On October 8, 2026, the FBI — alongside partner agencies from six other countries — publicly attributed a sustained email theft campaign to hackers operating under the umbrella of Integrity Technology Group, a Chinese cybersecurity company already sanctioned by both the United States and the United Kingdom. The operation targeted government organizations, law enforcement agencies, healthcare systems, and religious institutions across Southeast Asia, exfiltrating email at scale.
What elevates this from a conventional espionage intrusion to a systemic risk is the monetization model: the operators ran a portal granting third parties access to the stolen emails. This isn't intelligence collection for a single customer — it's a commercialized breach-as-a-service operation. If your organization was compromised, your data wasn't just read once; it was potentially browsed, searched, and purchased repeatedly by unknown parties.
For defenders — particularly those in healthcare, government, and legal sectors where email archives contain regulated, privileged, and sensitive communications — this campaign demands three immediate actions: hunt for the reconnaissance and exploitation patterns described in the joint advisory, audit mail server and web-facing infrastructure for signs of compromise, and assume that any historical breach of email infrastructure may now have a downstream exposure problem that extends well beyond the initial intrusion.
Technical Analysis
Threat Actor and Attribution
Integrity Technology Group is a Chinese cybersecurity firm that has been formally sanctioned by both the U.S. and UK governments. The joint advisory from the FBI and six partner nations connects the company to a hacking operation that conducted large-scale email theft against Southeast Asian targets. The victimology — government, law enforcement, healthcare, religious institutions — is consistent with intelligence-collection priorities, but the addition of a third-party access portal introduces a criminal monetization layer that blurs the line between state-directed espionage and for-profit intrusion operations.
This dual-use model matters for defenders tactically: it means the operators had both the persistence and discipline of an APT and the volume-driven incentives of a criminal enterprise. Expect broad scanning, opportunistic exploitation of known web-facing flaws, and long dwell times on mail infrastructure.
Attack Chain (Defender's Perspective)
Based on the advisory's description, the campaign followed a recognizable pattern:
- Reconnaissance and vulnerability scanning. The operators scanned target websites for flaws using a purpose-built tool. This phase generates high-volume, anomalous web traffic — probe patterns against login portals, mail web access interfaces (Outlook Web App / Exchange Control Panel paths), and administrative endpoints.
- Initial exploitation of web-facing infrastructure. Vulnerable web applications — particularly email front-ends — served as the entry point. Web-accessible mail interfaces are high-value targets because a single exploit yields access to the entire mailbox store rather than a single endpoint.
- Persistence and mailbox access. Once inside, the operators accessed email content directly — either through compromised credentials against webmail interfaces, webshells planted on mail servers, or abuse of mail server services and APIs.
- Aggregation and resale. Stolen email was centralized into infrastructure supporting a portal where third parties could browse or purchase access — implying structured exfiltration, indexing, and long-term storage rather than smash-and-grab collection.
Affected Platforms
While the advisory does not enumerate specific product versions, the victim profile and technique set point squarely at:
- Internet-facing webmail and mail infrastructure (Exchange Server / OWA-type interfaces, and equivalent platforms common in Southeast Asian government and healthcare environments)
- Web applications and CMS platforms fronting victim organizations, scanned for exploitable flaws
- Identity and authentication layers protecting email access, where credential theft or session hijacking enables mailbox access without exploiting the mail server directly
Exploitation Status
This is a confirmed, actively attributed campaign with multi-government attribution and existing U.S./UK sanctions against the operating company. This is not theoretical. Organizations matching the victim profile — and their regional partners, suppliers, and correspondent organizations — should treat this as an active threat requiring retrospective hunting, not a forward-looking hypothetical.
Detection & Response
The detections below target the observable behaviors this campaign must generate: anomalous web scanning, webshell deployment on web/mail infrastructure, suspicious mailbox access patterns, and bulk access consistent with email harvesting. Rules are tuned to minimize noise — pair them with asset context (mail servers, DMZ web servers) before broad deployment.
