The advisory, released on Thursday by Britain’s National Cyber Security Centre and agencies from six other countries, describes how China-linked operators combine automated scanning, compromised devices and direct exploitation of security weaknesses to steal sensitive information from organisations worldwide.
The US Justice Department simultaneously announced court-authorised seizures targeting Microscan and FishHub, two tools allegedly operated by personnel associated with Integrity Technology Group. Seven domains were seized in an operation intended to prevent further use of the infrastructure. The disruption aimed to disable services rather than issue warnings.
American investigators said Microscan identified weaknesses in computer networks, while FishHub supported targeted phishing attacks and deployed malware capable of providing unauthorised remote access or extracting files. The allegations were detailed in court documents unsealed in Pennsylvania.
The targets of Microscan activity included a South Carolina electricity company, airports in Japan and Poland, Taiwanese energy companies, universities and an international non-governmental organisation, the Justice Department said. Approximately 20 universities in Taiwan were confirmed victims of FishHub activity.
The British agency, part of GCHQ, said Integrity Tech supplied capabilities to cyber operators through developing and selling tools, acquiring infrastructure and compromising networks. The activity overlapped with campaigns identified by security researchers as Flax Typhoon, Ethereal Panda and Red Juliett.
Paul Chichester, the NCSC’s director of operations, said the breadth of targeted sectors demonstrated the scale of the threat. He urged organisations to examine the technical guidance and strengthen their defences against the methods identified by investigators.
The warning was issued with agencies from Australia, Canada, Japan, New Zealand, Spain and the United States. It draws on investigations of attacks affecting North America, Southeast Asia and Africa, and includes technical indicators intended to help security teams identify possible compromises.
The US National Security Agency said affected sectors included government services, critical manufacturing, healthcare and information technology. Law enforcement bodies, educational institutions and religious organisations were also among the targets identified by investigators.
Officials described a combination of large botnets, virtual private network infrastructure and techniques that exploit legitimate administrative tools already present within victim systems. Such methods can make unauthorised activity harder to distinguish from ordinary network management.
The advisory identifies attempts to exploit known software vulnerabilities, steal credentials and maintain access after an initial intrusion. It urges defenders to examine network logs, investigate suspicious connections, apply security updates and restrict access to sensitive systems. Administrators should investigate unusual authentication patterns indicating stolen credentials.
The authorities also highlighted the use of artificial intelligence to assist automated scanning, alongside manual techniques deployed after attackers identify vulnerable systems. Their findings describe a mixture of commercially available utilities and specialised malicious capabilities rather than a single attack method.
The Justice Department alleged that Integrity Tech used a network of internet-connected devices infected with Mirai malware to support Microscan reconnaissance. The botnet enabled scanning of external systems before operators attempted to exploit weaknesses they discovered.
FishHub, investigators said, was used after phishing attacks to install additional malware. Its capabilities allegedly included searching for selected files and transmitting information to servers controlled by the operators, as well as allowing remote access for their clients.
Integrity Tech has contracts with China’s government, according to US authorities. The company was sanctioned by Britain in December 2025 over alleged malicious cyber activity. The latest findings concern the conduct of operators and infrastructure associated with the business, rather than establishing that every attempted intrusion succeeded.
Beijing has rejected accusations surrounding Chinese cyber operations and has called for international cooperation on network security. The Chinese government maintains that it opposes cyberattacks and objects to the politicisation of cybersecurity disputes.
The American seizures follow a September 2024 operation against an Integrity Tech-linked botnet involving more than 200,000 compromised consumer devices worldwide. Authorities said the earlier network included equipment that could be remotely controlled without its owners’ knowledge.
The FBI’s San Diego and Baltimore field offices are investigating the latest case with its Cyber Division. The Justice Department said Japan’s National Police Agency provided assistance, while prosecutors in Pennsylvania and the department’s National Security Division are handling the proceedings. Officials have not announced arrests linked to the seizures.
Follow Arabian Post
Select Arabian Post as your preferred source on Google and MSN News for trusted business news and Arab politics and updates.