The US, UK and several allied countries have issued a joint alert detailing the tactics, techniques and procedures (TTPs) associated with a sanctioned Chinese organization.
The work of Integrity Technology Group has in the past enabled prolific Beijing-backed groups such as Flax Typhoon (aka Ethereal Panda, Red Juliett) according to the advisory, published on October 8.
“Integrity Tech employs individuals who support malicious cyber activity in different ways, including acquiring or building cyber tools for use and sale, acquiring and hosting infrastructure and compromising networks across global victims, which the authoring organizations track as China-based malicious cyber activity,” it continued.
“The services provided by Integrity Tech also contribute to the larger Chinese cyber ecosystem, which aims to exfiltrate sensitive data from victims around the world.”
The report highlighted various technical details associated with Integrity Tech TTPs including:
- The use of open source scanning tools to find vulnerabilities in networks and web-based applications
- The use of the “MicroScan” hacking tool which contains over 1300 pen-testing scripts designed to scan sites for specific flaws
- Initial access to networks and cloud services via command line utilities built on exploit codes written in Python and Go
- Exploitation of cross-site scripting (XSS) bugs to compromise third-party apps
- Use of the EBurst tool for password spraying/guessing to compromise Microsoft 365 email accounts
- Persistence by installing VPN clients (eg SoftEther) on victim devices to obfuscate command and control (C2) comms
- Staging exfiltration data with different file names to minimize detection of the MySQL email dump
- Creation of a bot using the PHP script Curlc4.txt to obtain emails from victims
- Use of DC.exe to trick a domain controller into handing over sensitive Active Directory information, including account credentials
- Exfiltration of email data from on-premises systems and cloud-based services, with targeted verticals including government, law enforcement, healthcare and religious institutions located in Southeast Asia
- Use of command-line utility office-cli to continuously access Microsoft Outlook 365 accounts and steal emails
Next Steps for Network Defenders
The report lists a large number of indicators of compromise (IoCs), additional resources and mitigations, as well as advice for incident responders that think they may already have been compromised.
However, its main advice for mitigating the threat from Integrity Tech can be distilled into the following:
- Disable unused services and ports, including automatic configuration, remote access and file sharing protocols
- Sanitize user input in web applications to prevent possible XSS payload injection
- Implement identity, credential and access management (ICAM) policies, and then require multifactor authentication (MFA) where possible
NCSC director of operations, Paul Chichester, said the extent of Integrity Tech’s activities should be concerning for all security teams.
“The breadth of sectors that have been targeted across the globe demonstrate the extent of the threat and all organizations should take note of this warning and engage with NCSC advice and guidance,” he added.
“We will continue to call out malicious actors and the malevolent ecosystem they operate in.”
Also on October 8, the US announced the seizure of several domains associated with hacking tools Microscan and FishHub, in a bid to disrupt the operations of Integrity Tech and associated threat groups.
