Threats · 4h ago
The US, UK and allies on October 8 issued a joint advisory describing Integrity Technology Group as a sanctioned China-based provider of cyber tools, infrastructure, and compromise services, while related domains including Microscan and FishHub were seized. The advisory says those services have supported Beijing-backed activity, including Flax Typhoon.
The report ties Integrity Tech to scanning networks and web apps, exploiting third-party apps and cloud services, password-spraying Microsoft 365 accounts, and installing VPN clients on victim devices so command traffic looks like ordinary remote access. In plain terms, the operator can hide behind legitimate-looking infrastructure and reuse the same access path across different victims and campaigns.
That framing matters because it shifts the threat from a single crew to a services layer: if the tooling and hosting can be rented, built, or moved, knocking out one domain does not remove the capability. For organizations that rely on Microsoft 365, cloud apps, or exposed web applications, the exposure is the ecosystem around the intrusion, not just one named actor.
1 source covering this story
UK Allies Warn of Cyber Threat from China’s Integrity Technology Group
The UK, US and allies have issued an alert detailing malicious activity associated with China’s Integrity Technology Group
Part of the PlainSec briefing for 2026-10-09