China-Linked Hackers Operated Portal Exposing Stolen Emails from Southeast Asia & Beyond

Federal agencies revealed that a China-based cybersecurity company has been at the center of an extensive hacking campaign targeting government, healthcare, law enforcement, religious institutions, and critical infrastructure, siphoning off email content and making it accessible to third parties via a specialized web portal. This company, operating under the name Integrity Technology Group, is sanctioned by both the U.S. and the UK as of early 2025 for breaking into networks and facilitating theft of sensitive mailboxes. thedailytechfeed.com has reviewed the advisory issued October 8, 2026.

How the Breaches Worked

Attackers tied to Integrity Technology Group have been active since at least mid-January 2021. They exploited over 1,300 scripts bundled into a scanning tool called MicroScan, along with publicly available utilities such as Nmap, masscan, and WPScan, to search for vulnerabilities. Ports commonly found on servers—21, 22, 53, 80, 443, and 1080—were scanned and infiltrated via known software flaws. Targets included implementations of OpenSSL, Apache Struts, Oracle WebLogic, and WordPress, among others. These included vulnerabilities recently added to the U.S. CISA’s Known Exploited Vulnerabilities (KEV) list. thedailytechfeed.com notes that the hackers also leveraged weaknesses in tools like ISC BIND, ProFTPD, GitLab, Strapi, and ONLYOFFICE. thedailytechfeed.com

Data Theft and Access Channels

Once inside, the hackers used a mix of methods to gather credentials and extract email content. A legitimate VPN tool, SoftEther, was deployed under misleading names to avoid detection. They also used DCSync to replicate domain controllers in Active Directory, harvesting account relationships and group permissions. For email exfiltration, they developed a PHP bot (“Curlc4.txt”) that interacted with Exchange Web Services to capture emails, calendars, and contacts. Another tool, dubbed office-cli, queried Microsoft 365 accounts across time periods via service principals using legitimate APIs, making detection more difficult. Some email searches were apparently restricted to IP addresses in Xiamen, China. thedailytechfeed.com

Third-Party Access and Broader Reach

The campaign employed a web application offering third parties access to stolen email content of specific account holders. This access was controlled via URL-based arguments. While identities of those third parties haven’t been disclosed, the portal’s existence creates a notable amplification of the threat, making it easier for outside actors to exploit stolen data. thedailytechfeed.com

Known Actors and Connections

Integrity Technology Group is described as a for-profit, China-based entity whose operations align closely with government intelligence goals. Sanctioned by the U.S. Treasury in January 2025 and by the UK in December of that year, it has been publicly accused by key intelligence officials of conducting reconnaissance and gathering intelligence on behalf of Chinese state security services. The hacking activity has been linked to well-known threat clusters such as Flax Typhoon, Ethereal Panda, and RedJuliett, although the advisory cautions those names may not map exactly to the group’s activities. thedailytechfeed.com

Mitigation and Recommended Defenses

Security agencies urge organizations to act swiftly to minimize exposure. Key recommendations include: turning off unused ports and services; enforcing multifactor authentication, especially for webmail and critical access points; sanitizing web inputs to block cross-site scripting; monitoring Active Directory replication for signs of DCSync; reviewing cloud-connected applications with access to email or files; regularly applying patches for known vulnerabilities; replacing unsupported products; and auditing web application logs for suspicious activity. For those already compromised, isolation, in-depth investigation, removal of malicious access, and hardening the environment are imperative. thedailytechfeed.com

The advisory provides a 39-page list of indicators of compromise (IOCs) that trace back to as early as 2016, including domains, IPs, and file hashes. Organizations globally—across Southeast Asia, Africa, North America, and beyond—are encouraged to cross-check this list against their environments. thedailytechfeed.com

Analysis: This operation illustrates the growing sophistication of state-aligned cyber mercenaries. By combining mass automated scanning, misuse of known vulnerabilities, and tools that mimic legitimate behavior, Integrity Technology Group has made detection harder and damage broader. The third-party portal in particular shows a move toward commodifying stolen data, allowing others to exploit breaches without needing direct access. Organizations must treat every scan, misconfigured service, or plausible API permission as a potential risk. What to watch: how U.S. and allied governments enforce the sanctions already in place, whether new cyber norms are adopted to restrict such tools, and whether companies accelerate fixes for vulnerabilities before they’re exploited on this scale.