CISA, FBI, NSA and International Partners Warn of China-based Cybersecurity Company Enabling Threat Actors to Target Multiple Critical Infrastructure Sectors Wo
U.S. and international agencies warn a China-based cybersecurity firm enables global attacks on critical infrastructure via botnets, VPNs and edge devices, urging network defenders to implement mitigations.
The Cybersecurity and Infrastructure Security Agency (CISA), FBI, NSA, and international partners issued a joint advisory warning that Integrity Technology Group, a China-based cybersecurity company, is enabling threat actors to target critical infrastructure sectors worldwide. The company is accused of providing tools such as large-scale botnets, VPN infrastructure, and living-off-the-land techniques to malicious actors. Investigations revealed activity across North America, Southeast Asia, and Africa, prompting recommendations for network defenders to detect and respond to these threats.
Integrity Technology Group, with alleged ties to the Chinese government, is identified as a key enabler of malicious cyber activity. The company acquires or develops cyber tools, hosts infrastructure, and compromises networks globally. Threat actors using Integrity Tech’s resources employ tactics consistent with groups known as Flax Typhoon, Ethereal Panda, and Red Juliett, focusing on edge devices that are often overlooked by targeted organizations.
The advisory provides actionable steps for network defenders to secure edge infrastructure and protect networks, including patching known exploited vulnerabilities. It emphasizes the importance of collaboration between government agencies and the private sector to address the threat posed by Chinese government-affiliated actors targeting critical infrastructure, including operational technology systems.
CISA Acting Executive Assistant Director for Cybersecurity Chris Butera and FBI Assistant Director Brett Leatherman emphasized the urgency of the threat. They urged organizations to review the advisory, implement mitigations, and report suspicious activity. The advisory highlights targeted sectors such as government, critical manufacturing, healthcare, law enforcement, and education, calling for heightened vigilance and proactive defense measures.