FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8.
The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more than 1,300 scripts, guessed passwords for Microsoft 365 and Exchange accounts, and copied mailboxes using tools designed to collect mail.
The hackers have been breaking into networks since at least mid-January 2021, according to the agencies’ joint advisory. It describes the hacking in the present tense but provides no date for any theft and does not specify how many organizations were breached.
The same hackers targeted U.S. government services, critical manufacturing, healthcare, and IT organizations, along with U.S. law enforcement, education, and religious groups. Organizations in Southeast Asia, Africa, and North America were also targeted.
The hackers also run a web application that “provides third-party access to stolen email content,” the advisory said. It does not identify those third parties.
In September 2024, the FBI disrupted a botnet, a network of hijacked devices, that the U.S. Justice Department said Integrity Technology Group controlled. It held more than 200,000 routers, cameras, and other consumer devices, and Lumen researchers had named it Raptor Train.
Leave a Reply