Back to Intelligence

CISA AA26-281a: Chinese State-Linked Actors Blending Automated Scanning and Hands-On Intrusion to Hit Exchange and Exfiltrate Email — Detection and Defense Guide

SA
Security Arsenal Team
October 8, 2026
12 min read

On October 8, 2026, CISA — together with partner agencies — published AA26-281a, a joint advisory detailing how Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning infrastructure, a large-scale network of compromised devices, and hands-on-keyboard intrusion techniques to target and steal sensitive data from organizations worldwide, including US critical infrastructure sectors.

This is not a theoretical campaign. The advisory describes a mature, repeatable intrusion cycle: automated vulnerability scanning at scale, initial access via cross-site scripting (XSS) and password spraying against Microsoft Exchange servers, persistence established through VPN software, and bulk exfiltration of emails and credentials using scripts. If your organization runs internet-facing Exchange, operates VPN concentrators, or sits in a critical infrastructure vertical, treat this as a priority-one threat-hunting trigger.

Notably, the advisory does not center on a single CVE — it describes a technique-driven campaign that chains commodity exploitation methods rather than relying on one exotic zero-day. That makes behavioral detection, not just patch management, your primary line of defense.


Technical Analysis

Threat Actor and Enabling Infrastructure

The advisory attributes enablement to the Integrity Technology Group, a company linked to Chinese state-directed cyber operations. The operational model blends two tiers:

  1. Automated tier — large-scale scanning tooling plus a compromised device network (botnet-style proxy infrastructure) used to anonymize scanning, brute force, and exploitation traffic. This gives the actors a constantly rotating source IP pool, making IP-based blocklists largely ineffective on their own.
  2. Hands-on tier — once automated tooling identifies a foothold, human operators take over for credential harvesting, persistence, lateral movement, and staged exfiltration.

Attack Chain (Defender's View)

StageTechniqueObservable Surface
ReconnaissanceAutomated vulnerability scanning from rotating proxy IPsWeb server/IIS logs, WAF, perimeter IDS
Initial AccessPassword spraying against Exchange (OWA/EWS/Autodiscover); XSS against web-facing appsEvent ID 4625/4624 on Exchange, IIS logs, application logs
PersistenceAbuse of legitimate VPN software; access tokens/credentials harvested post-compromiseVPN auth logs, new service/process installs, account logon anomalies
CollectionScripts enumerating mailboxes, harvesting credentials, exporting emailPowerShell activity, Exchange Management Shell, staging archives
ExfiltrationScripted transfer of email and credential data through the compromised device networkEgress volume anomalies, proxy/VPN egress, DNS

Affected Products and Platforms

  • Microsoft Exchange Server — internet-facing OWA, EWS, and Autodiscover endpoints are the named password-spraying and credential-theft target. Unpatched, internet-exposed Exchange remains the highest-risk asset class.
  • VPN appliances and clients — the actors establish persistence through VPN software, meaning any remote access gateway (and any endpoint where rogue VPN clients can be installed) is in scope.
  • Web applications vulnerable to XSS — used as an initial access vector and likely for session/credential theft.

Exploitation Status

This is confirmed, active, in-the-wild exploitation against organizations worldwide, explicitly including US critical infrastructure. The advisory's core warning is that the combination — automated breadth plus human depth — lets these actors scale victimization far beyond what either tier could achieve alone.


Detection & Response

The detections below target the behaviors named in the advisory: password spraying against Exchange, scripted mailbox/email collection, and rogue VPN persistence. They are tuned to be hunt-grade, not alert-and-ignore grade — baseline your environment before promoting to high-severity alerting.

