Security Advisory · October 8, 2026
A new joint advisory from the FBI, CISA, NSA and partner agencies in seven other countries describes a years-long campaign of webmail password spraying and mailbox theft. Here's what it means for small and mid-sized businesses.
On October 8, 2026, CISA published advisory AA26-281A, co-sealed by the FBI, NSA and cyber agencies in the UK, Australia, Canada, Japan, New Zealand and Spain. It attributes a long-running hacking campaign to Integrity Technology Group, a China-based company with links to the Chinese government. Security researchers also track the activity as Flax Typhoon, Ethereal Panda and Red Juliett.
The victims include government agencies, law enforcement, healthcare, manufacturing, IT providers, schools and religious organizations. Most of the confirmed data theft was in Southeast Asia, but the targets also include North America.
Most of the advisory describes attacks on email accounts and mailboxes. Three techniques stand out.
The attackers use an open-source tool called EBurst to guess passwords against Microsoft Exchange and Office 365. It attacks ten different login points, including Outlook on the web, ActiveSync (phones), Autodiscover and Exchange Web Services. Password spraying tries a few common passwords against many accounts, so it often stays under lockout thresholds. If MFA only protects the browser login and not ActiveSync or EWS, those other login points stay open.
Once in, the attackers don't need to stay logged in. One tool pulls mail through Exchange Web Services, compresses and encrypts it, and uploads it to their servers. Another, called office-cli, keeps automated access to Microsoft 365 mailboxes using stolen cloud application credentials. Changing a user's password does not revoke that kind of app access. You have to find and remove the app.
The attackers injected code into legitimate but vulnerable websites. The code showed visitors a fake username and password prompt, then offered a password-protected ZIP file. Inside was malware disguised as a Windows diagnostics program (DiagTrack.exe) that goes after the victim's email data. Password-protected archives are a common trick because many scanners can't look inside them.
The advisory lists eight vulnerabilities the group has exploited. Every one is old and already patched: Pulse Connect Secure VPN (CVE-2019-11510), GitLab (CVE-2021-22205), Apache Struts, ProFTPD, ISC BIND, GNU Bash "Shellshock", ONLYOFFICE DocumentServer and Strapi. In other words, they got in through systems that were never updated or were past end of life. The group also installs SoftEther VPN software, renamed to look like Windows system files, to keep a back door open, and it steals Active Directory credentials with a DCSync tool.
These steps are drawn from the advisory's own recommendations, in the order we'd do them.
We think you should know what a product covers and what it doesn't.
No single product covers all of it. That's why the advisory lists nineteen mitigations, not one.
Isolate the affected machines, keep the logs, and report it: in the US to the FBI (ic3.gov) or CISA (cisa.gov/report). The full advisory includes indicators of compromise (domains, IP addresses and file hashes) in STIX format for your security team or provider. CISA notes that many of those indicators are years old, so check them before blocking.
Source: CISA, FBI, NSA et al., Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data, Advisory AA26-281A, October 8, 2026. Summary by the EFA Security team.
The full advisory, with indicators of compromise and MITRE ATT&CK mappings.