The UK National Cyber Security Centre (NCSC) and eight international partners issued an advisory on 8 October 2026 exposing global cyber espionage enabled by China-based Integrity Technology Group, which has links to the Chinese government. China-linked actors used AI-enabled automated scanning, large-scale botnets and manual exploitation to compromise organisations and steal sensitive data, including from critical sectors. Integrity Tech personnel supported these operations through tool development, infrastructure acquisition and hosting, and network compromise. The reported activity is consistent with campaigns publicly known as Flax Typhoon, Ethereal Panda and Red Juliett, among others.
The disclosure follows UK sanctions imposed in December 2025 on Integrity Tech and Sichuan Anxun Information Technology, known as i-Soon. The UK said Integrity Tech managed a covert cyber network and assisted attacks, including against UK public-sector IT systems, while i-Soon targeted more than 80 government and private-sector systems worldwide. The NCSC assessed it was almost certain that a broader Chinese private-sector ecosystem of security firms, data brokers and hackers for hire supports Chinese state-linked operations. These actions build on an August 2025 joint exposure of three other China-based companies linked to SALT TYPHOON. The NCSC urged organisations to implement the latest advisory’s mitigation guidance and strengthen cyber resilience.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
Gurucul published a report providing domain, IP address and file-hash indicators for Chinese government-linked attacks enabled by Integrity Technology Group. It included detection queries for domain and URL fields, source and destination IP addresses, and MD5 and SHA-256 hashes.
The NCSC and eight international partners issued an advisory detailing how Integrity Tech enables China-linked actors to compromise networks using AI-enabled scanning, large-scale botnets and manual exploitation. The advisory described sensitive-data theft across multiple sectors and activity consistent with Flax Typhoon, Ethereal Panda and Red Juliett, alongside Integrity Tech personnel’s role in tool development, infrastructure provision and network compromise.
The article reports that Xu Zewei, a co-defendant in the case involving Zhang Yu, was extradited from Italy to the United States to face charges involving alleged theft of COVID-19 research from U.S. universities and immunology and virology researchers.
The European Union imposed sanctions on Integrity Technology Group, also known as Integrity Tech.
The NCSC, industry and 15 international partners across nine countries issued guidance on defending against cyber threats from covert networks.
The UK sanctioned i-Soon and Integrity Tech, stating that i-Soon targeted more than 80 government and private-sector IT systems worldwide. It said Integrity Tech managed a covert cyber network and provided technical assistance for cyberattacks, including against UK public-sector IT systems.
The UK and partners from 12 other countries issued an advisory linking Sichuan Juxinhe, Beijing Huanyu Tianqiong and Sichuan Zhixin Ruije to SALT TYPHOON cyber-espionage. The activity targeted government, telecommunications, transportation and military infrastructure globally to enable Chinese intelligence services to track targets’ communications and movements.
The United States imposed sanctions on Integrity Technology Group for facilitating hacking operations.
The FBI disrupted the Raptor Train botnet, which contained more than 200,000 hijacked routers, cameras and other consumer devices. The U.S. Justice Department attributed the botnet to Integrity Technology Group.
The NCSC and international partners exposed Integrity Tech as the operator of a substantial botnet of malware-infected internet-connected devices. The advanced persistent threat group Flax Typhoon used the botnet to conduct cyberattacks.
The U.S. State Department announced a reward of up to $10 million for information leading to the identification or location of Chinese national Zhang Yu. He was charged in connection with the 2021 Microsoft Exchange Server attacks attributed to Silk Typhoon, formerly Hafnium.
CISA added CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199 and CVE-2023-22894 to its Known Exploited Vulnerabilities Catalog based on reported activity by Chinese government-linked attackers enabled by Integrity Technology Group.
Unsealed U.S. court documents identified alleged Integrity Technology Group targets including a South Carolina power company, airports in Japan and Poland, Taiwanese natural gas and power companies, and a multinational nongovernmental organization. These disclosures broadened the identified targeting beyond the previously reported Taiwanese universities.
The U.S. Justice Department and FBI seized six internet domains supporting Integrity Tech’s Microscan and FishHub tools, which enabled vulnerability reconnaissance, phishing, malware delivery, remote access and file theft. Prosecutors identified approximately 20 Taiwanese universities as confirmed victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 310 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
24 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcesecurityaffairs.com
Open sourceinfosecurity-magazine.com
Open sourceitpro.com
Open sourcencsc.gov.uk
Open sourcebankinfosecurity.com
Open sourcegov.uk
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.