Original Coverage & Source Attribution: www.israeldefense.co.il
U.S. and international cybersecurity agencies have warned that Integrity Technology Group, a China-based cybersecurity company with ties to the Chinese government, is enabling cyber operations targeting critical infrastructure and other organizations worldwide.
In an advisory released October 8, the Cybersecurity and Infrastructure Security Agency (CISA), FBI, National Security Agency (NSA) and international partners said the company acquires or develops cyber tools, provides hosting infrastructure and compromises networks to support malicious activity. Their findings draw on investigations and observed activity in North America, Southeast Asia and Africa.
According to the advisory, the activity is consistent with operations publicly associated with Flax Typhoon, Ethereal Panda and Red Juliett. The agencies said the actors have targeted government organizations, critical manufacturing, healthcare, law enforcement and educational institutions.
A key concern is the targeting of network edge devices, such as routers and other equipment connecting internal networks to external systems. These devices may receive less security monitoring than other parts of an organization’s infrastructure, making them attractive targets for attackers seeking persistent, difficult-to-detect access.
The operations also employ techniques including large-scale botnets, virtual private network infrastructure and so-called living-off-the-land methods, which use legitimate system tools and capabilities to conduct malicious activity while potentially making it harder to distinguish from normal administration.
The warning comes amid sustained concerns among Western governments that China-linked cyber actors are positioning themselves inside critical infrastructure networks, including operational technology (OT) environments that support physical processes. Such access could potentially be used to disrupt essential services at a later stage, although the advisory does not establish that every compromised network has been prepared for disruption.
CISA urged organizations to review the advisory, search their networks for signs of compromise, patch known exploited vulnerabilities and implement recommended mitigations for exposed infrastructure. The FBI also encouraged organizations to report suspicious activity to local field offices.
The agencies’ warning highlights a broader challenge for defenders: identifying and disrupting the infrastructure and commercial entities that support cyber operations, rather than focusing exclusively on the individual actors carrying them out.
The advisory provides technical indicators and defensive guidance intended to help network defenders identify malicious activity, investigate potential compromises and reduce the risk of further intrusion.




