Agencies from the United States, the United Kingdom, Australia, Canada, Japan, New Zealand and Spain put their names to a single advisory on 8 October accusing a Beijing company of supplying the tools behind years of intrusions. The 58-page document carries the FBI, CISA and the NSA alongside Britain's National Cyber Security Centre, Australia's Signals Directorate, the Canadian Centre for Cybersecurity, two Japanese agencies, New Zealand's NCSC and Spain's intelligence service.
Integrity Technology Group is the company named in the advisory, described as a China-based for-profit business with links to the Chinese government. Its employees acquire or build cyber tools for use and sale, host infrastructure, and compromise networks worldwide.
The Justice Department and the FBI seized the domains behind two of those tools the same day, under warrants unsealed in the Western District of Pennsylvania. Six domains are named in the filing, covering MicroScan, which hunts for weaknesses in a target's systems, and FishHub, which delivers malware through emails written to look legitimate.
Brett Leatherman, who runs the FBI's Cyber Division, set out the logic of going after a supplier rather than an attacker. "The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity," he said. "By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure."
A Web Page For Reading Stolen Mail
The actors enabled by Integrity Tech maintain a custom web application that gives third parties access to stolen email content. A user passes arguments in a web address to pull up the messages belonging to one specific account. Two sentences in the 58 pages describe it.
Access to some of that material was restricted by geography, to internet addresses in Xiamen, China. The FBI also recovered an archived email database the attackers had used to choose which accounts to target, and the advisory says the stolen mail came from both on-premises servers and cloud accounts.
Who those third parties were is not stated anywhere. The advisory does not say how many there were, whether they paid for access, how many mailboxes the application exposed, or what the application was called.
Victims of the email theft were government organisations, law enforcement agencies, healthcare systems and religious institutions in Southeast Asia. Access to victim networks has been observed since at least mid-January 2021, and some of the indicators the agencies published date back to 2016.
Scanning Scripts And A Spear-Phishing Kit
MicroScan is the older of the seized tools, in use since as early as 2017. The advisory describes a Python web application holding more than 1,300 penetration testing scripts, aimed at software including Apache Struts, Oracle WebLogic, Jenkins, WordPress and Juniper ScreenOS.
Prosecutors named a power company in South Carolina, airports in Japan and Poland, a multinational charity, and Taiwanese gas, electricity and university networks among the scanned targets. They stressed that scanning a target does not mean the target was breached.
FishHub, the second seized tool, arrives in a compressed file and starts a process disguised as a Windows component. It talks back to a domain the FBI attributes to Integrity Tech, and roughly 20 Taiwanese universities are confirmed victims.
SoftEther, a legitimate virtual private network client, is what the attackers installed on victim machines to keep their access. The advisory notes that security products are less likely to flag it precisely because it is a real product.
Sanctions Came First, Twice
The Treasury's sanctions office blocked the company's assets in January 2025, under an executive order on malicious cyber activity. It cited infrastructure Integrity Tech ran that was used in intrusions between summer 2022 and autumn 2023.
Britain followed in December 2025 with an asset freeze of its own. The listing states that Integrity Tech controlled and managed a botnet of over 260,000 compromised devices worldwide, meaning ordinary internet-connected machines taken over and run as one network, used to reach UK public sector systems.
The FBI confirmed the main MicroScan access domain was still online in September 2026, more than a year after the first sanctions. Troy Rivetti, the US Attorney in western Pennsylvania, described this week's action as "our second disruption of Integrity Tech's massive operations in as many years".
The first came in September 2024, when the FBI took control of the same company's botnet of more than 200,000 home routers, cameras and storage devices. The operation held while the attackers flooded the FBI's own infrastructure with traffic to knock it offline. French authorities took part, and four allied countries issued a joint advisory.
An Ecosystem Rather Than A Group
Actors enabled by Integrity Tech use methods consistent with activity publicly tracked as Flax Typhoon, Ethereal Panda and Red Juliett, the advisory says, while cautioning that they may also do work unconnected to the company. Naming a company rather than a hacking crew is the shift it represents.
Chris Butera, CISA's acting executive assistant director for cybersecurity, said Chinese government-affiliated actors "continue to position themselves within critical infrastructure networks, including operational technology systems". Their aim, he said, is "disrupting critical functions at a future time of their choosing". Some suppliers have answered that by pushing protection down to the grid edge rather than holding it at the perimeter.
No charges accompanied the seizures. The unsealed affidavit and warrant name prosecutors but no defendant, and no indictment of the company or any individual has been made public.
What The Advisory Leaves Out
Sectors and regions across Southeast Asia, Africa and North America appear in the advisory without a total, and nobody has published a victim count for the period it covers, which runs from January 2021. Ten agencies put their names to the document without agreeing a number.
The Chinese embassy in Washington did not respond to a request for comment, and the foreign ministry's briefing that day addressed a separate hacking report without mentioning the advisory. Integrity Tech itself told the Shanghai Stock Exchange, when the United States sanctioned it in January 2025, that the accusations had no factual basis.