Ten governments name a Shanghai contractor as the engine behind China's data-theft campaigns

A joint advisory led by CISA and the FBI pins years of intrusions on Integrity Technology Group and lists eight old, unpatched flaws the operators keep riding into critical infrastructure.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 4 min read
Illustration: a dim server room aisle in a government data centre
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Ten government agencies, led by the FBI and CISA, on October 8, 2026 named Shanghai-based Integrity Technology Group as the enabler behind intrusions tied to the activity clusters Flax Typhoon, Ethereal Panda and Red Juliett.
  • The hackers are still breaking in through eight listed flaws, the oldest being CVE-2014-6278, a Bash command-injection bug from 2014 that CISA only added to its must-patch list on October 2, 2025.
  • Targeted sectors include US government services, critical manufacturing, healthcare and information technology, plus victims across Southeast Asia, Africa and North America, along with law enforcement, education and religious organisations.
  • Threat Vectr's review of the published indicators counts more than 20 attacker-controlled domains, many hosted on the SoftEther VPN service, used for command-and-control.
  • The advisory ties the operators to Flax Typhoon, a cluster the US Treasury sanctioned Integrity Tech over in January 2024.

A private company in Shanghai has been doing the legwork for Chinese state hacking. Ten national cyber agencies have now put their names to a document that says exactly that.

The joint advisory, AA26-281A, was published on October 8, 2026 by CISA, the FBI, the NSA, Britain's NCSC, Australia's ACSC, Canada's Cyber Centre, Japan's NPA and NCO, New Zealand's NCSC and Spain's CNI. It names Integrity Technology Group, a for-profit Chinese firm, as the outfit acquiring tools, renting infrastructure and breaking into networks on behalf of operators the private sector tracks as Flax Typhoon, Ethereal Panda and Red Juliett.

None of this is new in spirit. The US Treasury sanctioned Integrity Tech in January 2024 over the Flax Typhoon botnet. We first reported on Flax Typhoon on 2 September 2026, and that earlier story on a related FBI warning from 23 September noted how persistently these actors target industrial networks. What's new here is the length of the shared bug list and how old most of it is.

Which bugs are they still using?

Eight CVEs, and most of them should've been dead years ago. The advisory lists flaws in Bash, ProFTPD, BIND, Apache Struts, Pulse Secure, GitLab, Pulse Policy Secure and Zimbra. Three sit on CISA's Known Exploited Vulnerabilities catalogue, meaning US federal agencies were ordered to patch them.

CVE Product CVSS Federal patch deadline
CVE-2014-6278 GNU Bash 8.8 2025-10-23
CVE-2015-3306 ProFTPD 1.3.5 10.0 not listed
CVE-2015-5477 ISC BIND 9.x 7.8 not listed
CVE-2019-11510 Ivanti Pulse Connect Secure 10.0 2022-05-03
CVE-2021-22205 GitLab CE/EE 10.0 2021-11-17

The Bash entry is the one that should sting. CVE-2014-6278 is a leftover from the original Shellshock mess of 2014, a flaw that lets a remote attacker run commands on a server by stuffing a booby-trapped value into an environment variable. CISA only added it to the must-patch list on October 2, 2025, with a federal fix-by date of October 23, 2025. Eleven years late isn't a typo.

CVE-2019-11510, a file-read bug in Pulse Connect Secure VPN appliances, is the vulnerability that gave Chinese and Russian operators access to US networks through 2020 and 2021. The attackers are still finding boxes that were never patched.

How do they actually get in?

Scan, spray, log in, stay. The advisory describes a shop that leans heavily on open-source scanners pulled from GitHub to find exposed services on ports 21, 22 and 53, then throws password-spraying attacks, guessing one common password across many accounts, at Microsoft Exchange webmail, and chains cross-site scripting flaws into web apps.

Once inside, they install commercial VPN software to keep a quiet way back in and use scripts to copy out emails and credentials. The report calls it "living off the land": the attackers use admin tools already present on the victim's machines, so antivirus has nothing obvious to flag.

What should defenders do this week?

Start with the KEV list, not the advisory's PDF. The three KEV-tagged bugs above carry hard evidence of active abuse. Patch them, or confirm the affected product is retired. Pulse Connect Secure in particular shouldn't still be reachable from the public internet in 2026.

Threat Vectr pulled the published indicator feed and counted more than 20 attacker domains, concentrated on SoftEther VPN hosting and throwaway TLDs like .ml, .tk, .ga and .cf. Block them at the resolver, then hunt backwards through DNS logs.

Turn on multifactor authentication on every external service that supports it, especially Exchange and VPN portals. Password spraying stops working the moment a second factor is in the way.

The tradecraft here is dull by design. What matters is the attribution. Nine allies standing behind an FBI corporate naming, with the sanctions file already open, is the signal Beijing will actually read.

© 2026 Threat Vectr