Chinese Government-linked cyber threat actors combine automated and hands-on hacking tools to steal sensitive data

This section contains time sensitive announcements about specific cyber threats, vulnerabilities and scams. Each alert has information you need to be aware of, and what actions to take to mitigate any risk to you or your organisation.

Subscribe to our updates to be notified as soon as we publish an alert.

10:00AM, 9 October 2026

TLP Rating: Clear

Joint advisory on Chinese Government-linked cyber threat actors

The NCSC has joined international partners in releasing an advisory concerning the activities of Chinese government-linked actors being enabled by a China-based company, Integrity Technology Group. The advisory contains useful information about these actors, including the capabilities that they employ in undertaking this activity and indicators of compromise, as well as mitigations and response actions to protect critical information.

The NCSC has previously released a range of information related to activity discussed in the advisory, including previous alerts such as:

What's happening

Systems affected

The actors enabled by Integrity Technology Group undertake a range of activity affecting a variety of systems, often commencing with activity against vulnerable websites and web-based applications. The advisory sets out the activity more specifically to enable defenders to better protect critical information.

What to look for

How to tell if you're at risk

The advisory describes circumstances which enabled observed malicious activity and highlights victims of exfiltration in government and healthcare sectors.

How to tell if you're affected

The advisory includes an extensive list of Indicators of Compromise at Appendix A starting at page 19 and the linked STIX files.

What to do

Prevention

The authoring organisations recommend the following key actions:

  • Disable unused services and ports, such as automatic configuration, remote access, or file sharing protocols.
  • Sanitize user input in web applications to prevent possible cross-site scripting (XSS) payload injection.
  • Implement identity, credential, and access management (ICAM) policies, and then require multifactor authentication (MFA) for services (to the extent possible).

The advisory also includes a number of other preventative actions defenders can take.

Mitigation

Read the Mitigations section in the advisory for full details on how to mitigate.

More information

Download the advisory [PDF, 1.4 MB]

If you require more information or further support, submit a report on our website:

Report an incident  External Link External Lin.External Link.

If you need assistance using the tool, call us on 0800 114 115. Calling us is free within New Zealand. We’re open 7am to 7pm, Monday to Friday, and we’re closed on public holidays.