Somewhere on your network there is probably an FTP server nobody has logged into since 2016, or a DNS box that “just works,” or an old Java app still running Struts 2.3. On October 8, cyber agencies from seven countries put out a joint advisory saying that’s exactly what one long-running China-linked operation keeps finding and breaking into.
The bugs are old: 2014, 2015, 2016, 2021, 2023. CISA added five of them to its Known Exploited Vulnerabilities list the same day and gave federal agencies until Sunday, October 11, to deal with them. Everyone else gets the same advice with no deadline attached. Use the weekend anyway.
Nobody needed a zero-day. They needed the server you forgot you still had.
The 5-Minute Cyber BriefDon’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
What happened
The FBI, CISA, NSA and partner agencies in the UK, Australia, Canada, Japan, New Zealand and Spain released advisory AA26-281A on October 8. It describes threat actors enabled by Integrity Technology Group, a China-based company the agencies say has links to the Chinese government. Their tradecraft overlaps with activity tracked publicly as Flax Typhoon, Ethereal Panda and Red Juliett.
Based on evidence from multiple FBI investigations, the advisory describes a mix of automated and hands-on work:
- Mass scanning. Open-source scanners (fscan, masscan, nmap, dirsearch, wpscan and others) focused on ports 21 (FTP), 22 (SSH), 53 (DNS), 80, 443 and 1080 (SOCKS). A web app called MicroScan, in use since at least 2017, holds more than 1,300 scripts for specific bugs in software like WebLogic, Jenkins, Struts, Rejetto and WordPress.
- Exchange and Microsoft 365 password spraying with EBurst, across OWA, ECP, EWS, ActiveSync, Autodiscover, MAPI, RPC, OAB and Exchange PowerShell.
- Fake login prompts injected through cross-site scripting on vulnerable websites, followed by a malware download.
- Persistence through SoftEther VPN, a legitimate VPN client, often renamed
conhost.exeordllhost.exeand set to reconnect on startup. - Mail theft through an EWS bot (Curlc4) and a command-line tool (office-cli) that reads Microsoft 365 mailboxes with app credentials, plus DCSync against Active Directory using
DC.exe.
The advisory lists eight vulnerabilities the actors exploited successfully. CISA added the five not already in its catalog to KEV on October 8: ProFTPD mod_copy (CVE-2015-3306), ISC BIND TKEY (CVE-2015-5477), Apache Struts (CVE-2016-3081), ONLYOFFICE Docs (CVE-2021-3199) and Strapi (CVE-2023-22894). The other three are Bash “Shellshock” (CVE-2014-6278), Pulse Connect Secure (CVE-2019-11510) and GitLab (CVE-2021-22205).
The same day, the Justice Department and FBI announced the seizure of seven domains tied to the group’s scanning and spear-phishing tools.
Why it matters
This isn’t a story about one product. It’s about everything that fell off the patch list because it was old, quiet or owned by a team that no longer exists. The targets the agencies name include government, critical manufacturing, healthcare and IT, and also education, law enforcement and religious organizations. In other words: organizations that look a lot like most of our readers.
The mail theft is the part that hurts. Once these actors have a mailbox, or an app registration that can read mailboxes, a patch on the original server doesn’t get them out.
What to do first
- Pull an external scan of your own address space for ports 21, 53 and 1080. Anything answering on FTP or SOCKS that you can’t name an owner for goes on Monday’s agenda, or gets switched off today.
- Search your asset inventory for ProFTPD 1.3.5, BIND 9 older than 9.9.7-P2 or 9.10.2-P3, Struts 2.3.x, ONLYOFFICE Document Server 5.1.5–5.6.2 and Strapi up to 4.5.5. Upgrade or retire what you find. Replacing end-of-life products is one of the advisory’s own recommendations.
- Check Exchange and Microsoft 365 sign-in logs for password spraying across legacy endpoints (EWS, ActiveSync, Autodiscover, OAB). Require MFA on webmail and VPN, and turn off legacy authentication where you still can.
- Review Entra ID app registrations and service principals that hold mail-read permissions. Rotate secrets on any you can’t explain.
- Load the AA26-281A STIX indicators into your SIEM or EDR. Vet them before you block: CISA notes some date back to 2016.
Forward this
For whoever owns our servers and Microsoft 365: on October 8, agencies from seven countries warned that a China-linked group is breaking into organizations through old, forgotten servers (FTP, DNS, Struts, Strapi, ONLYOFFICE) and then stealing email. Can we confirm by Monday that we don’t have any of the listed versions exposed, and that nobody outside IT can read mailboxes through an app registration?
Details
- Advisory: AA26-281A, “Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data,” released October 8, 2026, with STIX JSON/XML indicators.
- Authoring agencies: FBI, CISA, NSA, NCSC-UK, ASD’s ACSC, Canadian Centre for Cyber Security, Japan NPA and NCO, NCSC-NZ, Spain CNI.
- Newly added to KEV on October 8 (federal due date October 11): CVE-2015-3306 ProFTPD 1.3.5 (mod_copy, unauthenticated file copy); CVE-2015-5477 ISC BIND before 9.9.7-P2 / 9.10.2-P3 (TKEY denial of service); CVE-2016-3081 Apache Struts 2.3.19–2.3.20.2, 2.3.21–2.3.24.1, 2.3.25–2.3.28 (dynamic method invocation command injection); CVE-2021-3199 ONLYOFFICE Document Server 5.1.5–5.6.2 (path traversal, unauthorized write); CVE-2023-22894 Strapi up to 4.5.5 (cleartext storage of sensitive information).
- Also listed as exploited: CVE-2014-6278 GNU Bash, CVE-2019-11510 Pulse Connect Secure, CVE-2021-22205 GitLab.
- Named tools: MicroScan, EBurst, SoftEther VPN client, Curlc4 (EWS mail bot), office-cli, DC.exe (DCSync), DiagTrack.exe / live700_v1.exe (XSS-delivered malware).
- Disruption: DOJ and FBI announced the seizure of seven domains supporting the group’s scanning and spear-phishing tooling on October 8.
Hunt / verify
- Look for SoftEther VPN on endpoints and servers: binaries named
conhost.exeordllhost.exeoutsideC:\Windows\System32, and services or Run keys that reconnect a VPN at startup. On Linux, look for SoftEther pulled down withcurlorwget. - Alert on unexpected Active Directory replication requests (DCSync) from hosts that aren’t domain controllers.
- In web server logs, look for directory enumeration bursts against
.phpand.aspxpaths, and for ProFTPDSITE CPFR/SITE CPTOcommands. - In Microsoft 365, review EWS and Graph mailbox access by app identities, especially new client secrets added to existing apps.
- Check DNS and proxy logs against the advisory’s domain list (for example
studiocloud[.]xyz,natcloudservice[.]com,96html[.]com).
Slack paste: AA26-281A (Oct 8, 7 countries): China-linked actors exploiting old servers (ProFTPD 1.3.5, BIND TKEY, Struts 2.3 S2-032, ONLYOFFICE 5.x, Strapi ≤4.5.5, plus Shellshock, Pulse, GitLab), Exchange password spraying, SoftEther VPN persistence, M365 mail theft. KEV due Sun Oct 11. Action: find and patch/retire exposed FTP/DNS/Struts, MFA on webmail, review mail-read app registrations, load the STIX IOCs.
Sources
- CISA: AA26-281A joint cybersecurity advisory (October 8, 2026)
- CISA: Known Exploited Vulnerabilities Catalog
- U.S. Department of Justice: domain seizure announcement (October 8, 2026)
- BleepingComputer: FBI disrupts Chinese hacking tools used to breach critical infrastructure
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.