Integrity Technology Group, also known as Integrity Tech, is a Beijing-based, for-profit cybersecurity company with Chinese government links and government contracts that enables China-linked cyberespionage operations. Its personnel develop and acquire offensive tools, sell capabilities, host infrastructure, and compromise networks worldwide. Associated activity overlaps with operations tracked as Flax Typhoon, Ethereal Panda, and Red Juliett; these tracking labels are not interchangeable with the company and may include activity independent of it. Its targeting includes government and law enforcement agencies, healthcare systems, information technology organizations, manufacturers, religious institutions, nongovernmental organizations, universities, and critical infrastructure. Documented reconnaissance targets include U.S. power infrastructure, Japanese and Polish airports, and Taiwanese natural gas companies, power companies, and universities. Approximately 20 Taiwanese universities were confirmed victims of FishHub activity. Reconnaissance against an organization does not by itself establish successful compromise. Integrity Tech operates MicroScan, a vulnerability-reconnaissance platform used since at least 2017 with more than 1,300 penetration-testing scripts, and FishHub, which supports spear phishing and malware delivery for remote access and file theft. It built and operated the Mirai-based Raptor Train botnet, using compromised consumer and Internet of Things devices to support scanning and obscure malicious traffic. Associated intrusion methods include exploitation of internet-facing applications, credential-harvesting webpages, password spraying against Microsoft Exchange and Microsoft 365, webshells, privilege-escalation tools, and DCSync credential theft. Operators maintain persistent access using SoftEther VPN, abuse legitimate system utilities, disguise malicious artifacts, and automate collection and exfiltration of email from on-premises and cloud services. Company-associated infrastructure also provides third parties access to stolen email. A September 2024 disruption targeted its botnet of more than 200,000 compromised devices. The United States sanctioned the company in January 2025, and the United Kingdom sanctioned it in December 2025. An October 2026 court-authorized operation disrupted infrastructure supporting MicroScan, FishHub, malware delivery, and persistent remote access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
The advisory lists CVE-2014-6278 among eight successfully exploited flaws found in the hackers' penetration-testing scripts. It identifies affected GNU Bash versions as through 4.3 bash43-026; a fixed release was not confirmed.
CVE-2015-3306 affects ProFTPD 1.3.5 and is fixed in 1.3.5a. The advisory identifies it as successfully exploited and newly added to KEV, although the article could not verify that catalog addition at its stated check time.
The advisory lists CVE-2015-5477 as successfully exploited. The article describes it as a denial-of-service bug that makes the BIND DNS server exit and identifies fixed versions 9.9.7-P2 and 9.10.2-P3.
CVE-2016-3081 affects Apache Struts versions 2.3.19–2.3.20.2, 2.3.21–2.3.24.1, and 2.3.25–2.3.28. Exploitation requires Dynamic Method Invocation to be enabled; disabling it is an alternative to upgrading.
CVE-2019-11510 is among the eight successfully exploited flaws. The listed affected Pulse Connect Secure releases are 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4.
3 more CVEs tied to this actor tracked in Mallory.
496 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Beijing-based contractor that built and operated cyber tools used for vulnerability scanning, intrusions, spear-phishing, remote access, and data theft. U.S. authorities seized infrastructure supporting its Microscan and FishHub tools. The company also operated a large Mirai-based IoT botnet and supplied offensive capabilities to China-linked actors.
A sanctioned Chinese organization associated with network compromises, credential theft and email exfiltration. It develops or acquires cyber tools, supplies infrastructure and has enabled groups such as Flax Typhoon. The advisory describes attacks against government, law enforcement, healthcare and religious institutions in Southeast Asia.
China-based operator allegedly providing scanning and intrusion infrastructure to clients. Microscan identified potential vulnerabilities; FishHub supported spear phishing and subsequent malware delivery for remote access and file theft. Approximately 20 Taiwanese universities were confirmed FishHub victims, while other named organizations were scanning targets, not necessarily breached.
A Chinese government contractor that supplies tools and technical support for China-linked hacking operations. Its Microscan tool uses compromised-device infrastructure to identify network weaknesses, while FishHub supports deceptive emails and delivery of malware for remote access and file theft. Authorities seized six supporting domains; approximately 20 Taiwanese universities were confirmed victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.