CISA Issues Warning on Chinese Government-Linked Threat Actors

The threat actors employ a combination of botnets, VPN infrastructure and living-off-the-land techniques.

Silhouetted hackers at laptops facing each other against US and Chinese flag backgrounds with binary code and stars, representing cyber conflict.
istock.com/BeeBright

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA) and international partners released a joint Cybersecurity Advisory Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data. 

The advisory details malicious cyber activity enabled by the Integrity Technology Group (Integrity Tech), a China-based company with ties to the Chinese government, targeting organizations around the globe—including critical manufacturing and information technology sectors in the U.S.

These Integrity Tech-enabled threat actors employ a sophisticated combination of large-scale botnets, virtual private network (VPN) infrastructure, living off the land techniques, and repositories of computer network exploitation tools to infiltrate networks and exfiltrate sensitive data. Their tactics, techniques, and procedures (TTPs) are consistent with cyber activity known publicly as Flax Typhoon, Ethereal Panda and Red Juliett—among other names—and include exploiting vulnerabilities through automated scanning tools, cross-site scripting (XSS) attacks, and password spraying. 

The advisory shares detection and mitigation guidance to help network defenders reduce the risk of compromise, and provides a full list of successfully exploited Common Vulnerabilities and Exposures. CISA has added the following five CVEs to the Known Exploited Vulnerabilities Catalog (KEV) based on this activity:

CISA is also recommending the following actions to help protect your organization:

  • Disable unused services and ports, such as automatic configuration, remote access, or file sharing protocols.
  • Sanitize user input in web applications to prevent possible XSS payload injection.
  • Implement identity, credential, and access management (ICAM) policies, and require multifactor authentication for services (to the extent possible).

CISA encourages security professions to review the full advisory and leverage available resources, such as CISA’s Eviction Strategies Tool and Internet Exposure Reduction Guidance.

More in Cybersecurity