On October 8, 2026, CISA, the FBI, the NSA, and international partners issued a joint advisory warning that China-based cybersecurity company Integrity Technology Group is enabling threat actors to target critical infrastructure worldwide.
Targeting Critical Infrastructure
CISA, the FBI, the NSA, and international partners issued a joint Cybersecurity Advisory stating that Integrity Technology Group (Integrity Tech) is enabling threat actors to target multiple critical infrastructure sectors worldwide. According to the advisory, Integrity Tech has ties to the Chinese government and acts as a key enabler by acquiring or developing cyber tools, hosting infrastructure, and compromising networks globally.
Based on real-world investigations in North America, Southeast Asia, and Africa, the advisory notes that these threat actors use tactics, techniques, and procedures consistent with activity publicly known as Flax Typhoon, Ethereal Panda, and Red Juliett. They utilize large-scale botnets, virtual private network infrastructure, and living off the land.
Stealthy Access and Targeted Sectors
To maintain long-term, stealthy access to networks, the threat actors are targeting edge devices that are not closely monitored by the targeted organization. The campaign has targeted critical infrastructure sectors including government, critical manufacturing, and healthcare, alongside victims in U.S. law enforcement and education organizations.
“Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing,” said Acting Executive Assistant Director for Cybersecurity Chris Butera.
Official Response and Guidance
The agencies urge organizations to review the advisory, hunt for signs of compromise, and implement recommended mitigations to secure edge infrastructure. This includes patching listed known exploited common vulnerabilities and exposures (CVEs).
"Integrity Technology Group, a China-based company with ties to the Chinese government, is one of those enterprises, acquiring or developing cyber tools and hosting infrastructure for actors targeting networks worldwide," said Assistant Director Brett Leatherman of the FBI's Cyber Division. Officials encourage organizations to apply the advisory's mitigations and report suspicious activity to their local FBI field office.
What to do
- Review the joint Cybersecurity Advisory to understand the tactics used by these threat actors.
- Hunt for signs of compromise across your networks.
- Implement recommended actions and mitigations to secure edge infrastructure.
- Patch the listed known exploited common vulnerabilities and exposures (CVEs).
- Report suspicious activity to your local FBI field office.
Key facts and where they come from
- CISA, FBI, NSA and international partners issued a joint advisory warning about Integrity Technology Group.
issued a joint Cybersecurity Advisory warning that Integrity Technology Group (Integrity Tech), a China-based cybersecurity company, is enabling threat actors to target multiple critical infrastructure sectors worldwide
- Integrity Tech has ties to the Chinese government and enables malicious cyber activity.
With ties to the Chinese government, Integrity Tech is a key enabler of malicious cyber activity by acquiring or developing cyber tools, hosting infrastructure, and compromising networks globally.
- Threat actors are using TTPs consistent with Flax Typhoon, Ethereal Panda, and Red Juliett.
are using tactics, techniques, and procedures (TTPs) consistent with the activity publically known as Flax Typhoon, Ethereal Panda, and Red Juliett.
- Actors target unmonitored edge devices to maintain long-term access.
To maintain long-term, stealthy access to networks, these actors are targeting edge devices that are not closely monitored by the targeted organization.
