Allied Governments Warn of Sanctioned Chinese Firm Linked to Global Hacking Operations
The US, UK and several allied countries have published a joint advisory describing the tactics, techniques and procedures linked to Integrity Technology Group, a sanctioned Chinese organisation. Released on October 8, the advisory says the company's work has in the past enabled prolific Beijing-backed groups, including Flax Typhoon (also known as Ethereal Panda and Red Juliett).
According to the advisory, Integrity Tech employs people who support malicious cyber activity in several ways. These include acquiring or building cyber tools for use and sale, acquiring and hosting infrastructure, and compromising networks across global victims. The authors say its services also feed into the wider Chinese cyber ecosystem, which aims to steal sensitive data from victims around the world.
The report includes a large number of indicators of compromise, additional resources and mitigations, plus guidance for incident responders who suspect they may already be affected. Paul Chichester, the UK NCSC's director of operations, said the range of sectors targeted worldwide shows the extent of the threat, and that all organisations should take note and engage with NCSC advice. Also on October 8, the US announced it had seized several domains tied to hacking tools called Microscan and FishHub, aiming to disrupt Integrity Tech and associated threat groups.
This summary is based on the opening of the source article, so further technical detail and the full list of recommended mitigations are in the original advisory.