As reported by The Hacker News, the FBI and six partner agencies disclosed on October 8 that hackers tied to Integrity Technology Group—a China-based company with confirmed links to the Chinese government—systematically exfiltrated email from government, law enforcement, healthcare, and religious organizations across Southeast Asia, Africa, and North America. What elevates this advisory beyond routine APT attribution is a detail buried in the text: the actors operated a web application that provided third-party access to stolen email content.
This is a significant operational development worth examining closely. Traditional state-linked espionage campaigns hoard stolen intelligence internally. The creation of a distribution portal implies either a commercial monetization layer—selling access to exfiltrated mailboxes to buyers whose identities remain unknown—or a structured information-sharing mechanism with affiliated actors. Either interpretation fundamentally changes how defenders must think about downstream risk: a single intrusion may produce multiple consumers of the stolen data, each with different objectives and timelines.
The Tradecraft Profile
The advisory describes a methodology that is technically unsophisticated but operationally persistent. The actors used a custom scanning tool with over 1,300 scripts to identify web vulnerabilities, performed password-guessing attacks against Microsoft 365 and Exchange accounts, and deployed purpose-built mail collection utilities. Active since at least January 2021, this is not a zero-day campaign—it is opportunistic exploitation of weak credentials and unpatched web applications, sustained over years.
This persistence model is the real threat. The actors do not need elite capability when defenders leave credential hygiene and web application patching incomplete. The same group previously controlled the Raptor Train botnet—over 200,000 compromised consumer devices—disrupted by the FBI in September 2024. The new advisory makes clear that the botnet takedown addressed only one limb of the operation.
Who Bears the Greatest Risk
The targeting pattern reveals deliberate selection of organizations holding sensitive but poorly defended communications:
Organizations running on-premises Exchange without MFA, or with externally exposed web applications lacking current patching, represent the highest-exposure configuration.
Shield53 Recommendations
Immediate Actions
- Enforce MFA on all email accounts — particularly Microsoft 365 and on-premises Exchange. Password-guessing success indicates weak or absent second-factor authentication. Prioritize accounts with administrative privileges and those handling sensitive communications.
- Audit Exchange and M365 mailbox access — review sign-in logs for anomalous OAuth grants, unfamiliar IP geographies, and bulk mail export patterns. The mail collection tools described suggest structured exfiltration that may produce detectable anomalies in audit logs.
- Conduct external attack surface mapping — identify internet-facing web applications and validate patch status against known vulnerabilities. A scanning tool with 1,300+ scripts will find what you leave exposed.
- Hunt for mailbox collection tooling — deploy detection rules for unusual Exchange Web Services (EWS) API usage, abnormal MailItemsAccessed events in Microsoft Purview, and scheduled task-based mail export utilities.
Strategic Actions
- Assume compromise of sensitive communications — if your organization falls within the targeted sectors and runs exposed Exchange or lacks MFA, treat historical email as potentially compromised. Evaluate what sensitive information may require notification or remediation workflows.
- Reduce email as a sensitive data repository — move high-value communications to encrypted, access-controlled platforms with stronger authentication and logging. Email remains the soft underbelly of organizational security.
- Monitor for the third-party distribution model — if stolen email is being shared via a portal, downstream consumers may attempt to leverage that content in phishing, influence operations, or additional intrusions. Watch for precision-targeted social engineering that references information only obtainable from your mail systems.
The most troubling aspect of this advisory is not the capability—it is the sustainability. A for-profit company with state links, operating a distribution portal for stolen email, across multiple continents, for over four years. The FBI's botnet disruption was necessary but insufficient. Until credential hygiene and web application hardening become non-negotiable across the targeted sectors, this operating model will persist.
Defenders should treat this advisory as a confirmation that their email environment is a primary intelligence target, not a secondary concern. The gap between 'we know this matters' and 'we have actually hardened our mail infrastructure' remains the single largest exposure in the sectors this campaign is designed to exploit.