Sigma Rules
---
title: Webshell Drop on Web or Mail Server Process
description: Detects web server or mail server worker processes writing script files to web-accessible directories, consistent with webshell deployment following web exploitation as described in the Integrity Technology Group campaign.
references:
- https://thehackernews.com/2026/10/fbi-says-china-linked-hackers-ran.html
- https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/10/09
status: experimental
id: 3f9c1a72-8b44-4e19-a2d6-7c5e8f1a9b03
tags:
- attack.persistence
- attack.t1505.003
logsource:
category: file_event
product: windows
detection:
selection_img:
Image|endswith:
- '\w3wp.exe'
- '\httpd.exe'
- '\nginx.exe'
- '\tomcat8.exe'
- '\java.exe'
selection_ext:
TargetFilename|endswith:
- '.aspx'
- '.asp'
- '.ashx'
- '.asmx'
- '.jsp'
- '.php'
selection_path:
TargetFilename|contains:
- '\inetpub\wwwroot\'
- '\ClientAccess\'
- '\FrontEnd\HttpProxy\'
- '\htdocs\'
- '\www\'
condition: selection_img and selection_ext and selection_path
falsepositives:
- Legitimate application deployment pipelines writing web content
- CMS administrative publishing activity
level: high
---
title: Web Server Process Spawning Command Shell
description: Detects web or mail server worker processes spawning command interpreters or scripting engines, a hallmark of post-exploitation via webshell or direct command injection against internet-facing applications.
references:
- https://thehackernews.com/2026/10/fbi-says-china-linked-hackers-ran.html
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/10/09
status: experimental
id: 8d2e5b91-4c37-4f82-b6a1-9e3d7c2a5f18
tags:
- attack.execution
- attack.t1059
- attack.t1190
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\w3wp.exe'
- '\httpd.exe'
- '\nginx.exe'
- '\tomcat8.exe'
- '\php-cgi.exe'
- '\UMWorkerProcess.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\net.exe'
- '\net1.exe'
- '\whoami.exe'
- '\ipconfig.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare legitimate application integrations; investigate parent application and command line
level: critical
---
title: Anomalous Logon to Mail Server from Unusual Source
description: Detects successful network logons to Exchange or mail infrastructure from non-interactive logon types outside expected service patterns, consistent with attacker access to mail services using compromised credentials.
references:
- https://thehackernews.com/2026/10/fbi-says-china-linked-hackers-ran.html
- https://attack.mitre.org/techniques/T1078/
author: Security Arsenal
date: 2026/10/09
status: experimental
id: b17a3e48-2d95-4c61-8f24-6a1b9d4e7c52
tags:
- attack.initial_access
- attack.t1078
logsource:
category: authentication
product: windows
detection:
selection:
Logon_Type:
- 3
- 8
filter_service_accounts:
User|endswith: '$'
filter_health_mailbox:
User|startswith:
- 'HealthMailbox'
- 'SYSTEM'
condition: selection and not filter_service_accounts and not filter_health_mailbox
falsepositives:
- Normal OWA/EAS client authentication - baseline source IPs per mail server and alert on deviations
level: medium
KQL — Microsoft Sentinel / Defender
The following hunt queries target mailbox access anomalies (the campaign's objective) and scanning/exploitation patterns against web infrastructure (the entry vector). The mailbox query uses OfficeActivity; the web query works against CommonSecurityLog from WAF/IIS ingestion or Syslog for Linux-hosted front-ends.
