The UK’s National Cyber Security Centre (NCSC), alongside international partners from six countries, has identified China-linked Integrity Technology Group as a major facilitator of global cyberattacks. The company is accused of providing AI-enabled tools, large-scale botnets, and hands-on exploitation techniques to actors targeting organizations and critical sectors worldwide.
The NCSC, a part of GCHQ, issued a formal advisory revealing that Integrity Tech, which maintains links to the Chinese government, supports a broader ecosystem of malicious cyber activity. These operations include developing tools for sale, acquiring infrastructure, and compromising networks globally. The activity linked to the company is consistent with known campaigns such as Flax Typhoon, Ethereal Panda, and Red Juliett.
Tools and Tactics of Integrity Tech
Integrity Tech enables malicious actors to perform automated scanning and utilize substantial botnets—networks of internet-connected devices infected with malware—to execute cyberattacks. In September 2024, the NCSC exposed the company as the operator of a significant botnet utilized specifically by the advanced persistent threat group Flax Typhoon to steal sensitive and confidential data.
According to the NCSC, the company employs individuals who contribute directly to the Chinese cyber ecosystem, facilitating the compromise of global networks. Paul Chichester, NCSC Director of Operations, stated, The extensive malicious cyber activities, and services by Integrity Tech, that have been exposed today should be extremely concerning for all network defenders.
International Response and Sanctions
The UK government previously sanctioned Integrity Tech last year for its role in malicious cyber activity directed at the UK and its allies. The current advisory serves as a call for organizations to bolster their cyber resilience and adopt defensive measures against these evolving threats.
The NCSC coordinated this new advisory alongside government agencies from Australia, Canada, Japan, New Zealand, Spain, and the United States. Authorities are urging network defenders to review the provided guidance to better protect against the techniques employed by actors supported by the Integrity Tech ecosystem.