The advisory, published on Thursday, identifies Integrity Technology Group, a company based in China, as an enabler of operations targeting government services, manufacturers, healthcare providers and technology networks. It describes automated scanning, large botnets and direct exploitation of vulnerable systems, while providing technical indicators intended to help organisations detect intrusions.
Britain’s National Cyber Security Centre (NCSC), part of GCHQ, issued the warning alongside eight partner agencies from Australia, Canada, Japan, New Zealand, Spain and the United States. The agencies said Integrity Tech had helped threat actors acquire hacking tools, operate supporting infrastructure and compromise networks across multiple countries.
The warning coincided with a separate American operation against infrastructure allegedly operated by the company. The US Justice Department and Federal Bureau of Investigation announced court-authorised seizures of seven internet domains linked to two tools, Microscan and FishHub, used to identify weaknesses and facilitate attacks.
American investigators said Microscan supported vulnerability scanning against internet-facing systems, while FishHub was used to deliver malicious software through targeted phishing. Court documents allege that personnel associated with Integrity Tech operated the tools as part of activity tracked by cybersecurity specialists as Flax Typhoon.
The Justice Department said confirmed FishHub victims included approximately 20 universities in Taiwan. It also alleged that unauthorised remote administration software connected compromised networks to a server controlled by Integrity Tech. The seizures were intended to deny operators access to infrastructure supporting those activities.
The joint advisory draws on investigations and observed malicious activity in North America, Southeast Asia and Africa. It says hackers combined automated techniques with hands-on activity after gaining access, making it important for defenders to examine both exposed devices and signs of unauthorised movement within networks.
Among the techniques highlighted are exploitation of vulnerabilities in widely used software, misuse of legitimate administration utilities and reliance on virtual private network infrastructure to obscure the origins of malicious connections. The agencies also described artificial intelligence-enabled capabilities within the broader threat environment, alongside conventional methods for locating and exploiting weaknesses.
Paul Chichester, the NCSC’s director of operations, said the activities and services attributed to Integrity Tech should concern network defenders. He urged organisations across affected sectors to consult official guidance and strengthen protections against the techniques described.
The US National Security Agency said the company employed people who contributed to a wider ecosystem of malicious cyber operations, including developing tools and hosting infrastructure. American authorities maintain that Integrity Tech has contracts with China’s government and has supported operations linked to state interests.
China rejects allegations that it sponsors cyberattacks. Following the American action, its embassy in Washington disputed the accusations, reiterated Beijing’s opposition to hacking and criticised what it characterised as the politicisation of cybersecurity. The claims against Integrity Tech remain allegations by the participating governments and investigators.
The latest warning follows sanctions imposed by Britain on Integrity Tech in December 2025 over alleged malicious cyber activity affecting Britain and its allies. Officials have also previously associated the company with Flax Typhoon, a group identified in investigations of compromised internet-connected equipment.
An earlier American operation in September 2024 disrupted a botnet linked to the company involving more than 200,000 compromised consumer devices. Such networks can allow operators to route traffic through equipment belonging to unsuspecting users, complicating attempts to identify the source of attacks.
The new advisory urges organisations to patch known vulnerabilities, restrict unnecessary external access, monitor authentication and network activity, and investigate technical indicators associated with the identified operations. Its guidance is directed particularly at operators of critical services, where a breach could expose sensitive information or disrupt essential functions.
Security teams are also advised to review systems that may have been compromised before vulnerabilities were corrected. Installing software updates alone cannot establish whether attackers previously obtained credentials or maintained access. The agencies’ technical guidance includes information intended to support forensic examinations, identify suspicious connections and help organisations determine whether additional containment measures are necessary.
The FBI said its San Diego and Baltimore field offices were investigating the case with assistance from its Cyber Division. Prosecutors in Pennsylvania and the Justice Department’s National Security Division are handling the legal proceedings, with assistance from authorities in Japan.
Follow Arabian Post
Select Arabian Post as your preferred source on Google and MSN News for trusted business news and Arab politics and updates.