proxy traffic (1080).

The advisory says free public tools suggest the actors look for easier victims.

They have also used MicroScan, a Python web application packed with scanning scripts. It checks sites for known flaws in products such as OpenSSL, Oracle WebLogic, WordPress, Jenkins and Apache Struts.

Second, they get in. One method is cross-site scripting, or XSS. Booby-trapped code on a vulnerable site changes what a visitor sees.

The FBI recovered one such payload. It shows a fake login form. The user can type any name and password. The page then offers a download.

The download holds a program called live700_v1.exe. It starts a process named DiagTrack.exe. That is also the name of real Windows software. The FBI assesses that the program likely targets email data.

A second method is password spraying. A tool called EBurst tries common passwords across many Exchange and Office365 mailboxes. This avoids hammering one account until it locks.

Third, they stay. The actors install SoftEther, a genuine VPN client. They set it to reconnect at startup. They often name the installer conhost.exe or dllhost.exe.

SoftEther is real VPN software. The advisory says security tools on the device are therefore less likely to flag it.

Fourth, they take the mail. A PHP script called Curlc4.txt talked to Microsoft's Exchange Web Services interface. That interface exposes email, calendars and contacts. The script compressed emails before sending them out. Sometimes it also encrypted them.

A separate tool, DC.exe, used a technique called DCSync. It asks a domain controller to hand over Active Directory data. That data includes account credentials, group memberships and trust relationships.

1,300+
Penetration-testing scripts in MicroScan
Source: CISA joint advisory AA26-281a (October 8, 2026)
2017
Earliest reported MicroScan use
Source: CISA joint advisory AA26-281a (October 8, 2026)
6
Ports the actors mainly scan
Source: CISA joint advisory AA26-281a (October 8, 2026)

Why this is hard for defenders

No single step needs an exotic tool. The scanners are free. The VPN is real. A file named like a Windows component draws little attention.

The agencies stress that the techniques are not unique to Chinese actors. What the advisory documents is the combination, aimed at email and identity data.

That changes the question a detection team must ask. It is no longer "is this software malicious?" It becomes "should this software be on this machine, talking to that address?"

What leaders should ask this week

The advisory's own priorities are clear. Turn off unused services and ports. Clean up the inputs that web applications accept. Require multifactor authentication on every service. Patch promptly.

Then put these questions to your teams. Do we know every VPN client installed on servers and laptops? Who approved each one?

Do files called conhost.exe or dllhost.exe appear outside their normal locations? Who watches access to our Exchange Web Services interface?

Could we see a domain controller being asked for bulk copies of credentials? Do all email accounts, including old ones, require multifactor authentication?

Ask also for the advisory's indicators of compromise. CISA offers them as a download. Have your team check them against your logs.

Software that is allowed to run can still be doing the wrong job. A budget that only pays to detect the unusual will miss an attacker who stays ordinary.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.

Share this insight