CISA AA26-281A: How Chinese Government-Linked Actors Steal Sensitive Data
| October 09, 2026
Key Takeaways
- CISA links China-based Integrity Tech to activity tracked as Flax Typhoon, also called Ethereal Panda or Red Juliett.
- Targets include US critical infrastructure and organizations in Southeast Asia, Africa, and North America.
- Initial access combines XSS credential-harvesting pages delivering DiagTrack.exe malware with EBurst password spraying against Exchange.
- Actors install SoftEther VPN clients disguised as conhost.exe or dllhost.exe to maintain stealthy, startup-persistent remote access.
- Data theft combines Curlc4.txt and office-cli email collection with DCSync credential harvesting through DC.exe.
- The Picus Platform simulates Flax Typhoon threats to validate security controls against these attacks.
CISA published a joint cybersecurity advisory on October 8, 2026, which describes how Chinese government-linked threat actors combine automated reconnaissance with hands-on intrusion to steal sensitive data.
Integrity Technology Group, a China-based company, supports this activity by developing or acquiring tools, hosting infrastructure, and compromising networks. The reported targets include US critical infrastructure and organizations in Southeast Asia, Africa, and North America [1].
In this blog, we will explain how these threat actors operate and show how you can use Picus to validate your security controls against their attacks.
Who Is Behind the Activity
The advisory links Integrity Tech to a wider Chinese cyber ecosystem focused on stealing sensitive information. The actors supported by Integrity Tech use techniques consistent with activity tracked by cybersecurity vendors under names such as Flax Typhoon, Ethereal Panda, and Red Juliett.
The actors use large botnets, VPNs, and collections of hacking tools. They combine tools already available on victim systems and legitimate remote access software with custom tools built to collect data.
Tactics and Techniques Used by Chinese Government Linked Threat Actors
Reconnaissance
The actors use BBScan, dirsearch, Fscan, ksubdomain, masscan, Nmap, OneForAll, ShuiZe, and WPScan to identify potential targets. They focus on scanning ports 21 (FTP), 22 (SSH), 53 (DNS), 80 (HTTP), 443 (HTTPS), and 1080 (SOCKS). They also use dirsearch to enumerate PHP and ASP or .NET pages.
These tools cover different parts of reconnaissance, including finding subdomains, discovering open ports, fingerprinting applications, and finding website paths.
The following illustrative command checks the six listed TCP ports on the local machine:
|
nmap -sT -p 21,22,53,80,443,1080 127.0.0.1 |
For subdomain discovery, OneForAll can be used as shown in this illustrative command:
|
python3 oneforall.py --target victim.example run |
The actors also use MicroScan, a Python-based web application containing more than 1,300 penetration testing scripts. Its scripts target services including OpenSSL, Oracle WebLogic, WordPress, Jenkins, and Apache Struts.
Initial Access and Execution
The actors gain access to victim networks and cloud services using command-line tools built from exploit code written in Python and Go. They also use JavaScript and HTML to carry out cross-site scripting (XSS) attacks.
The XSS payload changes a vulnerable web page to display username and password fields for credential harvesting. After a user enters any username and password, the page generates a download link for a password-protected ZIP archive. The archive is built from encoded bytes inside the payload and contains live700_v1.exe.
The executable starts a process named DiagTrack.exe, which uses the same name as legitimate Windows software. The process establishes encrypted communications over HTTP with dns.studiocloud[.]xyz. The malware also contains functions for querying user mailboxes, suggesting that it is designed to steal email data.
The actors also use EBurst, an open source Python tool, to attack Microsoft Office 365 and Exchange email accounts through password spraying and password guessing. EBurst supports multiple Exchange interfaces, such as Exchange Control Panel (ECP), Exchange Web Services (EWS), Offline Address Book (OAB), and Outlook Web Access (OWA). This allows the tool to attempt authentication through different interfaces rather than relying only on the webmail login page.
Persistence
The actors install SoftEther VPN clients on victim devices to maintain remote access and hide command-and-control communications. They configure the clients to reconnect automatically at startup, allowing the connections to resume after a device restarts.
On Windows, they download the installers using PowerShell or other tools already available on the system. On Linux and Unix systems, they use curl or wget. The installers are often named conhost.exe or dllhost.exe to resemble common Windows executables.
SoftEther connects to actor-controlled servers using their domains, subdomains, or IP addresses. Because it is legitimate VPN software, its presence may be less likely to trigger endpoint alerts. The actors use these connections to maintain access and support data exfiltration.
Collection and Exfiltration
The actors download databases and manually pull data from victim email accounts. They stage email dumps under filenames such as 001.gif, All_scanner_vXX.pl.gz, Css.js, Include.png, M2k.js, M2k_list.js, and M2k_ui_adm.js to make the collected data less noticeable. In All_scanner_vXX.pl.gz, XX represents a one- or two-digit number.
They use Curlc4.txt, a PHP script, to collect email through the Microsoft EWS API. The API also provides access to other mailbox content, including calendars and contacts. The script uploads collected email to a remote server after compressing it. In some cases, it also encrypts the data using RC4 or AES-128-CBC.
The script accepts up to two command-line arguments. The first appears to set its working directory. If it is missing, the script searches for a writable directory in locations including /, /home, /var/www, /usr, and /var/tmp. The second argument is stored in a variable saved to the targeted system.
The full script is not provided, but the available PHP fragments include:
|
public $file='/var/tmp/.sess.zip'; curl_setopt($this->ch, CURLOPT_HTTPHEADER,array("X-Id: $clientid")) |
The first fragment sets a file path for a hidden ZIP archive. The second adds an X-Id header to an HTTP request using the value of $clientid.
The actors also use DC.exe to perform DCSync, a technique that retrieves sensitive Active Directory data through directory replication. The collected information includes account credentials, group memberships, and trust relationships. The tool connects to a victim's domain controller through Remote Procedure Call (RPC) and uses the Directory Replication Service to retrieve directory data.
Additionally, the actors use office-cli, a Linux command-line tool, to automate the collection and exfiltration of email from Microsoft Outlook 365 accounts across different time periods. Mailbox access is configured through JSON files stored in a config directory, using client_id, tenant_id, and secret. The tool saves collected email in subdirectories under a dump directory. The actors periodically update the accounts targeted by the tool.
How Picus Simulates Attacks by Chinese Government Linked Threat Actors
We strongly suggest simulating attacks by Chinese government-linked threat actors to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other threat groups within minutes with a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for Chinese government-linked threat actors: :
|
Threat ID |
Threat Name |
Attack Module |
|
35793 |
Flax Typhoon Threat Group Campaign Malware Download Threat |
Network Infiltration |
|
59630 |
Flax Typhoon Threat Group Campaign Malware Email Threat |
E-mail Infiltration |
|
34712 |
JuicyPotato Hacktool Download Threat |
Network Infiltration |
|
72570 |
JuicyPotato Hacktool Email Threat |
E-mail Infiltration |
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.
References
[1] Cybersecurity and Infrastructure Security Agency (CISA), “Chinese government-linked cyber threat actors combine automated and hands-on hacking tools to steal sensitive data,” Cybersecurity Advisory AA26-281A, Oct. 8, 2026. Accessed: Oct. 9, 2026. [Online]. Available: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
