SOC Prime Bias: Critical

09 Oct 2026 13:20 UTC

Chinese State-Linked Hackers Blend Automated Tools With Hands-On Attacks

Author Photo
SOC Prime Team linkedin icon Follow
Chinese State-Linked Hackers Blend Automated Tools With Hands-On Attacks
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

Chinese government-linked actors, supported by Integrity Technology Group, utilize a combination of automated scanning tools, large-scale botnets, and manual exploitation. They target sensitive data across critical infrastructure sectors using vulnerabilities in web applications and Microsoft Exchange servers. The actors employ various techniques for persistence, credential theft, and data exfiltration to achieve their objectives.

Investigation

The investigation was conducted by multiple international agencies, including the FBI, CISA, NSA, and others, based on technical evidence recovered from multiple investigations related to Integrity Technology Group. Analysts observed the use of custom tools like MicroScan, EBurst, and Curlc4.txt, alongside standard living-off-the-land techniques. Findings revealed specific malware such as live700_v1.exe and the use of SoftEther VPN for persistence.

Mitigation

Organizations should prioritize disabling unused services and ports and sanitizing web application inputs to prevent injection attacks. Implementing multifactor authentication (MFA) for all services and adopting strong identity and access management (ICAM) policies is critical. Additionally, timely patching of software and firmware is recommended to reduce the risk of exploitation.

Response

Upon detection, organizations should isolate compromised hosts and initiate threat hunting to determine the full scope of the intrusion. Review relevant logs and artifacts to identify specific TTPs and a timeline of activities. Implement eviction countermeasures systematically using established playbooks to contain and eradicate the threat actor from the network.

Attack Flow

Detections

Download or Upload via Powershell (via cmdline)

SOC Prime Team
09 Oct 2026

Possible Unauthorized Network Scan via Nmap Or Masscan (via cmdline)

SOC Prime Team
09 Oct 2026

Suspicious Mailbox Export Request (via powershell)

SOC Prime Team
09 Oct 2026

Suspicious Executable File Named Like a Legitimate System Process was Created (via file_event)

SOC Prime Team
09 Oct 2026

Possible DCSync Attack (via audit)

SOC Prime Team
09 Oct 2026

DCSync Rights was Granted (via audit)

SOC Prime Team
09 Oct 2026

Azure Authentication Request Was Perfomed With Suspicious User Agent (via azure)

SOC Prime Team
09 Oct 2026

Password Spraying and Guessing on Microsoft Exchange Servers [Azure Activity Logs]

SOC Prime AI Rules
09 Oct 2026

Automated Vulnerability Scanning Tools Used by Chinese Government-linked Actors [AWS Cloudtrail]

SOC Prime AI Rules
09 Oct 2026

Detection of DCSync Activity Using DC.exe [Windows Sysmon]

SOC Prime AI Rules
09 Oct 2026

Detection of Abnormal Executables for Malicious Activity [Windows Process Creation]

SOC Prime AI Rules
09 Oct 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary has gained initial access to the workstation. To maintain persistence and evade detection by SOC analysts looking for unknown binaries, the adversary performs a “Masquerading” technique. They take a simple benign executable (in this case, calc.exe) and rename it to DiagTrack.exe. They then execute this renamed file from a non-standard directory (C:UsersPublic). This action is intended to trigger the detection rule which monitors for the execution of DiagTrack.exe when it is used as a masquerading tool.

  • Regression Test Script:

    # Simulation Script: Masquerading as DiagTrack.exe
    $TargetDir = "C:UsersPublicDownloads"
    $MaliciousName = "DiagTrack.exe"
    $SourceBinary = "C:WindowsSystem32calc.exe"
    
    # 1. Create directory if it doesn't exist
    if (!(Test-Path $TargetDir)) {
        New-Item -ItemType Directory -Path $TargetDir -Force | Out-Null
    }
    
    # 2. Copy and rename the binary to masquerade
    Copy-Item -Path $SourceBinary -Destination "$TargetDir$MaliciousName" -Force
    
    # 3. Execute the masqueraded binary to trigger the detection
    Write-Host "[+] Executing masqueraded binary: $TargetDir$MaliciousName"
    Start-Process -FilePath "$TargetDir$MaliciousName"
    
    Write-Host "[+] Simulation complete. Check SIEM for detection."
  • Cleanup Commands:

    # Cleanup Script
    $TargetDir = "C:UsersPublicDownloads"
    $MaliciousName = "DiagTrack.exe"
    
    if (Test-Path "$TargetDir$MaliciousName") {
        Remove-Item -Path "$TargetDir$MaliciousName" -Force
        Write-Host "[+] Cleanup successful: $MaliciousName removed."
    } else {
        Write-Host "[-] Cleanup failed: File not found."
    }