// Hunt 1: Anomalous mailbox access patterns — bulk reads consistent with email harvesting
// Look for accounts accessing an abnormal volume of distinct mailboxes or items in short windows
OfficeActivity
| where TimeGenerated > ago(14d)
| where Operation in ("MailItemsAccessed", "MessageBind", "FolderBind")
| where RecordType == "ExchangeItem" or RecordType == "ExchangeItemAggregated"
| extend ClientIP = tostring(parse_json(ClientIP)), UserId = tostring(UserId)
| summarize
Operations = count(),
DistinctFolders = dcount(tostring(parse_json(Folders))),
SourceIPs = make_set(ClientIP, 5)
by UserId, bin(TimeGenerated, 1h)
| where Operations > 200 or DistinctFolders > 50
| project TimeGenerated, UserId, Operations, DistinctFolders, SourceIPs
| order by Operations desc;
// Hunt 2: Scanning and probing patterns against web/mail front-ends
// High request volume from single sources to auth/webmail paths, or 4xx burst behavior
CommonSecurityLog
| where TimeGenerated > ago(7d)
| where RequestURL has_any ("/owa/", "/ecp/", "/ews/", "/autodiscover/", "/rpc/", "/api/")
| summarize
Requests = count(),
DistinctPaths = dcount(RequestURL),
FailedResponses = countif(DeviceAction =~ "failure" or toint(AdditionalExtensions) between (400 .. 499))
by SourceIP, bin(TimeGenerated, 10m)
| where Requests > 300 or (DistinctPaths > 40 and FailedResponses > 50)
| project TimeGenerated, SourceIP, Requests, DistinctPaths, FailedResponses
| order by Requests desc;
// Hunt 3: Webshell execution — web worker processes spawning shells (Defender for Endpoint)
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName in~ ("w3wp.exe", "httpd.exe", "nginx.exe", "tomcat8.exe", "php-cgi.exe", "UMWorkerProcess.exe")
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "net.exe", "whoami.exe", "ipconfig.exe", "wscript.exe", "cscript.exe")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine, AccountName, InitiatingProcessCommandLine
| order by TimeGenerated desc;
Velociraptor VQL
For endpoint forensics on suspected compromised web/mail servers, this artifact hunts for recently created script files in web-accessible directories — the filesystem residue of webshell deployment:
-- Hunt: Recently created script files in web-accessible directories (webshell triage)
-- Scope to Exchange ClientAccess and standard web roots; flag files created in the last 90 days
LET cutoff <= timestamp(epoch=now() - (90 * 24 * 3600))
SELECT FullPath,
Mtime AS Modified,
Ctime AS Created,
Size,
Btime AS BirthTime
FROM glob(globs=[
'C:/inetpub/wwwroot/**/*.aspx',
'C:/inetpub/wwwroot/**/*.asp',
'C:/inetpub/wwwroot/**/*.ashx',
'C:/Program Files/Microsoft/Exchange Server/*/ClientAccess/**/*.aspx',
'C:/Program Files/Microsoft/Exchange Server/*/FrontEnd/HttpProxy/**/*.aspx',
'/var/www/**/*.php',
'/usr/share/nginx/**/*.php',
'/opt/tomcat/webapps/**/*.jsp'
])
WHERE Created > cutoff OR BirthTime > cutoff
ORDER BY Created DESC
-- Corroborating hunt: web worker processes with unexpected child processes (live state)
SELECT Pid,
Ppid,
Name,
CommandLine,
Exe,
Username,
CreateTime
FROM pslist()
WHERE Name =~ '(?i)(cmd|powershell|pwsh|net|whoami|wscript|cscript)'
AND Ppid IN (SELECT Pid FROM pslist() WHERE Name =~ '(?i)(w3wp|httpd|nginx|tomcat|php-cgi|UMWorkerProcess)')
Hardening & Verification Script
For Exchange environments — the highest-value target class in this campaign — this script audits for webshell indicators, reviews suspicious mailbox access permissions, and verifies that web-facing virtual directories are not exposing administrative interfaces externally:
# Exchange / web-facing mail infrastructure hardening audit
# Run elevated on the Exchange server. Review output before making changes.
$report = @()
# 1) Scan web-accessible directories for recently created/modified script files (webshell triage)
$webRoots = @(
"$env:SystemDrive\inetpub\wwwroot",
"$env:ExchangeInstallPath\ClientAccess",
"$env:ExchangeInstallPath\FrontEnd\HttpProxy"
) | Where-Object { Test-Path $_ }
$cutoff = (Get-Date).AddDays(-90)
foreach ($root in $webRoots) {
Get-ChildItem -Path $root -Recurse -Include *.aspx,*.asp,*.ashx,*.asmx -ErrorAction SilentlyContinue |
Where-Object { $_.CreationTime -gt $cutoff -or $_.LastWriteTime -gt $cutoff } |
ForEach-Object {
$report += [PSCustomObject]@{
Check = 'RecentScriptFile'
Path = $_.FullName
Created = $_.CreationTime
Modified= $_.LastWriteTime
}
}
}
# 2) Audit non-default FullAccess mailbox permissions (bulk access = harvesting enabler)
Get-Mailbox -ResultSize Unlimited | Get-MailboxPermission |
Where-Object {
$_.AccessRights -match 'FullAccess' -and
-not $_.IsInherited -and
$_.User -notmatch 'NT AUTHORITY|HealthMailbox|S-1-5-'
} | ForEach-Object {
$report += [PSCustomObject]@{
Check = 'NonDefaultFullAccess'
