← Back to blog

China-Linked Hackers Exploited Web Flaws to Breach Critical Sectors

FBI and international partners expose a Chinese cyber group targeting government, healthcare, and religious organizations. They used a custom portal to distribute stolen emails and exploited web application vulnerabilities.

TL;DR

  • Hackers linked to Integrity Technology Group targeted SE Asian sectors including government and healthcare.
  • Stolen emails were distributed via a third-party access portal built by the attackers.
  • The group used automated tools to scan for and exploit web application vulnerabilities.
  • US and UK have sanctioned the company behind the hacking operations.
  • Organizations should audit third-party access and patch web apps regularly.

A cybersecurity company linked to China conducted widespread attacks against government bodies, law enforcement, healthcare systems, and religious institutions across Southeast Asia. According to a joint statement from the FBI and agencies from six other nations, these hackers leveraged web application flaws and maintained persistent access through a custom-built portal.

The operation, attributed to Integrity Technology Group (ITG), involved scanning target websites for vulnerabilities using proprietary tools. Once inside, the attackers exfiltrated sensitive email communications and created a backend system that enabled third parties to access this stolen data. This method suggests a high level of operational sophistication and possible resale or sharing of intelligence.

Attack Vector and Tactics

  • Hackers used vulnerability scanning tools to identify weaknesses in public-facing web applications.
  • They exploited unpatched flaws to gain initial access to internal networks.
  • A custom portal was developed to manage and share stolen email credentials and communications.
  • Targets spanned multiple critical infrastructure sectors, indicating broad strategic intent.

Defensive Recommendations

  • Regularly audit all web applications for known vulnerabilities and apply patches immediately.
  • Implement strict access controls and monitor for unauthorized third-party portals or backdoors.
  • Review network logs for unusual outbound data transfers or unknown administrative interfaces.
  • Train staff on recognizing phishing attempts that could lead to initial compromise.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

China-Linked Hackers Exploited Web Flaws to Breach Critical Sectors — Agent Breach Blog | Agent Breach