Sigma Rules

YAML
---
title: Exchange Mailbox Export or Email Collection via Script
id: 4f2a9c31-7b6e-4d58-a1c2-9e8f0d3b5a71
status: experimental
description: Detects scripted email collection on Exchange servers consistent with AA26-281a exfiltration TTPs, including Exchange Management Shell mailbox export cmdlets and direct access to mailbox data stores.
references:
  - https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
  - https://attack.mitre.org/techniques/T1114/
author: Security Arsenal
date: 2026/10/09
tags:
  - attack.collection
  - attack.t1114.002
logsource:
  category: process_creation
  product: windows
detection:
  selection_cmdlet:
    CommandLine|contains:
      - 'New-MailboxExportRequest'
      - 'Export-Mailbox'
      - 'Get-MailboxExportRequest'
      - 'Search-Mailbox'
  selection_shell:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\cmd.exe'
  selection_paths:
    CommandLine|contains:
      - '\\*.pst'
      - 'Program Files\\Microsoft\\Exchange Server'
  condition: selection_cmdlet or (selection_shell and selection_paths)
falsepositives:
  - Legitimate eDiscovery or compliance export by Exchange administrators
  - Backup solutions performing mailbox-level export
level: high
---
title: Password Spraying Pattern Against Exchange Authentication
id: 8c1d5e72-3a4f-4b89-b2d7-6f9a1c4e8d03
status: experimental
description: Detects password spraying behavior against Exchange (OWA/EWS/Autodiscover) characterized by many failed logons across distinct accounts from a single source, consistent with AA26-281a initial access TTPs. Deploy as a threshold-based correlation in your SIEM; this rule defines the atomic failure event.
references:
  - https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
  - https://attack.mitre.org/techniques/T1110/003/
author: Security Arsenal
date: 2026/10/09
tags:
  - attack.credential_access
  - attack.t1110.003
logsource:
  product: windows
  service: security
detection:
  selection:
    LogonType: 3
    LogonProcessName:
      - 'Advapi'
      - 'NtLmSsp'
    FailureReason|contains: '%%2313'
  filter_known:
    IpAddress:
      - '127.0.0.1'
      - '::1'
  condition: selection and not filter_known
falsepositives:
  - Misconfigured service accounts with stale credentials
  - Mobile devices retrying expired passwords via EWS/ActiveSync
level: medium
---
title: Rogue VPN Client Installation or Execution for Persistence
id: 2e7b4f19-5c83-4a96-d3e1-8a6f2b9c7e54
status: experimental
description: Detects installation or execution of VPN client software on servers where VPN clients are not expected (Exchange, domain controllers, application servers), consistent with AA26-281a persistence via VPN software.
references:
  - https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
  - https://attack.mitre.org/techniques/T1133/
author: Security Arsenal
date: 2026/10/09
tags:
  - attack.persistence
  - attack.t1133
  - attack.t1078
logsource:
  category: process_creation
  product: windows
detection:
  selection_vpn:
    Image|contains:
      - '\openvpn'
      - '\wireguard'
      - '\tailscale'
      - '\zerotier'
      - '\softether'
      - '\anyconnect'
      - '\GlobalProtect'
      - '\forticlient'
  selection_server:
    Computer|contains:
      - 'EXCH'
      - '-DC-'
      - 'SRV'
  condition: selection_vpn and selection_server
falsepositives:
  - Approved remote access tooling deployed by IT; maintain an allowlist of sanctioned VPN binaries and server naming conventions
level: high

Note on the rogue VPN rule: the Computer filter assumes naming conventions that flag servers. Replace with your actual server OU/naming pattern or pivot to an asset-tag lookup in your SIEM. Without that scoping this rule will be noisy on endpoints, where VPN clients are often legitimate.

KQL — Microsoft Sentinel / Defender

The following query hunts the two highest-signal behaviors from the advisory together: a password-spray burst against Exchange followed by a successful logon from the same source (spray success), plus scripted mailbox export activity on Exchange servers.

KQL — Microsoft Sentinel / Defender
// Hunt 1: Password spraying against Exchange followed by successful authentication
let sprayWindow = 1h;
let failThreshold = 20;
let FailedSpray = SecurityEvent
| where EventID == 4625
| where LogonType == 3
| where IpAddress !in ("127.0.0.1", "::1", "-")
| summarize FailedAccounts = dcount(Account), FailedAttempts = count(),
            Accounts = make_set(Account, 50) by IpAddress, bin(TimeGenerated, sprayWindow)
| where FailedAccounts >= failThreshold
| project SprayTime = TimeGenerated, IpAddress, FailedAccounts, FailedAttempts;
let SuccessfulLogons = SecurityEvent
| where EventID == 4624
| where LogonType in (3, 8, 10)
| project SuccessTime = TimeGenerated, IpAddress, Account, Computer;
FailedSpray
| join kind=inner SuccessfulLogons on IpAddress
| where SuccessTime between (SprayTime .. SprayTime + 4h)
| project SprayTime, SuccessTime, IpAddress, Account, Computer, FailedAccounts, FailedAttempts
| sort by SprayTime desc;

// Hunt 2: Scripted mailbox export / email collection on Exchange servers
DeviceProcessEvents
| where DeviceName has_any ("EXCH", "EX-")  // tune to your Exchange naming convention
| where ProcessCommandLine has_any (
    "New-MailboxExportRequest", "Export-Mailbox", "Search-Mailbox",
    "Get-MailboxExportRequest", ".pst")
| project TimeGenerated, DeviceName, AccountName, FileName,
          ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessAccountName
| sort by TimeGenerated desc;

// Hunt 3: Unexpected VPN/tunneling client execution on servers
DeviceProcessEvents
| where DeviceName has_any ("EXCH", "SRV", "DC")  // tune to your server naming convention
| where FileName has_any ("openvpn", "wireguard", "tailscale", "zerotier",
    "softether", "vpnagent", "forticlient", "panGP", "anyconnect")
   or ProcessCommandLine has_any ("--config", "tun0", "wireguard", "openvpn")
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine,
          AccountName, SHA256, InitiatingProcessFileName
| sort by TimeGenerated desc;

Velociraptor VQL

Use this artifact for rapid triage of a suspected-compromised Exchange server: it surfaces scripted email collection processes, recent staging archives, and unexpected tunneling clients in one sweep.

