CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
NOTABLECVE-2015-3306 +7exploitedNATOA2threat

AA26-281A: China-linked actors enabled by Integrity Technology Group scan with MicroScan, spray Exchange and Microsoft 365 passwords and steal mail, and five old flaws from the scanner's scripts enter CISA KEV

Joint advisory: Flax Typhoon-consistent actors spray Exchange and Microsoft 365, steal mail and keep SoftEther access

Analysis

The FBI, CISA, NSA, NCSC UK and partners from Australia, Canada, Japan, New Zealand and Spain describe Integrity Technology Group as a China-based company with links to the Chinese government that builds and sells cyber tools, hosts infrastructure and compromises networks; the actors it enables use tactics consistent with Flax Typhoon, Ethereal Panda and Red Juliett, among others (FBI IC3, AA26-281A, 2026-10-08). The Justice Department says the FBI seized the domains of MicroScan and the FishHub phishing platform, both operated by Integrity Tech (U.S. Department of Justice, 2026-10-08). Victims include U.S. government services, other critical sectors and organisations in Southeast Asia, Africa and North America; the advisory names no Swiss victim (FBI IC3, AA26-281A, 2026-10-08).

The chain starts with open-source scanners and MicroScan, a Python-based web application of 1,300-plus scripts, used since at least 2017 (FBI IC3, AA26-281A, 2026-10-08). Initial access has mostly come since January 2021 from command-line exploit utilities, and additionally from a cross-site-scripting payload that overlays a login form and offers a ZIP holding an executable that starts a process named like the Windows DiagTrack service (FBI IC3, AA26-281A, 2026-10-08). The actors spray and guess passwords with the EBurst tool against Exchange and Microsoft 365 (ECP, EWS, OAB, OWA, RPC, API, MAPI, PowerShell, Autodiscover, ActiveSync) (FBI IC3, AA26-281A, 2026-10-08). Persistence is a SoftEther VPN client, often named conhost.exe or dllhost.exe, which endpoint tools are less likely to flag (FBI IC3, AA26-281A, 2026-10-08). Collection uses a PHP bot and a Linux utility that read mail through Exchange Web Services and Microsoft 365 with application client, tenant and secret values, and a DCSync tool that replicates directory data from a domain controller; mail was stolen from government, law-enforcement and healthcare bodies in Southeast Asia (FBI IC3, AA26-281A, 2026-10-08).

Appendix B lists eight successfully exploited CVEs recovered from MicroScan's scripts: ProFTPD 1.3.5, ISC BIND 9.x, Apache Struts 2.3.19 to 2.3.28, ONLYOFFICE DocumentServer 5.1.5 through 5.6.2 and Strapi up to 4.5.5, plus GNU Bash through 4.3, Pulse Connect Secure and GitLab from 11.9 (FBI IC3, AA26-281A, 2026-10-08); CISA added the first five to its catalogue on 2026-10-08 (CISA KEV catalogue, 2026-10-08). Apache names Struts 2.3.20.3, 2.3.24.3 and 2.3.28.1 as fixed (Apache Struts, 2021-02-13) and Strapi names 4.8.0 (Strapi, 2023-04-17).

Triage: conhost.exe and dllhost.exe are legitimate Windows names, so the file's path, signature and network behaviour separate a downloaded SoftEther client from the system binary (FBI IC3, AA26-281A, 2026-10-08).

Cited evidence

The activity in the advisory is reported to be consistent with campaigns also publicly known as Flax Typhoon, Ethereal Panda and Red Juliett among others.

NCSC UK 2026-10-08

Integrity Tech has contracts with the PRC government.

U.S. Department of Justice 2026-10-08

Network defenders should include these interfaces when defending against EBurst.

FBI, CISA, NSA, NCSC UK and partners (joint advisory AA26-281A) 2026-10-08

Sources6

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.