Chinese Cyber Threat Actors Target Global Organizations
Government-linked threat actors from China are exploiting vulnerabilities to steal sensitive data worldwide.
Published · 2 min read
Media: Keith Weller, USDA Agricultural Research Service · USGS · NASA/Isaac Watson
Chinese government-linked cyber threat actors are actively exploiting vulnerabilities to steal sensitive data from organizations worldwide, including those in critical infrastructure sectors in the United States, according to a cybersecurity advisory released by the Cybersecurity and Infrastructure Security Agency (CISA) and other international partners on October 8, 2026.
The advisory details how these threat actors, enabled by the Integrity Technology Group, a China-based company with links to the Chinese government, are utilizing a combination of automated scanning tools, large-scale botnets, and hands-on exploitation techniques. These methods are used to target and compromise networks across multiple sectors, including Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology.
Exploitation Techniques
The cyber threat actors are reportedly exploiting vulnerabilities by using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers. They establish persistence through virtual private network (VPN) software and exfiltrate emails and credentials using scripts. The advisory emphasizes the importance of disabling unused services and ports, sanitizing web application inputs to prevent injection attacks, implementing multifactor authentication for all services, and applying timely patches to reduce risks of compromise.
The advisory identifies several specific vulnerabilities being exploited, including CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, and CVE-2023-22894.
Global Impact
The threat actors have targeted victims not only in the United States but also in Southeast Asia, Africa, and North America. In the US, they have targeted law enforcement, education, and religious organizations, in addition to critical infrastructure sectors.
The advisory is based on technical evidence from multiple Federal Bureau of Investigation (FBI) investigations related to Integrity Technology Group. It is a joint effort by several organizations, including the FBI, CISA, National Security Agency (NSA), United Kingdom National Cyber Security Centre (NCSC-UK), Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), the Canadian Centre for Cyber Security (Cyber Centre), Japan’s National Police Agency (NPA) and National Cybersecurity Office (NCO), New Zealand’s National Cyber Security Centre (NCSC-NZ), and Spain’s Centro Nacional de Inteligencia (CNI).
Recommendations for Organizations
The advisory urges network defenders from government and relevant organizations to hunt for potential compromises from this activity and better protect against this threat and other Chinese government-linked cyber targeting. It provides US federal, state, local, territorial, and tribal (FSLTT) government agencies, as well as international and industry partners, with the indicators and details necessary to proactively defend their networks against this threat and protect critical data.
Organizations are encouraged to review the advisory in detail and implement the recommended mitigation strategies to safeguard their networks against these sophisticated cyber threats.
Sources (1)
TradepilotUSA News writes each story in its own words from the independent reports listed above and links to them. How we report · Report a correction