VQL — Velociraptor
-- Hunt for AA26-281a TTPs: scripted email collection, PST staging, rogue VPN clients
LET procs = SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(New-MailboxExportRequest|Export-Mailbox|Search-Mailbox|\.pst|openvpn|wireguard|tailscale|zerotier|softether)'
   OR Name =~ '(?i)(openvpn|wireguard|tailscaled|zerotier|vpnagent)'

LET staged_pst = SELECT FullPath, Size, Mtime, Atime
FROM glob(globs=['C:/Users/*/*.pst', 'C:/ProgramData/**/*.pst',
                 'C:/Windows/Temp/**/*.pst', 'C:/Temp/**/*.zip',
                 'C:/Windows/Temp/*.7z', 'C:/Windows/Temp/*.rar'])
WHERE Mtime > now() - 1209600  -- artifacts created in the last 14 days

SELECT 'Process' AS ArtifactType, Name AS Item, CommandLine AS Detail,
       Username AS Context, CreateTime AS Timestamp
FROM procs
UNION ALL
SELECT 'StagedFile' AS ArtifactType, FullPath AS Item,
       format(format='Size: %d bytes', args=[Size]) AS Detail,
       '' AS Context, Mtime AS Timestamp
FROM staged_pst
ORDER BY Timestamp DESC

Remediation / Hardening Script

This PowerShell script (run elevated on each Exchange server, with Exchange Management Shell loaded) audits for the advisory's observable artifacts: unauthorized mailbox export requests, suspicious recent logon tooling, unauthorized VPN software, and staging files. It is read-only audit plus targeted hardening — review output before removing anything.

PowerShell
#Requires -RunAsAdministrator
# AA26-281a Exchange Server Audit & Hardening - Security Arsenal
# Run inside Exchange Management Shell on each Exchange server

$report = @()
$reportDir = "C:\SecurityAudit_$(Get-Date -Format 'yyyyMMdd_HHmm')"
New-Item -Path $reportDir -ItemType Directory -Force | Out-Null

# 1. Audit active and recent mailbox export requests (exfiltration indicator)
Write-Host "[*] Auditing mailbox export requests..." -ForegroundColor Cyan
try {
    $exports = Get-MailboxExportRequest | Get-MailboxExportRequestStatistics
    $exports | Export-Csv "$reportDir\MailboxExportRequests.csv" -NoTypeInformation
    if ($exports) {
        Write-Host "[!] ALERT: $($exports.Count) mailbox export request(s) found. Review $reportDir\MailboxExportRequests.csv for unauthorized exports." -ForegroundColor Red
    } else {
        Write-Host "[+] No mailbox export requests found." -ForegroundColor Green
    }
} catch { Write-Host "[-] Export request audit skipped: $($_.Exception.Message)" -ForegroundColor Yellow }

# 2. Search for PST staging files in common exfiltration locations
Write-Host "[*] Scanning for staged PST/archive files..." -ForegroundColor Cyan
$stagingPaths = @('C:\Users','C:\ProgramData','C:\Windows\Temp','C:\Temp')
$staged = Get-ChildItem -Path $stagingPaths -Recurse -Include *.pst,*.7z,*.rar -ErrorAction SilentlyContinue |
          Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-30) } |
          Select-Object FullName, Length, LastWriteTime
$staged | Export-Csv "$reportDir\StagedFiles.csv" -NoTypeInformation
if ($staged) { Write-Host "[!] ALERT: Potential staged exfiltration files found. Review $reportDir\StagedFiles.csv" -ForegroundColor Red }

# 3. Detect unauthorized VPN/tunneling software (persistence indicator)
Write-Host "[*] Checking for VPN/tunneling software..." -ForegroundColor Cyan
$vpnPatterns = 'openvpn|wireguard|tailscale|zerotier|softether|forticlient|anyconnect|GlobalProtect'
$rogueVpn = Get-ItemProperty HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*,
                               HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* -ErrorAction SilentlyContinue |
            Where-Object { $_.DisplayName -match $vpnPatterns } |
            Select-Object DisplayName, DisplayVersion, Publisher, InstallDate
$rogueVpn | Export-Csv "$reportDir\VpnSoftware.csv" -NoTypeInformation
if ($rogueVpn) { Write-Host "[!] ALERT: VPN software detected on a server. Validate against your approved software list." -ForegroundColor Red }

