Hackers tied to Integrity Technology Group used scanners, password spraying, and multiple exploits to break into networks and steal email from government, healthcare, law enforcement, and religious organizations across Southeast Asia and beyond. The advisory says they also used tools like SoftEther, DCSync, and custom mail theft bots to maintain access and extract data, while the FBI previously disrupted their Raptor Train botnet. #IntegrityTechnologyGroup #RaptorTrain #FlaxTyphoon #Microsoft365 #Exchange
Keypoints
- Integrity Technology Group-linked hackers targeted organizations in Southeast Asia, Africa, North America, and the U.S.
- They used Nmap, masscan, WPScan, and MicroScan to find vulnerable systems.
- They exploited multiple flaws, including issues in Apache Struts, GitLab, and Strapi.
- They stole mail from Microsoft 365 and Exchange using password spraying and custom tools.
- The FBI previously disrupted their Raptor Train botnet and now urges defenders to patch, enable MFA, and hunt for intrusion signs.
Read More: https://thehackernews.com/2026/10/fbi-says-china-linked-hackers-ran.html