China-Linked Hackers Pair Automated Scanning With Hands-On Attacks to Steal Business Data
CISA has published an advisory describing how Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are stealing sensitive data from organisations worldwide. The targets include US critical infrastructure sectors. The advisory dates from 8 October 2026.
The actors blend automated and manual methods. They use scanning tools and large-scale botnets to find weaknesses, then follow up with hands-on exploitation. The techniques named include cross-site scripting attacks and password spraying against Microsoft Exchange servers. Once inside, they establish a lasting foothold through VPN software and use scripts to pull out emails and credentials. The advisory also lists a number of known vulnerabilities, some of them several years old, which shows that unpatched systems remain an easy way in.
To reduce the risk, CISA recommends that organisations disable unused services and ports, sanitise web application inputs to prevent injection attacks, enable multifactor authentication on all services, and apply patches promptly. These steps are especially relevant for any business running Microsoft Exchange or exposing VPN and web services to the internet.