UK, US and allied cyber authorities have publicly named China-based Integrity Technology Group as a central enabler of government-linked hacking operations that are stealing sensitive data and probing critical infrastructure worldwide.[1][2][3] A joint advisory released this week by the UK National Cyber Security Centre, the US National Security Agency, FBI and partners in Australia, Canada, Japan, New Zealand and Spain warns that Integrity Tech’s tools and infrastructure are being used at scale by Chinese state-linked threat actors to compromise networks across multiple sectors.[1][2][3]
The advisory describes Integrity Tech as a for-profit company with links to the Chinese government whose employees build or acquire offensive cyber tools, host infrastructure and conduct intrusions on behalf of China-linked actors.[2][6][12] The company’s operations have enabled campaigns targeting government services and facilities, critical manufacturing, healthcare, public health and information technology organizations, with victims reported in North America, Europe, Asia and Africa.[2][3][4] Authorities stress that the activity is focused on long-term access and data theft rather than noisy disruption, making it particularly difficult for defenders to spot without proactive threat hunting.[3][9][14]
According to the technical report accompanying the advisory, Integrity Tech-supported operators combine automated scanning tools, large-scale botnets and hands-on-keyboard exploitation to identify and weaponize vulnerabilities in exposed internet-facing systems.[3][4][11] UK officials say the firm’s tooling incorporates artificial intelligence to accelerate reconnaissance, allowing threat actors to rapidly sift through global attack surfaces for misconfigurations and unpatched services before pivoting manually once inside target networks.[1][3][11] US law enforcement filings further allege that Integrity Tech built a botnet of compromised Internet-of-Things devices using a Mirai-derived malware variant, which was then used to power large-scale vulnerability scanning and follow-on attacks.[4][11][15]
The campaign is closely linked to the Chinese state-sponsored group known as Flax Typhoon, also tracked as Ethereal Panda and Red Juliett, which has been active since at least 2021 and repeatedly targeted US critical infrastructure organizations.[5][8][10] The US Treasury Department sanctioned Integrity Technology Group in January 2025 for supporting Flax Typhoon operations, citing incidents in which the group leveraged the company’s infrastructure and tools to conduct espionage and data exfiltration against American entities.[6][8][11] This week’s action builds on that designation, with the FBI and Department of Justice announcing the seizure of multiple domains associated with Integrity Tech-operated tools “Microscan” and “FishHub,” which were used for vulnerability scanning and spearphishing in support of Flax Typhoon’s global campaigns.[4][11][13]
For defenders, the advisory underscores that the threat is not limited to any single product or CVE but to a broad class of exposed services and weak credentials that Integrity Tech-enabled actors can rapidly discover and exploit.[3][7][9] Organizations in the named sectors are urged to review the report’s indicators of compromise and tactics, techniques and procedures, deploy multi-factor authentication on all remote access services, harden and segment IoT devices, and prioritize patching of internet-facing systems identified as vulnerable in recent vendor and government advisories.[2][3][5] The authors also recommend aggressive logging, centralized monitoring and regular threat hunting based on the provided telemetry to detect botnet scanning, anomalous authentication patterns and lateral movement associated with the campaign.[3][7][9]
Beyond immediate mitigation, the UK and its allies frame Integrity Tech as emblematic of a wider ecosystem of commercial entities that sell or operate offensive cyber capabilities for state-linked customers, blurring the line between government and private-sector responsibility.[1][2][12] By calling out the company by name and combining sanctions, technical disruption and public guidance, Western governments are signaling that firms which materially support state-backed hacking activity face not only diplomatic and legal consequences but also coordinated cyber countermeasures.[8][11][14] Security leaders are being urged to treat relationships with such vendors, and exposure to their tooling, as a strategic risk and to integrate intelligence about enablers like Integrity Tech into existing nation-state threat models.[3][9][12]
References
- China-linked malicious actors called out by UK and …
- NSA Joins FBI and Others to Provide Guidance to Mitigate …
- Chinese Government-linked Cyber Threat Actors Combine …
- FBI seizes domains linked to China-nexus botnet
- UK Allies Warn of Cyber Threat from China’s Integrity …
- FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
- Chinese Government-linked Cyber Threat Actors Combine …
- Treasury Sanctions Technology Company for Support to …
- CISA AA26-281A: How Chinese Government-Linked Actors Steal Sensitive Data
- US cracks down on Chinese hacking group ‘Flax Typhoon’; seizes 7 internet domains
- FBI disrupts Flax Typhoon hacking tools used in global cyberattacks
- US Disrupts China-Linked Integrity Tech ‘s Cyber Espionage Tools
- DOJ, FBI seize Flax Typhoon-linked hacking tools …
- International coalition seizes tools used by cyber firm behind Flax Typhoon
- US Seizes China‑Linked Cyber Tools ‘Microscan’ and ‘ …
