CrowdStrike Links South Korean Bank Hacks to China-Based Actor Using AI
CrowdStrike details how a China-based threat actor leveraged generative AI to execute South Korean bank hacks, signaling a new era of cyber threats.
Integrity Technology Group, a China-linked firm, ran an illicit portal providing third parties access to stolen government and healthcare emails. FBI confirms.
Senior Technology Analyst

Integrity Technology Group, a China-linked firm, ran an illicit portal providing third parties access to stolen government and healthcare emails. FBI confirms.
In a coordinated move that underscores the escalating sophistication of state-aligned cyber-espionage, the FBI and a coalition of international partners have unmasked a sprawling surveillance operation orchestrated by Integrity Technology Group (ITG). The organization, which maintains clear ties to Chinese state interests, operated a proprietary portal that functioned as a clearinghouse for exfiltrated sensitive data. This was not a typical ransomware extortion scheme; it was a methodical, long-term intelligence-gathering apparatus targeting government agencies, healthcare systems, and religious institutions across Southeast Asia.
For years, ITG operated under the thin veneer of a legitimate cybersecurity consultancy. However, intelligence gathered by the FBI and its counterparts reveals that the company was effectively a front for harvesting high-value intelligence. By leveraging a custom-built toolkit designed to scan external-facing web infrastructure for unpatched vulnerabilities, ITG systematically compromised hundreds of organizations. The resulting data—ranging from diplomatic cables to private medical records—was then indexed and made available through a centralized portal, effectively commodifying espionage for third-party access.
The technical efficiency of Integrity Technology Group relied on a modular scanning framework that prioritized speed and stealth. Rather than relying on public-facing exploit kits, ITG developed internal tools capable of identifying common web application vulnerabilities—specifically those related to outdated server-side software and misconfigured API endpoints—at scale. Once a foothold was established, the hackers deployed persistent backdoors, allowing for the exfiltration of mail spools and internal communications without triggering traditional network behavior anomalies.
What makes the ITG operation particularly dangerous is its focus on "low-and-slow" data exfiltration. The actors were not interested in immediate destruction or disruption. Instead, they maintained long-term access, treating compromised mail servers as a live feed of intelligence. The portal they developed served as the interface for this live feed, allowing for granular searching and filtering of stolen content. By organizing the data into a searchable database, the operators enabled third parties to perform targeted queries against specific government officials or organizations, drastically lowering the barrier to entry for state actors looking to exploit the stolen information.
The revelation of the ITG portal has triggered a swift response from the United States and the United Kingdom, both of which have formally sanctioned the company and its primary operators. These sanctions are designed to freeze the group’s financial assets and complicate their ability to procure infrastructure, such as cloud hosting services and domain registrations, that are essential for their continued operation. However, sanctions alone are unlikely to dismantle the infrastructure entirely. The decentralized nature of modern cyber-espionage means that actors often simply rebrand under new corporate shells, utilizing the same underlying codebase and tactics.
The inclusion of religious institutions and healthcare providers as primary targets highlights a broader shift in the strategic calculus of China-linked threat actors. By targeting these sectors, ITG was not just seeking military or political secrets; they were mapping the social and demographic fabric of the Southeast Asian region. The stolen emails provide a granular view of decision-making processes, internal dissent, and vulnerability to external influence, which can be leveraged for years to come.
Attributing complex cyber operations to a specific corporate entity like Integrity Technology Group is a significant achievement for international law enforcement. It requires the deep integration of signals intelligence, forensic analysis of server logs, and the tracking of financial transactions related to infrastructure rental. Yet, the persistence of these campaigns remains a thorn in the side of global security agencies. As these threat actors continue to refine their automation tools, the window of time between a vulnerability being announced and it being weaponized by groups like ITG continues to shrink.
For organizations operating in regions targeted by ITG, the incident serves as a stark reminder that standard security hygiene is no longer sufficient. Organizations must move toward a zero-trust architecture that assumes internal networks are already compromised. This includes strict enforcement of multi-factor authentication, rigorous auditing of API access logs, and the implementation of automated threat detection systems capable of identifying unusual data egress patterns. Relying on perimeter security is, in the face of actors like ITG, a losing strategy. The ability of the FBI to finally shine a light on the ITG portal is a victory, but it is one that arrives after years of undetected infiltration, highlighting the urgent need for a more proactive approach to threat hunting and intelligence sharing among private and public sectors alike.
This report was independently synthesized, fact-checked, and expanded with technical mitigation guidance and risk evaluations by the Zero Hour Tech editorial desk. Initial reporting, vendor bulletins, or threat telemetry were tracked from thehackernews.com .
Contributing editor at Zero Hour Tech, specializing in cybersecurity & privacy analysis, vulnerability response, and emerging software paradigms.
View Full Profile & Articles →CrowdStrike details how a China-based threat actor leveraged generative AI to execute South Korean bank hacks, signaling a new era of cyber threats.
Explore key findings in frontier AI security, focusing on indirect prompt injection, alignment bypass techniques, and robust agentic mitigation frameworks.
Get our concise weekly security briefings covering newly disclosed vulnerabilities, exploit mechanics, and actionable system hardening guides.
100% Privacy guaranteed. One-click unsubscribe at any time.