CODERED VTA

Chinese State Linked Operators Blend Botnets and Manual Hacking to Steal Sensitive Data

High
Inside a computer with cabling
Photo by pixellaphoto on Flickr

A joint advisory tracked as AA26-281A, published on 8 October 2026, describes sustained computer network exploitation activity carried out by Chinese government-linked threat actors enabled by Integrity Technology Group, a China-based company assessed to have links to the Chinese government. The activity targets organisations worldwide, including multiple United States critical infrastructure sectors — Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology. The advisory names eight vulnerabilities used by this cluster: CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199 and CVE-2023-22894. Every one of these is a known, long-published flaw rather than a zero-day, which means exposure is driven by unpatched and forgotten internet-facing systems rather than by any new vendor failure. Government, Federal Civilian Executive Branch, and State, Local, Tribal and Territorial bodies are explicitly called out as being in scope alongside private critical infrastructure operators.

The advisory describes a blended operating model rather than a single intrusion technique. The actors run large-scale botnets and automated scanning tools to find exposed services at volume, then route hands-on activity through virtual private network infrastructure to obscure its origin. Where a target presents a web application, cross-site scripting payload injection is used against inputs that are not properly sanitised. Against Microsoft Exchange servers, the operators fall back on password spraying — attempting a small number of common passwords across a large list of accounts, which avoids the lockout thresholds that defeat conventional brute forcing. Once inside, they establish persistence through VPN software and use living-off-the-land techniques, drawing on legitimate administrative binaries already present on the host, supplemented by repositories of computer network exploitation tooling. Collection and exfiltration of emails and credentials is handled by scripts, which keeps the operator footprint small and the volume of data moved high.

The strategic weight of this activity comes from its combination of breadth and patience. Automated scanning at botnet scale gives the operators continuous visibility of which organisations have left an old flaw exposed, while the hands-on phase is reserved for targets judged worth the operator time — a model that scales reconnaissance without scaling attribution risk. Exploitation here is not hypothetical. All eight named CVEs appear in the CISA Known Exploited Vulnerabilities catalogue: CVE-2019-11510 and CVE-2021-22205 were listed on 3 November 2021 and both carry known use in ransomware campaigns, CVE-2014-6278 was listed on 2 October 2025, and CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199 and CVE-2023-22894 were all added on 8 October 2026 alongside this advisory. FIRST EPSS places CVE-2019-11510 at a 100.0% probability of exploitation within the next thirty days, CVE-2021-22205 at 99.7%, CVE-2014-6278 at 99.6%, CVE-2015-3306 at 98.0%, CVE-2016-3081 at 94.5% and CVE-2015-5477 at 91.8%; the remaining two are lower, with CVE-2021-3199 at 14.5% and CVE-2023-22894 at 3.4%. The practical consequence for an exposed organisation is the loss of mailbox contents and valid credentials, and because persistence is established in VPN software rather than in a conventional malware implant, access can survive routine endpoint cleanup and password resets that do not extend to the remote access tier. For regulated sectors, email and credential theft at this scale also carries direct privacy and notification exposure, independent of whatever the operators do with the access next.

Attack Surface

Email, Web Application, Remote Access Service, Infrastructure, Server OS

Tactics

Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Credential Access, Defense Evasion, Collection, Exfiltration

Techniques

  • T1595 – Active Scanning
  • T1584.005 – Compromise Infrastructure: Botnet
  • T1190 – Exploit Public-Facing Application
  • T1110.003 – Brute Force: Password Spraying
  • T1133 – External Remote Services
  • T1059 – Command and Scripting Interpreter
  • T1114.002 – Email Collection: Remote Email Collection
  • T1020 – Automated Exfiltration

SuperPRO's Threat Countermeasures Procedures

  1. Patch the eight CVEs named in advisory AA26-281A across all internet-facing estate, prioritising CVE-2019-11510 and CVE-2021-22205 first because CISA KEV records both as used in ransomware campaigns and EPSS rates them at 100.0% and 99.7% respectively, followed by CVE-2014-6278, CVE-2015-3306, CVE-2016-3081 and CVE-2015-5477.
  2. Enforce multifactor authentication on Outlook Web Access, Exchange ActiveSync and all remote access services, and disable legacy basic authentication endpoints on Exchange so password spraying cannot bypass the MFA layer.
  3. Alert in the SIEM on Windows Security event ID 4625 where a single source IP generates failed logons against 10 or more distinct Exchange accounts within an hour, which is the signature of the password spraying described in the advisory.
  4. Disable unused services and listening ports on externally reachable hosts, specifically automatic configuration services, unused remote access daemons, and file sharing protocols such as SMB on TCP/445 and NetBIOS on TCP/139 where they are not required.
  5. Apply server-side input validation and context-aware output encoding to every user-supplied parameter in public web applications, and deploy a Content-Security-Policy header that blocks inline script execution to defeat the cross-site scripting payload injection described in the advisory.
  6. Ingest the AA26-281A STIX bundle published by CISA into the SIEM, EDR and perimeter firewall as blocklists and retrospective hunt queries covering at least the preceding 12 months of proxy, VPN and mail logs.
  7. Audit VPN appliances for unauthorised local accounts, modified configuration files and unexpected session persistence, and rotate all VPN, LDAP bind and Exchange service credentials on any appliance that ran a vulnerable build of the affected software.

Source

Code Red Cyber / VTA – coderedcyber.ai