Red Team

NCSC and allies expose Integrity Tech’s China-linked hacking toolkit

NCSC co-sealed advisory AA26-281A details Integrity Tech’s tooling: mass scanning, Exchange password spraying, SoftEther persistence and DCSync.

Target motif with the headline Allies expose China-linked hacking contractor's toolkit

The NCSC and partners in six other countries have published a 58-page technical breakdown of how Beijing-based Integrity Technology Group equips China-linked intruders. Most of the tradecraft is unglamorous, which is exactly why UK defenders should read it closely.

What happened

On 8 October 2026 the UK’s National Cyber Security Centre co-sealed a joint cybersecurity advisory, product ID AA26-281A, with the FBI, CISA and NSA in the United States and agencies from Australia, Canada, Japan, New Zealand and Spain. Its subject is Integrity Technology Group (Integrity Tech), a for-profit Chinese company the authoring agencies say has links to the Chinese state and supplies tools, infrastructure and hands-on intrusion capability to China-linked threat actors. The activity overlaps with the clusters industry tracks under names including Flax Typhoon, Red Juliett and Ethereal Panda.

The advisory landed alongside a US law enforcement operation. The Justice Department and FBI seized seven domains behind two Integrity Tech platforms, a vulnerability scanning service called MicroScan and a phishing and payload delivery tool called FishHub. Reported targets of the scanning include a power company in South Carolina, airports in Japan and Poland, Taiwanese energy firms and universities in Taiwan. The same day CISA added five of the eight vulnerabilities named in the advisory to its Known Exploited Vulnerabilities catalogue, giving US federal agencies until 11 October to patch.

This is not a new name for the NCSC. In September 2024 it helped expose Integrity Tech as the operator of a large Mirai-based botnet of compromised consumer and IoT devices, and the UK government sanctioned the company in 2025. Paul Chichester, the NCSC’s Director of Operations, said the activity exposed this week “should be extremely concerning for all network defenders”.

The technical picture

What stands out to me, reading the full advisory, is how closely the reconnaissance phase resembles a commercial external test. The actors lean on well-known open source tooling (masscan, Nmap, Fscan, dirsearch, wpscan, OneForAll and others) and concentrate on a small set of ports: FTP, SSH, DNS, HTTP, HTTPS and SOCKS. MicroScan, in use since at least 2017 according to the FBI, wraps more than 1,300 vulnerability check scripts aimed at products such as Oracle WebLogic, Jenkins, Apache Struts, WordPress and Juniper ScreenOS. The emphasis is volume: find the easy, exposed and forgotten, then go deeper only where it pays.

The exploited vulnerabilities reinforce that point. The list includes Shellshock (CVE-2014-6278), ProFTPD (CVE-2015-3306), an ISC BIND denial of service bug (CVE-2015-5477), Apache Struts (CVE-2016-3081), Ivanti Pulse Connect Secure (CVE-2019-11510), GitLab (CVE-2021-22205), ONLYOFFICE Docs (CVE-2021-3199) and Strapi (CVE-2023-22894). Several are approaching a decade old. None of them should still be reachable on a maintained estate.

Initial access also relies on cross-site scripting. The FBI recovered a payload that rewrote a vulnerable page to show a fake login form, harvested whatever was typed in, then offered a password-protected archive containing malware that launched a process named DiagTrack.exe to blend in with the legitimate Windows service.

Email is the clear prize. The open source tool EBurst is used to password spray and guess credentials across Exchange and Microsoft 365 interfaces, including OWA, EWS, Autodiscover, ActiveSync and MAPI. Once in, a command-line utility called office-cli uses app credentials (client ID, tenant ID and secret) to pull mailbox contents on a rolling basis, and a PHP bot talks to the EWS API to compress, optionally encrypt and ship mail to attacker servers. Integrity Tech even ran a web portal that let third parties browse stolen email.

For persistence the actors install SoftEther, a legitimate VPN client, often renamed to look like conhost.exe or dllhost.exe and set to reconnect on boot. Inside Windows domains they used a tool called DC.exe to perform DCSync, replicating credentials and trust information straight from domain controllers.

Flow diagram of the five intrusion stages described in advisory AA26-281A, from mass scanning to email exfiltration

Why it matters for UK organisations

The advisory’s named victims are mostly in the US, Taiwan and Southeast Asia, but the NCSC co-sealed it, published its own alert and pointed UK organisations to its guidance. Nothing in this toolkit is region specific. Automated scanning does not check nationality before it fingers an unpatched Struts server or a password-sprayable OWA endpoint, and the NCSC’s audience listing for the alert covers large organisations and the public sector, not just national infrastructure.

There is also a pointed UK detail in the indicators: one of the domains linked to SoftEther command and control in the advisory sits under the .co.uk namespace, a reminder that malicious infrastructure is often registered to look locally familiar. With UK cyber regulation moving steadily towards broader incident reporting and baseline security duties, a public, multi-government warning like this is the sort of thing boards should expect to be asked about.

Expert view

When we test UK organisations externally, the findings that lead to real compromise are rarely exotic. They are an old appliance nobody owns, a legacy web app with a reflected XSS, or a mail interface where legacy authentication was never switched off. This advisory reads like a catalogue of exactly those issues, operated at industrial scale by a state-aligned contractor.

The bit I would want every Microsoft 365 administrator to absorb is the office-cli detail. Once an attacker holds an application registration with mail read permissions, they no longer need a user’s password or to beat MFA again. That access looks like a legitimate integration, and in my experience app registrations and consented enterprise applications are among the least reviewed objects in a tenant. Equally, SoftEther running on a server should be treated as an incident until proven otherwise, precisely because endpoint tools tend to trust it.

I would also be cautious about reading too much into the NCSC’s reference to AI tools; the published technical detail describes automation and scripted scanning rather than anything novel. The lesson is speed and scale, not magic.

What to do now

  1. Patch or retire the eight listed CVEs and check for any internet-facing ProFTPD, Struts, BIND, Pulse Secure, GitLab, ONLYOFFICE or Strapi instances you did not know about (Cyber Essentials: security update management).
  2. Shrink your external footprint. Close unused ports and services, suppress version banners and run an external scan of your own ranges this week (Cyber Essentials: firewalls, secure configuration).
  3. Harden Microsoft 365 and Exchange. Enforce MFA everywhere, block legacy authentication and review sign-in logs for spraying patterns across EWS, ActiveSync and Autodiscover (Cyber Essentials: user access control).
  4. Audit app registrations and consented applications for mail read permissions, unfamiliar client secrets and owners you cannot account for.
  5. Hunt for the persistence and credential theft indicators: SoftEther binaries or services, renamed conhost.exe or dllhost.exe outside system paths, and directory replication requests from hosts that are not domain controllers (Cyber Essentials: malware protection).
  6. Fix XSS in your web estate and consider the NCSC’s Protective DNS service if you are eligible. Load the advisory’s STIX indicators into your SIEM or EDR.

Bottom line

AA26-281A is less a story about a sophisticated adversary than about a well-organised one that profits from basic gaps. If your organisation would struggle to say, today, which internet-facing services it runs and which applications can read its mailboxes, this advisory is your prompt to find out before someone else’s scanner does.

Sources