China-Linked Actors Leverage AI and Botnets for Global Data Theft, NCSC and Partners Warn
UK and international partners have exposed a China-linked company, Integrity Technology Group, for enabling sophisticated cyberattacks using AI and botnets to steal sensitive data worldwide.

The UK's National Cyber Security Centre (NCSC), alongside eight international partners from six countries, has issued a stark warning regarding the global malicious cyber activities enabled by Integrity Technology Group (Integrity Tech), a China-based company with alleged ties to the Chinese Government. The advisory details how this company has facilitated cyber actors in compromising networks and stealing sensitive data from organizations across the globe, employing a potent mix of advanced techniques.
Integrity Tech is accused of enabling malicious actors to uniquely leverage AI-driven tools for automated scanning, alongside large-scale botnets and hands-on exploitation methods. This combination allows for the widespread compromise of corporate networks and the exfiltration of confidential data from a diverse range of critical sectors. The scale and sophistication of these operations highlight a significant and evolving threat to global cybersecurity.
This is not the first time Integrity Tech has faced scrutiny. Last year, the UK government sanctioned the company, along with another China-based cybersecurity firm, for their involvement in malicious cyber activities targeting the UK and its allies. The advisory further points out that Integrity Tech employs individuals who actively contribute to a broader Chinese cyber ecosystem, including developing and selling tools, acquiring and hosting malicious infrastructure, and directly compromising networks.
The activities described in the advisory are consistent with previously identified campaigns, publicly known under names such as Flax Typhoon, Ethereal Panda, and Red Juliett. This attribution suggests a coordinated and persistent effort by state-sponsored or state-aligned actors to gather intelligence and disrupt targeted organizations.
In September 2024, the NCSC and its international partners had already identified Integrity Tech as the operator of a substantial botnet. This botnet, a network of infected internet-connected devices controlled remotely, was reportedly utilized by the advanced persistent threat group Flax Typhoon. The current advisory expands on these findings, detailing the broader ecosystem and the AI-enabled capabilities now being employed.
Organizations worldwide are urged to take immediate action to strengthen their cyber resilience and defend against these evolving threats. The NCSC advises network defenders to understand the techniques employed by these actors and implement the recommended mitigation strategies. The breadth of sectors targeted underscores the universal nature of this threat, making vigilance and proactive defense crucial for all.
The NCSC has co-issued this advisory with agencies from Australia, Canada, Japan, New Zealand, Spain, and the United States, demonstrating a unified international front against these malicious cyber operations. The full advisory is available via the FBI's website, providing detailed technical guidance and indicators of compromise for defenders.
This coordinated international action signals a commitment to transparency and collective defense against sophisticated state-sponsored cyber threats. By calling out the actors and the ecosystem that enables them, authorities aim to disrupt these operations and bolster the defenses of organizations worldwide against persistent and evolving cyber espionage and data theft campaigns.
This advisory from CISA, the FBI, and multiple international partners provides a deeper dive into the tactics, techniques, and procedures (TTPs) employed by China-linked threat actors enabled by Integrity Technology Group. It details the specific combination of large-scale botnets, VPN infrastructure, living-off-the-land techniques, and exploitation tools used for computer network exploitation (CNE) across critical infrastructure and other sectors. The advisory also includes a comprehensive list of affected products and specific indicators of compromise (IOCs) to aid in detection and mitigation efforts.