# 4. Review local admin group membership for unauthorized additions
Write-Host "[*] Enumerating local administrators..." -ForegroundColor Cyan
Get-LocalGroupMember -Group 'Administrators' -ErrorAction SilentlyContinue |
    Select-Object Name, ObjectClass, PrincipalSource |
    Export-Csv "$reportDir\LocalAdmins.csv" -NoTypeInformation
Write-Host "[+] Local admin membership exported to $reportDir\LocalAdmins.csv - review for unauthorized accounts." -ForegroundColor Green

# 5. Hardening: confirm legacy auth posture and audit log verbosity
Write-Host "[*] Checking PowerShell Script Block Logging (required for exfil detection)..." -ForegroundColor Cyan
$sbl = Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -ErrorAction SilentlyContinue
if (-not $sbl -or $sbl.EnableScriptBlockLogging -ne 1) {
    New-Item -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -Force | Out-Null
    Set-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -Name 'EnableScriptBlockLogging' -Value 1
    Write-Host "[+] Script Block Logging enabled." -ForegroundColor Green
} else { Write-Host "[+] Script Block Logging already enabled." -ForegroundColor Green }

Write-Host "`n[*] Audit complete. Report directory: $reportDir" -ForegroundColor Cyan
Write-Host "[!] NEXT STEPS: Reset credentials for any account involved in spray success; enforce MFA on all OWA/EWS access; block legacy authentication at the IdP." -ForegroundColor Yellow

Remediation and Hardening Priorities

There is no single patch for this campaign — it is technique-driven — so remediation is a layered hardening effort. Prioritize in this order:

  1. Exchange exposure (highest priority).

    • Inventory every internet-facing Exchange endpoint (OWA, EWS, Autodiscover, ECP). Remove ECP from the internet entirely; restrict OWA/EWS behind a VPN or conditional access where operationally feasible.
    • Ensure Exchange is on the latest supported Cumulative Update and Security Update. Internet-facing Exchange that is behind on SUs is precisely the target class described in the advisory.
    • Deploy the Exchange Emergency Mitigation (EM) service and the Exchange Health Checker script to validate patch and configuration posture.
    • Block legacy authentication (basic auth for EWS/ActiveSync/IMAP/POP) at the identity provider and on the server — password spraying against Exchange overwhelmingly succeeds through legacy auth paths that bypass MFA.
  2. Identity controls against password spraying.

    • Enforce phishing-resistant MFA for all remote access, prioritizing Exchange and VPN.
    • Implement smart lockout / account lockout thresholds with alerting on distributed failures (spraying uses one password across many accounts to evade per-account lockout — detect on distinct-account failure counts per source, not per-account counts).
    • Reset credentials for any account that shows spray success in the KQL hunt above, and audit those mailboxes for forwarding rules and delegate access added post-compromise.
  3. VPN persistence.

    • Inventory all VPN software organization-wide; maintain an allowlist. Any VPN client found on a server should be treated as suspicious until proven otherwise.
    • Audit VPN concentrator configurations, accounts, and session history for unauthorized access. Rotate credentials and certificates on any appliance that may have been touched.
    • Restrict outbound traffic from Exchange servers — they have almost no legitimate need to initiate arbitrary outbound connections, and egress filtering directly disrupts scripted exfiltration.
  4. XSS and web application exposure.

    • Scan and remediate XSS in internet-facing applications; deploy or tune WAF rules. XSS in this campaign is an initial access and credential/session theft vector, not a cosmetic finding.
  5. Monitoring and egress.

    • Ensure Script Block Logging, Module Logging, and IIS logs from Exchange are centrally collected — the detection content above depends on it.
    • Alert on anomalous egress volume from Exchange and VPN infrastructure, and on connections to low-reputation or rapidly rotating IPs consistent with compromised-device proxy networks.
  6. Reference the authoritative guidance. Read and action the full joint advisory: CISA AA26-281a — Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data. If you operate critical infrastructure, engage CISA's regional team and consider enrolling in CISA's free vulnerability scanning service.


Executive Takeaways

  • This is hybrid tradecraft, not a single bug. Automated scanning finds the door; human operators walk through it. Purely signature- or patch-based defense will miss half the kill chain.
  • Exchange + VPN = the crown jewels in this campaign. Email is both the target (data theft) and the pivot (credentials). Harden internet-facing Exchange and validate every piece of VPN software in your estate.
  • Rotating proxy infrastructure defeats blocklists. Detect the behavior (spray patterns, mailbox export cmdlets, rogue tunnels), not the source IP.
  • Assume a spray success means mailbox compromise. Hunt for forwarding rules, delegate grants, and export requests — not just the initial logon.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.