decrypted · 9 october 2026 · vulnerabilities and patching · supply chain · ai and llm security

A Beijing contractor ran the hacking kit, and the doors it used were a decade old

On Thursday the NCSC and six allied countries named a Beijing company, Integrity Technology Group, as the engine room behind the Flax Typhoon hacking campaign, while the FBI seized seven domains used to run its tools. The headline is attribution. The lesson for a UK director is duller and more useful: the intrusions leaned on old, well-known weaknesses in systems that faced the internet.

A contractor, not a unit

The joint advisory (AA26-281A) is co-sealed by agencies in the UK, US, Australia, Canada, Japan, New Zealand and Spain. The NCSC describes a company that employs people who develop tools for sale and use, acquire and host infrastructure, and compromise networks. Think of a locksmith that also sells burglary kits and rents out the getaway van. The UK sanctioned the firm in 2025. Paul Chichester, the NCSC's Director of Operations, said the findings "should be extremely concerning for all network defenders".

How the machinery worked

Two tools were disrupted. MicroScan is a scanner carrying more than 1,300 vulnerability-testing scripts, used to rattle the handles of internet-facing systems. FishHub came after a break-in: it delivered further malware and helped pull files out. Prosecutors say about 20 Taiwanese universities were hit through it.

Once inside, the advisory describes actors installing SoftEther VPN clients disguised as Windows files such as conhost.exe, pulling Active Directory data with a DCSync-style tool, and taking email through the Exchange Web Services interface. A tool called EBurst did password spraying against Exchange and Microsoft 365. That means trying one common password across every account, rather than many passwords on one account, so no single user trips a lockout. The NCSC adds that the attackers combine AI-enabled automated scanning, large botnets and manual exploitation.

What does a defender see? Very little, which is the point. Spraying looks like a scatter of ordinary failed sign-ins spread across many accounts. A VPN client named conhost.exe looks like housekeeping. Mail pulled through a legitimate interface looks like a mail app. Detection depends on knowing what normal looks like, and that again starts with an inventory.

Old holes, wide doors

The advisory lists eight vulnerabilities the actors successfully exploited. They include Bash (CVE-2014-6278), ProFTPD (CVE-2015-3306), Apache Struts (CVE-2016-3081), Pulse Connect Secure (CVE-2019-11510) and GitLab (CVE-2021-22205). CISA added five of the eight to its Known Exploited Vulnerabilities catalogue. Some are a decade old. None needed cleverness; they needed an internet-facing system nobody had retired.

The Secure by Design reading

Nothing in the listed exploits was new. It is a flaw in what you left switched on. The design decisions that blunt this campaign are unglamorous:

The cost is mostly an asset register and the nerve to turn things off. That is cheaper than explaining to a regulator why a 2015 file server was your front door. The advisory names no UK victims, and I have seen no claim of one. But a scanner does not check the postcode first.

Also this week

Firmware you cannot uninstall. Bitdefender found low-cost Android phones on MediaTek chips shipping with a system app that silently installs disguised apps for ad fraud. Thousands of devices across more than 150 countries are affected, and the largest shares are in Mexico, France and Italy. Some firmware carried certificates naming Shenzhen Zediel, though Bitdefender says that does not show the company was involved, and it has not established who added the code or where in the supply chain. Cleanup needs firmware-level fixes. If your staff bring in bargain handsets, the cheapest one may be the costliest.

Your old emails as training data. More than 100 US lawmakers wrote to Google and the defunct Spirit Airlines about a reported $10 million deal to train AI on Spirit's internal records, which one lawmaker says include about 100 million emails and 500 million Teams messages. Google says personal information will be excluded or de-identified by an independent third party. The lawmakers doubt that is enough. Under UK GDPR, a failed company's staff data is still staff data, and administrators and buyers of insolvent UK firms should expect the same question.

Ransomware recovery that allegedly was not. US prosecutors have charged the owner of MonsterCloud with wire fraud, alleging the firm quietly paid gangs and billed clients far more. The indictment alleges one $8,200 ransom became a $150,000 invoice, and that hundreds of US and Canadian firms were charged more than $19 million in total. These are allegations, and he has pleaded not guilty. Ask any recovery firm in writing whether it ever pays.

Sources

If you want help working out what your own organisation has left facing the internet, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.