10:00AM, 9 October 2026
TLP Rating:
Joint advisory on Chinese Government-linked cyber threat actors
The NCSC has joined international partners in releasing an advisory concerning the activities of Chinese government-linked actors being enabled by a China-based company, Integrity Technology Group. The advisory contains useful information about these actors, including the capabilities that they employ in undertaking this activity and indicators of compromise, as well as mitigations and response actions to protect critical information.
The NCSC has previously released a range of information related to activity discussed in the advisory, including previous alerts such as:
- Defending against China-nexus covert networks of compromised devices; and
- Cyber security agencies call out PRC-linked ‘botnet’ and provide mitigation advice which also addressed the activities of Integrity Technology Group.
What's happening
Systems affected
What to look for
How to tell if you're at risk
How to tell if you're affected
What to do
Prevention
The authoring organisations recommend the following key actions:
- Disable unused services and ports, such as automatic configuration, remote access, or file sharing protocols.
- Sanitize user input in web applications to prevent possible cross-site scripting (XSS) payload injection.
- Implement identity, credential, and access management (ICAM) policies, and then require multifactor authentication (MFA) for services (to the extent possible).
The advisory also includes a number of other preventative actions defenders can take.
Mitigation
Read the Mitigations section in the advisory for full details on how to mitigate.
More information
Download the advisory [PDF, 1.4 MB]
If you require more information or further support, submit a report on our website:
Report an incident External Link External Lin.External Link.
If you need assistance using the tool, call us on 0800 114 115. Calling us is free within New Zealand. We’re open 7am to 7pm, Monday to Friday, and we’re closed on public holidays.