Path = $_.Identity.ToString()
Created = $_.User.ToString()
Modified= ($_.AccessRights -join ',')
}
}
# 3) Check for ECP exposed externally (admin interface should be internal-only)
$ecp = Get-EcpVirtualDirectory -ErrorAction SilentlyContinue
foreach ($v in $ecp) {
$report += [PSCustomObject]@{
Check = 'ECPVirtualDirectory'
Path = $v.Server + $v.Name
Created = "ExternalUrl: $($v.ExternalUrl)"
Modified= "AdminEnabled: $($v.AdminEnabled)"
}
}
# 4) Verify IIS is not running world-writable content directories
foreach ($root in $webRoots) {
$acl = Get-Acl $root
$acl.Access | Where-Object {
$_.IdentityReference -match 'Everyone|BUILTIN\\Users' -and
$_.FileSystemRights -match 'Write|FullControl|Modify'
} | ForEach-Object {
$report += [PSCustomObject]@{
Check = 'WeakWebRootACL'
Path = $root
Created = $_.IdentityReference.ToString()
Modified= $_.FileSystemRights.ToString()
}
}
}
$report | Format-Table -AutoSize
$report | Export-Csv -Path ".\ExchangeHardeningAudit_$(Get-Date -Format 'yyyyMMdd').csv" -NoTypeInformation
Write-Host "`nAudit complete. Review the CSV for webshell indicators, excessive mailbox permissions, and exposed ECP." -ForegroundColor Yellow
Remediation
Given that this campaign combines opportunistic web exploitation with long-term mailbox access, remediation must address both the entry vector and the data-at-risk. Prioritize in this order:
-
Retrospective compromise assessment (immediately). If your organization operates internet-facing mail infrastructure — especially Exchange — and you match the victim profile (government, law enforcement, healthcare, faith-based organizations, or their partners in or connected to Southeast Asia), assume exposure until proven otherwise. Deploy the Sigma/KQL/VQL hunts above, review IIS and Exchange logs for the past 90+ days, and pull mailbox audit logs (
MailItemsAccessedoperations in Microsoft 365 unified audit logging, or equivalent on-premises auditing) to identify abnormal read patterns. -
Patch and reduce the external attack surface. The entry vector was unpatched or misconfigured web-facing applications identified by automated scanning. Inventory every internet-facing service — especially webmail, ECP, EWS, and Autodiscover endpoints — and confirm all are on current cumulative updates. ECP and other administrative virtual directories should never be reachable from the internet; restrict them at the load balancer/WAF and via IIS IP restrictions. Where patching lags, place a properly tuned WAF in front of mail web services as a compensating control — not a substitute.
-
Enforce phishing-resistant MFA on all mailbox access. Credential theft enables mailbox access without exploiting the server at all. Mandate FIDO2/passkey or certificate-based authentication for all users; eliminate legacy protocols (IMAP, POP3, basic-auth SMTP) that bypass MFA entirely. For on-premises Exchange, deploy hybrid modern auth or place access behind an identity-aware proxy.
-
Constrain mailbox delegation and audit continuously. Remove all non-essential FullAccess delegations (audit script above). Enable and centralize mailbox auditing — this is what allows you to answer the question "what did they read?" months later. Without
MailItemsAccessed-equivalent telemetry, scoping an email theft incident is guesswork. -
Monitor for scanning reconnaissance. The operators' scanning tool generates detectable pre-attack telemetry. Alert on high-volume probing of mail/auth paths (KQL Hunt 2) and feed confirmed scanner infrastructure to your blocklists. Early detection at the reconnaissance phase is the cheapest possible win.
-
Address the downstream exposure problem. Because stolen email was resold via a third-party portal, a historical breach carries ongoing risk: leaked credentials, privileged communications, PHI, and legal correspondence may still be circulating. If you confirm email theft, force credential resets for all users whose mailboxes were accessed, rotate any secrets or credentials transmitted via email, and engage counsel on breach notification obligations under applicable regulations (HIPAA for healthcare entities, applicable data protection laws for Southeast Asian operations).
-
Review sanctions and threat intelligence context. Integrity Technology Group is sanctioned by the U.S. and UK. Consult the full FBI joint advisory (released October 8, 2026, with six partner nations) for any published indicators of compromise, and ensure your threat intel platform ingests them. Organizations with regulatory obligations should document their response to this advisory as part of their threat-informed defense program under NIST CSF or CIS Controls.
Related Resources
Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.